From 6212932c3573345c3e7714ae07cb35693d01ae76 Mon Sep 17 00:00:00 2001 From: research bot Date: Thu, 25 Mar 2021 19:35:07 +0000 Subject: [PATCH 1/2] updating docs and package bits [ci skip] --- ..._policy_version_to_allow_all_resources.yml | 7 +- detections/cloud/aws_createaccesskey.yml | 6 +- detections/cloud/aws_createloginprofile.yml | 6 +- .../cloud/aws_setdefaultpolicyversion.yml | 6 +- detections/cloud/aws_updateloginprofile.yml | 6 +- ..._to_add_certificate_to_untrusted_store.yml | 1 - ...load_with_urlcache_and_split_arguments.yml | 2 +- ...oad_with_verifyctl_and_split_arguments.yml | 2 +- .../certutil_with_decode_argument.yml | 2 +- .../endpoint/clop_common_exec_parameter.yml | 12 +- .../clop_ransomware_known_service_name.yml | 6 +- ...create_service_in_suspicious_file_path.yml | 6 +- .../endpoint/detect_exchange_web_shell.yml | 2 +- .../endpoint/high_file_deletion_frequency.yml | 6 +- .../high_process_termination_frequency.yml | 6 +- ...process_deleting_its_process_file_path.yml | 6 +- .../ransomware_notes_bulk_creation.yml | 6 +- .../endpoint/resize_shadowstorage_volume.yml | 13 +- ...tolen_credentials_via_mimikatz_modules.yml | 2 - .../endpoint/suspicious_wevtutil_usage.yml | 2 +- .../endpoint/windows_event_log_cleared.yml | 2 +- docs/detections.md | 6865 +- docs/detections.wiki | 14104 +++- docs/mitre-map/coverage.csv | 63712 +++++++++------- docs/mitre-map/coverage.json | 23232 +++--- docs/mitre-map/detections.csv | 24992 +++--- docs/mitre-map/detections.json | 15194 ++-- docs/stories.md | 791 +- docs/stories.wiki | 1269 +- package/app.manifest | 2 +- package/default/analytic_stories.conf | 170 +- package/default/analyticstories.conf | 364 +- package/default/app.conf | 4 +- package/default/collections.conf | 2 +- package/default/content-version.conf | 2 +- package/default/es_investigations.conf | 86 +- package/default/macros.conf | 66 +- package/default/savedsearches.conf | 923 +- package/default/transforms.conf | 2 +- package/default/use_case_library.conf | 364 +- package/lookups/ransomware_extensions.csv | 4 +- package/lookups/ransomware_notes.csv | 2 + 42 files changed, 90835 insertions(+), 61422 deletions(-) diff --git a/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml b/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml index c9c846f28a..046e58d6bf 100644 --- a/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml +++ b/detections/cloud/aws_create_policy_version_to_allow_all_resources.yml @@ -1,4 +1,3 @@ - name: AWS Create Policy Version to allow all resources id: 2a9b80d3-6340-4345-b5ad-212bf3d0dac4 version: 2 @@ -29,8 +28,11 @@ tags: analytic_story: - AWS IAM Privilege Escalation asset_type: AWS Account + automated_detection_testing: passed cis20: - CIS 13 + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_create_policy_version/aws_cloudtrail_events.json kill_chain_phases: - Actions on Objectives mitre_attack_id: @@ -54,6 +56,3 @@ tags: risk_object_type: system risk_score: 20 security_domain: network - automated_detection_testing: passed - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_create_policy_version/aws_cloudtrail_events.json diff --git a/detections/cloud/aws_createaccesskey.yml b/detections/cloud/aws_createaccesskey.yml index 6441c1b7e7..9b287b1b03 100644 --- a/detections/cloud/aws_createaccesskey.yml +++ b/detections/cloud/aws_createaccesskey.yml @@ -25,8 +25,11 @@ tags: analytic_story: - AWS IAM Privilege Escalation asset_type: AWS Account + automated_detection_testing: passed cis20: - CIS 13 + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_createaccesskey/aws_cloudtrail_events.json kill_chain_phases: - Actions on Objectives mitre_attack_id: @@ -50,6 +53,3 @@ tags: risk_object_type: system risk_score: 20 security_domain: network - automated_detection_testing: passed - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_createaccesskey/aws_cloudtrail_events.json diff --git a/detections/cloud/aws_createloginprofile.yml b/detections/cloud/aws_createloginprofile.yml index c15ca04dca..ab5045322f 100644 --- a/detections/cloud/aws_createloginprofile.yml +++ b/detections/cloud/aws_createloginprofile.yml @@ -27,8 +27,11 @@ tags: analytic_story: - AWS IAM Privilege Escalation asset_type: AWS Account + automated_detection_testing: passed cis20: - CIS 13 + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_createloginprofile/aws_cloudtrail_events.json kill_chain_phases: - Actions on Objectives mitre_attack_id: @@ -52,6 +55,3 @@ tags: risk_object_type: system risk_score: 20 security_domain: network - automated_detection_testing: passed - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_createloginprofile/aws_cloudtrail_events.json diff --git a/detections/cloud/aws_setdefaultpolicyversion.yml b/detections/cloud/aws_setdefaultpolicyversion.yml index 6e770a2178..81f4fe04a5 100644 --- a/detections/cloud/aws_setdefaultpolicyversion.yml +++ b/detections/cloud/aws_setdefaultpolicyversion.yml @@ -27,8 +27,11 @@ tags: analytic_story: - AWS IAM Privilege Escalation asset_type: AWS Account + automated_detection_testing: passed cis20: - CIS 13 + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_setdefaultpolicyversion/aws_cloudtrail_events.json kill_chain_phases: - Actions on Objectives mitre_attack_id: @@ -53,6 +56,3 @@ tags: risk_object_type: system risk_score: 20 security_domain: network - automated_detection_testing: passed - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_setdefaultpolicyversion/aws_cloudtrail_events.json diff --git a/detections/cloud/aws_updateloginprofile.yml b/detections/cloud/aws_updateloginprofile.yml index 193ebaf94b..48ce03108b 100644 --- a/detections/cloud/aws_updateloginprofile.yml +++ b/detections/cloud/aws_updateloginprofile.yml @@ -25,8 +25,11 @@ tags: analytic_story: - AWS IAM Privilege Escalation asset_type: AWS Account + automated_detection_testing: passed cis20: - CIS 13 + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_updateloginprofile/aws_cloudtrail_events.json kill_chain_phases: - Actions on Objectives mitre_attack_id: @@ -50,6 +53,3 @@ tags: risk_object_type: system risk_score: 20 security_domain: network - automated_detection_testing: passed - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_updateloginprofile/aws_cloudtrail_events.json diff --git a/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml b/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml index 13e2839ec8..67dd384c0f 100644 --- a/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml +++ b/detections/endpoint/attempt_to_add_certificate_to_untrusted_store.yml @@ -52,4 +52,3 @@ tags: - Processes.parent_process - Processes.user security_domain: endpoint - diff --git a/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml b/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml index 133f86d1ad..87fbbfd62a 100644 --- a/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml +++ b/detections/endpoint/certutil_download_with_urlcache_and_split_arguments.yml @@ -31,6 +31,7 @@ references: tags: analytic_story: - Ingress Tool Transfer + automated_detection_testing: passed dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-sysmon.log kill_chain_phases: @@ -49,4 +50,3 @@ tags: - Processes.user - Processes.dest security_domain: endpoint - automated_detection_testing: passed diff --git a/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml b/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml index 188b733ce9..7c58bc5d30 100644 --- a/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml +++ b/detections/endpoint/certutil_download_with_verifyctl_and_split_arguments.yml @@ -32,6 +32,7 @@ references: tags: analytic_story: - Ingress Tool Transfer + automated_detection_testing: passed dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-sysmon.log kill_chain_phases: @@ -50,4 +51,3 @@ tags: - Processes.user - Processes.dest security_domain: endpoint - automated_detection_testing: passed diff --git a/detections/endpoint/certutil_with_decode_argument.yml b/detections/endpoint/certutil_with_decode_argument.yml index 34bf9e0c60..4daa11119d 100644 --- a/detections/endpoint/certutil_with_decode_argument.yml +++ b/detections/endpoint/certutil_with_decode_argument.yml @@ -34,6 +34,7 @@ references: tags: analytic_story: - Deobfuscate-Decode Files or Information + automated_detection_testing: passed dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1140/atomic_red_team/windows-sysmon.log kill_chain_phases: @@ -52,4 +53,3 @@ tags: - Processes.user - Processes.dest security_domain: endpoint - automated_detection_testing: passed diff --git a/detections/endpoint/clop_common_exec_parameter.yml b/detections/endpoint/clop_common_exec_parameter.yml index c8312f7c3e..d9455c76a3 100644 --- a/detections/endpoint/clop_common_exec_parameter.yml +++ b/detections/endpoint/clop_common_exec_parameter.yml @@ -17,11 +17,9 @@ search: '| tstats `security_content_summariesonly` values(Processes.process) as values(Processes.parent_process_name) as parent_process values(Processes.process_name) count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process = "*runrun*" OR Processes.process = "*temp.dat*" by Processes.parent_process_name - Processes.process_name Processes.process Processes.dest Processes.user Processes.process_id Processes.process_guid - | `drop_dm_object_name(Processes)` - | `security_content_ctime(firstTime)` - | `security_content_ctime(lastTime)` - | `clop_common_exec_parameter_filter`' + Processes.process_name Processes.process Processes.dest Processes.user Processes.process_id + Processes.process_guid | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` + | `security_content_ctime(lastTime)` | `clop_common_exec_parameter_filter`' how_to_implement: To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the @@ -34,6 +32,8 @@ tags: analytic_story: - Clop Ransomware automated_detection_testing: passed + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_b/windows-sysmon.log kill_chain_phases: - Obfuscation mitre_attack_id: @@ -51,5 +51,3 @@ tags: - Processes.user - Processes.process_id security_domain: endpoint - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_b/windows-sysmon.log diff --git a/detections/endpoint/clop_ransomware_known_service_name.yml b/detections/endpoint/clop_ransomware_known_service_name.yml index dcd20febdc..7dcf383e02 100644 --- a/detections/endpoint/clop_ransomware_known_service_name.yml +++ b/detections/endpoint/clop_ransomware_known_service_name.yml @@ -24,6 +24,9 @@ references: tags: analytic_story: - Clop Ransomware + automated_detection_testing: passed + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-system.log kill_chain_phases: - Privilege Escalation mitre_attack_id: @@ -41,6 +44,3 @@ tags: - OriginalFileName - process_path security_domain: endpoint - automated_detection_testing: passed - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-system.log diff --git a/detections/endpoint/create_service_in_suspicious_file_path.yml b/detections/endpoint/create_service_in_suspicious_file_path.yml index 6787d6592d..2dc01b2685 100644 --- a/detections/endpoint/create_service_in_suspicious_file_path.yml +++ b/detections/endpoint/create_service_in_suspicious_file_path.yml @@ -23,6 +23,9 @@ references: tags: analytic_story: - Clop Ransomware + automated_detection_testing: passed + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-system.log kill_chain_phases: - Privilege Escalation mitre_attack_id: @@ -39,6 +42,3 @@ tags: - Service_Name - Service_Start_Type security_domain: endpoint - automated_detection_testing: passed - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-system.log diff --git a/detections/endpoint/detect_exchange_web_shell.yml b/detections/endpoint/detect_exchange_web_shell.yml index 011bfc3c34..65c47b13d3 100644 --- a/detections/endpoint/detect_exchange_web_shell.yml +++ b/detections/endpoint/detect_exchange_web_shell.yml @@ -34,6 +34,7 @@ references: tags: analytic_story: - HAFNIUM Group + automated_detection_testing: passed dataset: - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1505.003/windows-sysmon_proxylogon.log kill_chain_phases: @@ -52,4 +53,3 @@ tags: - Filesystem.file_hash - Filesystem.user security_domain: endpoint - automated_detection_testing: passed diff --git a/detections/endpoint/high_file_deletion_frequency.yml b/detections/endpoint/high_file_deletion_frequency.yml index 556735275f..50aba144f0 100644 --- a/detections/endpoint/high_file_deletion_frequency.yml +++ b/detections/endpoint/high_file_deletion_frequency.yml @@ -26,6 +26,9 @@ references: tags: analytic_story: - Clop Ransomware + automated_detection_testing: passed + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log kill_chain_phases: - Exploitation mitre_attack_id: @@ -43,6 +46,3 @@ tags: - ProcessID - _time security_domain: endpoint - automated_detection_testing: passed - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log diff --git a/detections/endpoint/high_process_termination_frequency.yml b/detections/endpoint/high_process_termination_frequency.yml index b142ddc128..5784960f38 100644 --- a/detections/endpoint/high_process_termination_frequency.yml +++ b/detections/endpoint/high_process_termination_frequency.yml @@ -24,6 +24,9 @@ references: tags: analytic_story: - Clop Ransomware + automated_detection_testing: passed + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log kill_chain_phases: - Exploitation mitre_attack_id: @@ -39,6 +42,3 @@ tags: - _time - ProcessID security_domain: endpoint - automated_detection_testing: passed - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log diff --git a/detections/endpoint/process_deleting_its_process_file_path.yml b/detections/endpoint/process_deleting_its_process_file_path.yml index 82643ed65a..20c35f71cd 100644 --- a/detections/endpoint/process_deleting_its_process_file_path.yml +++ b/detections/endpoint/process_deleting_its_process_file_path.yml @@ -28,6 +28,9 @@ references: tags: analytic_story: - Clop Ransomware + automated_detection_testing: passed + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log kill_chain_phases: - Exploitation mitre_attack_id: @@ -48,6 +51,3 @@ tags: - result - _time security_domain: endpoint - automated_detection_testing: passed - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log diff --git a/detections/endpoint/ransomware_notes_bulk_creation.yml b/detections/endpoint/ransomware_notes_bulk_creation.yml index f426f36ccc..bbe1e912ab 100644 --- a/detections/endpoint/ransomware_notes_bulk_creation.yml +++ b/detections/endpoint/ransomware_notes_bulk_creation.yml @@ -26,6 +26,9 @@ references: tags: analytic_story: - Clop Ransomware + automated_detection_testing: passed + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log kill_chain_phases: - Obfuscation mitre_attack_id: @@ -43,6 +46,3 @@ tags: - Image - user security_domain: endpoint - automated_detection_testing: passed - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log diff --git a/detections/endpoint/resize_shadowstorage_volume.yml b/detections/endpoint/resize_shadowstorage_volume.yml index a69ec49c5a..88d00108a5 100644 --- a/detections/endpoint/resize_shadowstorage_volume.yml +++ b/detections/endpoint/resize_shadowstorage_volume.yml @@ -20,11 +20,8 @@ search: '| tstats `security_content_summariesonly` values(Processes.process) as = "wmic.exe" Processes.process_name = "vssadmin.exe" Processes.process="*resize*" Processes.process="*shadowstorage*" Processes.process="*/maxsize*" by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.dest - Processes.user Processes.process_id Processes.process_guid - | `drop_dm_object_name(Processes)` - | `security_content_ctime(firstTime)` - |`security_content_ctime(lastTime)` - | `resize_shadowstorage_volume_filter`' + Processes.user Processes.process_id Processes.process_guid | `drop_dm_object_name(Processes)` + | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `resize_shadowstorage_volume_filter`' how_to_implement: To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the @@ -36,6 +33,9 @@ references: tags: analytic_story: - Clop Ransomware + automated_detection_testing: passed + dataset: + - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log kill_chain_phases: - Exploitation mitre_attack_id: @@ -53,6 +53,3 @@ tags: - Processes.dest - Processes.user security_domain: endpoint - automated_detection_testing: passed - dataset: - - https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log diff --git a/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml b/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml index e50ba9c009..626f2f6d8d 100644 --- a/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml +++ b/detections/endpoint/ssa___applying_stolen_credentials_via_mimikatz_modules.yml @@ -59,5 +59,3 @@ tags: - _time risk_severity: high security_domain: endpoint - - diff --git a/detections/endpoint/suspicious_wevtutil_usage.yml b/detections/endpoint/suspicious_wevtutil_usage.yml index a47ef0d432..118240e995 100644 --- a/detections/endpoint/suspicious_wevtutil_usage.yml +++ b/detections/endpoint/suspicious_wevtutil_usage.yml @@ -28,7 +28,7 @@ tags: analytic_story: - Windows Log Manipulation - Ransomware - - Clop Ransomware + - Clop Ransomware asset_type: '' automated_detection_testing: passed cis20: diff --git a/detections/endpoint/windows_event_log_cleared.yml b/detections/endpoint/windows_event_log_cleared.yml index 8066d443e0..a2df6f11e6 100644 --- a/detections/endpoint/windows_event_log_cleared.yml +++ b/detections/endpoint/windows_event_log_cleared.yml @@ -20,7 +20,7 @@ tags: analytic_story: - Windows Log Manipulation - Ransomware - - Clop Ransomware + - Clop Ransomware asset_type: Endpoint automated_detection_testing: passed cis20: diff --git a/docs/detections.md b/docs/detections.md index d7d3480a81..d26bc1d4b7 100644 --- a/docs/detections.md +++ b/docs/detections.md @@ -17,6 +17,18 @@ All the detections shipped to different Splunk products. Below is a breakdown by +- [AWS Create Policy Version to allow all resources](#aws-create-policy-version-to-allow-all-resources) + + + +- [AWS CreateAccessKey](#aws-createaccesskey) + + + +- [AWS CreateLoginProfile](#aws-createloginprofile) + + + - [AWS Cross Account Activity From Previously Unseen Account](#aws-cross-account-activity-from-previously-unseen-account) @@ -29,8 +41,6 @@ All the detections shipped to different Splunk products. Below is a breakdown by -- [AWS EKS Kubernetes cluster sensitive object access](#aws-eks-kubernetes-cluster-sensitive-object-access) - - [AWS Network Access Control List Created with All Open Ports](#aws-network-access-control-list-created-with-all-open-ports) @@ -49,6 +59,14 @@ All the detections shipped to different Splunk products. Below is a breakdown by +- [AWS SetDefaultPolicyVersion](#aws-setdefaultpolicyversion) + + + +- [AWS UpdateLoginProfile](#aws-updateloginprofile) + + + @@ -100,6 +118,20 @@ All the detections shipped to different Splunk products. Below is a breakdown by + + + + + + + + + + + + + + @@ -202,6 +234,10 @@ All the detections shipped to different Splunk products. Below is a breakdown by + + + + @@ -242,6 +278,8 @@ All the detections shipped to different Splunk products. Below is a breakdown by + + @@ -437,7 +475,9 @@ All the detections shipped to different Splunk products. Below is a breakdown by -- [GCP Detect accounts with high risk roles by project](#gcp-detect-accounts-with-high-risk-roles-by-project) + + + @@ -445,8 +485,6 @@ All the detections shipped to different Splunk products. Below is a breakdown by -- [GCP Detect high risk permissions by resource and account](#gcp-detect-high-risk-permissions-by-resource-and-account) - @@ -455,7 +493,7 @@ All the detections shipped to different Splunk products. Below is a breakdown by -- [GCP Kubernetes cluster scan detection](#gcp-kubernetes-cluster-scan-detection) + @@ -491,81 +529,47 @@ All the detections shipped to different Splunk products. Below is a breakdown by -- [Kubernetes AWS detect RBAC authorization by account](#kubernetes-aws-detect-rbac-authorization-by-account) -- [Kubernetes AWS detect most active service accounts by pod](#kubernetes-aws-detect-most-active-service-accounts-by-pod) -- [Kubernetes AWS detect sensitive role access](#kubernetes-aws-detect-sensitive-role-access) -- [Kubernetes AWS detect service accounts forbidden failure access](#kubernetes-aws-detect-service-accounts-forbidden-failure-access) - - - [Kubernetes AWS detect suspicious kubectl calls](#kubernetes-aws-detect-suspicious-kubectl-calls) -- [Kubernetes Azure detect RBAC authorization by account](#kubernetes-azure-detect-rbac-authorization-by-account) -- [Kubernetes Azure detect most active service accounts by pod namespace](#kubernetes-azure-detect-most-active-service-accounts-by-pod-namespace) -- [Kubernetes Azure detect sensitive object access](#kubernetes-azure-detect-sensitive-object-access) -- [Kubernetes Azure detect sensitive role access](#kubernetes-azure-detect-sensitive-role-access) -- [Kubernetes Azure detect service accounts forbidden failure access](#kubernetes-azure-detect-service-accounts-forbidden-failure-access) -- [Kubernetes Azure detect suspicious kubectl calls](#kubernetes-azure-detect-suspicious-kubectl-calls) -- [Kubernetes Azure pod scan fingerprint](#kubernetes-azure-pod-scan-fingerprint) -- [Kubernetes Azure scan fingerprint](#kubernetes-azure-scan-fingerprint) -- [Kubernetes GCP detect RBAC authorizations by account](#kubernetes-gcp-detect-rbac-authorizations-by-account) -- [Kubernetes GCP detect most active service accounts by pod](#kubernetes-gcp-detect-most-active-service-accounts-by-pod) - - - -- [Kubernetes GCP detect sensitive object access](#kubernetes-gcp-detect-sensitive-object-access) - - - -- [Kubernetes GCP detect sensitive role access](#kubernetes-gcp-detect-sensitive-role-access) - - - -- [Kubernetes GCP detect service accounts forbidden failure access](#kubernetes-gcp-detect-service-accounts-forbidden-failure-access) - - - -- [Kubernetes GCP detect suspicious kubectl calls](#kubernetes-gcp-detect-suspicious-kubectl-calls) - - @@ -603,6 +607,8 @@ All the detections shipped to different Splunk products. Below is a breakdown by + + - [O365 Add App Role Assignment Grant User](#o365-add-app-role-assignment-grant-user) @@ -858,6 +864,34 @@ All the detections shipped to different Splunk products. Below is a breakdown by + + + + + + + + + + + + + + + + + + + + + + + + + + + + @@ -899,8 +933,6 @@ All the detections shipped to different Splunk products. Below is a breakdown by -- [gcp detect oauth token abuse](#gcp-detect-oauth-token-abuse) - @@ -939,6 +971,16 @@ All the detections shipped to different Splunk products. Below is a breakdown by + + + + + + + + + + @@ -958,6 +1000,14 @@ All the detections shipped to different Splunk products. Below is a breakdown by +- [Any Powershell DownloadFile](#any-powershell-downloadfile) + + + +- [Any Powershell DownloadString](#any-powershell-downloadstring) + + + - [Applying Stolen Credentials via Mimikatz modules](#applying-stolen-credentials-via-mimikatz-modules) @@ -998,6 +1048,18 @@ All the detections shipped to different Splunk products. Below is a breakdown by +- [CertUtil Download With URLCache and Split Arguments](#certutil-download-with-urlcache-and-split-arguments) + + + +- [CertUtil Download With VerifyCtl and Split Arguments](#certutil-download-with-verifyctl-and-split-arguments) + + + +- [CertUtil With Decode Argument](#certutil-with-decode-argument) + + + - [Certutil exe certificate extraction](#certutil-exe-certificate-extraction) @@ -1008,6 +1070,11 @@ All the detections shipped to different Splunk products. Below is a breakdown by +- [Clop Common Exec Parameter](#clop-common-exec-parameter) + + + +- [Clop Ransomware Known Service Name](#clop-ransomware-known-service-name) @@ -1028,6 +1095,13 @@ All the detections shipped to different Splunk products. Below is a breakdown by + + + + + +- [Cobalt Strike Named Pipes](#cobalt-strike-named-pipes) + - [Common Ransomware Extensions](#common-ransomware-extensions) @@ -1042,6 +1116,10 @@ All the detections shipped to different Splunk products. Below is a breakdown by +- [Create Service In Suspicious File Path](#create-service-in-suspicious-file-path) + + + - [Create local admin accounts using net exe](#create-local-admin-accounts-using-net-exe) @@ -1174,6 +1252,10 @@ All the detections shipped to different Splunk products. Below is a breakdown by +- [Detect Exchange Web Shell](#detect-exchange-web-shell) + + + @@ -1208,6 +1290,8 @@ All the detections shipped to different Splunk products. Below is a breakdown by +- [Detect Mimikatz Using Loaded Images](#detect-mimikatz-using-loaded-images) + @@ -1400,6 +1484,10 @@ All the detections shipped to different Splunk products. Below is a breakdown by +- [Eventvwr UAC Bypass](#eventvwr-uac-bypass) + + + @@ -1428,6 +1516,10 @@ All the detections shipped to different Splunk products. Below is a breakdown by +- [FodHelper UAC Bypass](#fodhelper-uac-bypass) + + + @@ -1444,6 +1536,14 @@ All the detections shipped to different Splunk products. Below is a breakdown by +- [High File Deletion Frequency](#high-file-deletion-frequency) + + + + + +- [High Process Termination Frequency](#high-process-termination-frequency) + @@ -1578,9 +1678,13 @@ All the detections shipped to different Splunk products. Below is a breakdown by +- [Nishang PowershellTCPOneLine](#nishang-powershelltcponeline) -- [Ntdsutil export ntds](#ntdsutil-export-ntds) + + + +- [Ntdsutil Export NTDS](#ntdsutil-export-ntds) @@ -1630,6 +1734,10 @@ All the detections shipped to different Splunk products. Below is a breakdown by +- [Process Deleting Its Process File Path](#process-deleting-its-process-file-path) + + + - [Process Execution via WMI](#process-execution-via-wmi) @@ -1652,6 +1760,10 @@ All the detections shipped to different Splunk products. Below is a breakdown by +- [Ransomware Notes bulk creation](#ransomware-notes-bulk-creation) + + + - [Rare Parent-Child Process Relationship](#rare-parent-child-process-relationship) @@ -1750,6 +1862,10 @@ All the detections shipped to different Splunk products. Below is a breakdown by +- [Resize ShadowStorage volume](#resize-shadowstorage-volume) + + + - [RunDLL Loading DLL By Ordinal](#rundll-loading-dll-by-ordinal) @@ -1758,6 +1874,10 @@ All the detections shipped to different Splunk products. Below is a breakdown by +- [Ryuk Wake on LAN Command](#ryuk-wake-on-lan-command) + + + @@ -1834,9 +1954,21 @@ All the detections shipped to different Splunk products. Below is a breakdown by +- [Suspicious Curl Network Connection](#suspicious-curl-network-connection) +- [Suspicious DLLHost no Command Line Arguments](#suspicious-dllhost-no-command-line-arguments) + + + + + + + + + +- [Suspicious GPUpdate no Command Line Arguments](#suspicious-gpupdate-no-command-line-arguments) @@ -1850,6 +1982,14 @@ All the detections shipped to different Splunk products. Below is a breakdown by +- [Suspicious PlistBuddy Usage](#suspicious-plistbuddy-usage) + + + +- [Suspicious PlistBuddy Usage via OSquery](#suspicious-plistbuddy-usage-via-osquery) + + + - [Suspicious Reg exe Process](#suspicious-reg-exe-process) @@ -1870,7 +2010,19 @@ All the detections shipped to different Splunk products. Below is a breakdown by -- [Suspicious Rundll32 no CommandLine Arguments](#suspicious-rundll32-no-commandline-arguments) +- [Suspicious Rundll32 no Command Line Arguments](#suspicious-rundll32-no-command-line-arguments) + + + +- [Suspicious SQLite3 LSQuarantine Behavior](#suspicious-sqlite3-lsquarantine-behavior) + + + +- [Suspicious Scheduled Task from Public Directory](#suspicious-scheduled-task-from-public-directory) + + + +- [Suspicious SearchProtocolHost no Command Line Arguments](#suspicious-searchprotocolhost-no-command-line-arguments) @@ -1924,6 +2076,10 @@ All the detections shipped to different Splunk products. Below is a breakdown by +- [Unified Messaging Service Spawning a Process](#unified-messaging-service-spawning-a-process) + + + - [Unload Sysmon Filter Driver](#unload-sysmon-filter-driver) @@ -1946,6 +2102,10 @@ All the detections shipped to different Splunk products. Below is a breakdown by +- [W3WP Spawning Shell](#w3wp-spawning-shell) + + + - [WBAdmin Delete System Backups](#wbadmin-delete-system-backups) @@ -1974,6 +2134,8 @@ All the detections shipped to different Splunk products. Below is a breakdown by +- [Windows DisableAntiSpyware Registry](#windows-disableantispyware-registry) + - [Windows Event Log Cleared](#windows-event-log-cleared) @@ -2120,6 +2282,34 @@ All the detections shipped to different Splunk products. Below is a breakdown by + + + + + + + + + + + + + + + + + + + + + + + + + + + + @@ -2151,8 +2341,6 @@ All the detections shipped to different Splunk products. Below is a breakdown by -- [DNS record changed](#dns-record-changed) - @@ -2202,6 +2390,8 @@ All the detections shipped to different Splunk products. Below is a breakdown by + + @@ -2374,6 +2564,8 @@ All the detections shipped to different Splunk products. Below is a breakdown by + + @@ -2406,6 +2598,12 @@ All the detections shipped to different Splunk products. Below is a breakdown by + + + + + + @@ -2558,6 +2756,10 @@ All the detections shipped to different Splunk products. Below is a breakdown by + + + + @@ -2616,6 +2818,8 @@ All the detections shipped to different Splunk products. Below is a breakdown by + + @@ -2639,6 +2843,10 @@ All the detections shipped to different Splunk products. Below is a breakdown by + + + + - [SMB Traffic Spike](#smb-traffic-spike) @@ -2718,6 +2926,22 @@ All the detections shipped to different Splunk products. Below is a breakdown by + + + + + + + + + + + + + + + + @@ -2754,6 +2978,8 @@ All the detections shipped to different Splunk products. Below is a breakdown by + + - [Unusually Long Content-Type Length](#unusually-long-content-type-length) @@ -2795,6 +3021,8 @@ All the detections shipped to different Splunk products. Below is a breakdown by + + @@ -2991,6 +3219,36 @@ All the detections shipped to different Splunk products. Below is a breakdown by + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + @@ -3255,6 +3513,14 @@ All the detections shipped to different Splunk products. Below is a breakdown by + + + + + + + + @@ -3282,6 +3548,8 @@ All the detections shipped to different Splunk products. Below is a breakdown by + + - [No Windows Updates in a time frame](#no-windows-updates-in-a-time-frame) @@ -3444,7 +3712,6 @@ All the detections shipped to different Splunk products. Below is a breakdown by -- [Spectre and Meltdown Vulnerable Systems](#spectre-and-meltdown-vulnerable-systems) @@ -3458,7 +3725,16 @@ All the detections shipped to different Splunk products. Below is a breakdown by -- [Suspicious Email - UBA Anomaly](#suspicious-email---uba-anomaly) + + + + + + + + + + @@ -3468,6 +3744,8 @@ All the detections shipped to different Splunk products. Below is a breakdown by + + - [Suspicious Java Classes](#suspicious-java-classes) @@ -3529,6 +3807,20 @@ All the detections shipped to different Splunk products. Below is a breakdown by + + + + + + + + + + + + + + @@ -3736,6 +4028,36 @@ All the detections shipped to different Splunk products. Below is a breakdown by + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + @@ -4030,6 +4352,14 @@ All the detections shipped to different Splunk products. Below is a breakdown by + + + + + + + + @@ -4162,6 +4492,16 @@ All the detections shipped to different Splunk products. Below is a breakdown by + + + + + + + + + + @@ -4293,15 +4633,29 @@ All the detections shipped to different Splunk products. Below is a breakdown by -- [Web Fraud - Account Harvesting](#web-fraud---account-harvesting) -- [Web Fraud - Anomalous User Clickspeed](#web-fraud---anomalous-user-clickspeed) -- [Web Fraud - Password Sharing Across Accounts](#web-fraud---password-sharing-across-accounts) + + + + + + + + + + + + + + + + + @@ -4376,6 +4730,12 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- #### Required field +* _time + +* eventName + +* sourceIPAddress + #### ATT&CK @@ -4444,6 +4804,12 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- #### Required field +* _time + +* eventName + +* sourceIPAddress + #### ATT&CK @@ -4510,6 +4876,12 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- #### Required field +* _time + +* eventName + +* sourceIPAddress + @@ -4572,6 +4944,12 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- #### Required field +* _time + +* eventName + +* sourceIPAddress + #### ATT&CK @@ -4594,6 +4972,235 @@ This is a strictly behavioral search, so we define "false positive" slightly dif #### Test Dataset +_version_: 1 + + +--- + +### AWS Create Policy Version to allow all resources +This search looks for CloudTrail events where a user created a policy version that allows them to access any resource in their account + +- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: +- **ATT&CK**: [T1078.004](https://attack.mitre.org/techniques/T1078.004/) +- **Last Updated**: 2021-02-22 + +
+ details + +#### Search +``` +`cloudtrail` eventName=CreatePolicyVersion eventSource = iam.amazonaws.com errorCode = success +| spath input=requestParameters.policyDocument output=key_policy_statements path=Statement{} +| mvexpand key_policy_statements +| spath input=key_policy_statements output=key_policy_action_1 path=Action +| search key_policy_action_1 = "*" +| stats count min(_time) as firstTime max(_time) as lastTime values(key_policy_statements) as policy_added by eventName eventSource aws_account_id errorCode userAgent eventID awsRegion userIdentity.principalId user_arn +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +|`aws_create_policy_version_to_allow_all_resources_filter` +``` +#### Associated Analytic Story + +* AWS IAM Privilege Escalation + + +#### How To Implement +You must install splunk AWS add on and Splunk App for AWS. This search works with cloudtrail logs. + +#### Required field + +* _time + +* eventName + +* userAgent + +* errorCode + +* requestParameters.userName + + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1078.004 | Cloud Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | + + +#### Kill Chain Phase + +* Actions on Objectives + + +#### Known False Positives +While this search has no known false positives, it is possible that an AWS admin has legitimately created a policy to allow a user to access all resources. That said, AWS strongly advises against granting full control to all AWS resources + +#### Reference + +* https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws + +* https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/ + + +#### Test Dataset + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_create_policy_version/aws_cloudtrail_events.json + + +_version_: 2 +
+ +--- + +### AWS CreateAccessKey +This search looks for CloudTrail events where a user A who has already permission to create access keys, makes an API call to create access keys for another user B. Attackers have been know to use this technique for Privilege Escalation in case new victim(user B) has more permissions than old victim(user B) + +- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: +- **ATT&CK**: [T1136.003](https://attack.mitre.org/techniques/T1136.003/) +- **Last Updated**: 2021-03-02 + +
+ details + +#### Search +``` +`cloudtrail` eventName = CreateAccessKey userAgent !=console.amazonaws.com errorCode = success +| search userName!=requestParameters.userName +| stats count min(_time) as firstTime max(_time) as lastTime by requestParameters.userName src eventName eventSource aws_account_id errorCode userAgent eventID awsRegion userIdentity.principalId user_arn +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +|`aws_createaccesskey_filter` +``` +#### Associated Analytic Story + +* AWS IAM Privilege Escalation + + +#### How To Implement +You must install splunk AWS add on and Splunk App for AWS. This search works with cloudtrail logs. + +#### Required field + +* _time + +* eventName + +* userAgent + +* errorCode + +* requestParameters.userName + + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1136.003 | Cloud Account | Persistence | + + +#### Kill Chain Phase + +* Actions on Objectives + + +#### Known False Positives +While this search has no known false positives, it is possible that an AWS admin has legitimately created keys for another user. + +#### Reference + +* https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws + +* https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/ + + +#### Test Dataset + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_createaccesskey/aws_cloudtrail_events.json + + +_version_: 1 +
+ +--- + +### AWS CreateLoginProfile +This search looks for CloudTrail events where a user A(victim A) creates a login profile for user B, followed by a AWS Console login event from user B from the same src_ip as user B. This correlated event can be indicative of privilege escalation since both events happened from the same src_ip + +- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: +- **ATT&CK**: [T1136.003](https://attack.mitre.org/techniques/T1136.003/) +- **Last Updated**: 2021-03-02 + +
+ details + +#### Search +``` +`cloudtrail` eventName = CreateLoginProfile +| rename requestParameters.userName as new_login_profile +| table src_ip eventName new_login_profile userName +| join new_login_profile src_ip [ +| search `cloudtrail` eventName = ConsoleLogin +| rename userName as new_login_profile +| stats count values(eventName) min(_time) as firstTime max(_time) as lastTime by eventSource aws_account_id errorCode userAgent eventID awsRegion userIdentity.principalId user_arn new_login_profile src_ip +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)`] +| `aws_createloginprofile_filter` +``` +#### Associated Analytic Story + +* AWS IAM Privilege Escalation + + +#### How To Implement +You must install splunk AWS add on and Splunk App for AWS. This search works with cloudtrail logs. + +#### Required field + +* _time + +* eventName + +* userAgent + +* errorCode + +* requestParameters.userName + + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1136.003 | Cloud Account | Persistence | + + +#### Kill Chain Phase + +* Actions on Objectives + + +#### Known False Positives +While this search has no known false positives, it is possible that an AWS admin has legitimately created a login profile for another user. + +#### Reference + +* https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws + +* https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/ + + +#### Test Dataset + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_createloginprofile/aws_cloudtrail_events.json + + _version_: 1
@@ -4635,6 +5242,18 @@ You must be ingesting your cloud infrastructure logs from your cloud provider. Y #### Required field +* _time + +* Authentication.signature + +* Authentication.vendor_account + +* Authentication.user + +* Authentication.user_role + +* Authentication.src + @@ -4662,7 +5281,7 @@ _version_: 1 ### AWS Detect Users creating keys with encrypt policy without MFA This search provides detection of KMS keys which action kms:Encrypt is accessible for everyone (also outside of your organization). This is an identicator that your account is compromised and the attacker uses the encryption key to compromise another company. -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: - **ATT&CK**: [T1486](https://attack.mitre.org/techniques/T1486/) - **Last Updated**: 2021-01-11 @@ -4695,6 +5314,20 @@ You must install splunk AWS add on and Splunk App for AWS. This search works wit #### Required field +* _time + +* eventName + +* eventSource + +* eventID + +* awsRegion + +* requestParameters.policy + +* userIdentity.principalId + #### ATT&CK @@ -4732,7 +5365,7 @@ _version_: 1 ### AWS Detect Users with KMS keys performing encryption S3 This search provides detection of users with KMS keys performing encryption specifically against S3 buckets. -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: - **ATT&CK**: [T1486](https://attack.mitre.org/techniques/T1486/) - **Last Updated**: 2021-01-11 @@ -4759,6 +5392,22 @@ You must install splunk AWS add on and Splunk App for AWS. This search works wit #### Required field +* _time + +* eventName + +* requestParameters.x-amz-server-side-encryption + +* requestParameters.bucketName + +* requestParameters.x-amz-copy-source + +* requestParameters.key + +* userAgent + +* region + #### ATT&CK @@ -4821,6 +5470,8 @@ You must install Splunk Add-on for Amazon Web Services and Splunk App for AWS. T #### Required field +* _time + @@ -4846,7 +5497,7 @@ _version_: 1 ### AWS Network Access Control List Created with All Open Ports The search looks for CloudTrail events to detect if any network ACLs were created with all the ports open to a specified CIDR. -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: - **ATT&CK**: [T1562.007](https://attack.mitre.org/techniques/T1562.007/) - **Last Updated**: 2021-01-11 @@ -4876,6 +5527,28 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- #### Required field +* _time + +* eventName + +* requestParameters.ruleAction + +* requestParameters.egress + +* requestParameters.aclProtocol + +* requestParameters.portRange.to + +* requestParameters.portRange.from + +* requestParameters.cidrBlock + +* userName + +* userIdentity.principalId + +* userAgent + #### ATT&CK @@ -4909,7 +5582,7 @@ _version_: 2 ### AWS Network Access Control List Deleted Enforcing network-access controls is one of the defensive mechanisms used by cloud administrators to restrict access to a cloud instance. After the attacker has gained control of the AWS console by compromising an admin account, they can delete a network ACL and gain access to the instance from anywhere. This search will query the CloudTrail logs to detect users deleting network ACLs. -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: - **ATT&CK**: [T1562.007](https://attack.mitre.org/techniques/T1562.007/) - **Last Updated**: 2021-01-12 @@ -4936,6 +5609,20 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- #### Required field +* _time + +* eventName + +* requestParameters.egress + +* userName + +* userIdentity.principalId + +* src + +* userAgent + #### ATT&CK @@ -4969,7 +5656,7 @@ _version_: 2 ### AWS SAML Access by Provider User and Principal This search provides specific SAML access from specific Service Provider, user and targeted principal at AWS. This search provides specific information to detect abnormal access or potential credential hijack or forgery, specially in federated environments using SAML protocol inside the perimeter or cloud provider. -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: - **ATT&CK**: [T1078](https://attack.mitre.org/techniques/T1078/) - **Last Updated**: 2021-01-26 @@ -4995,6 +5682,24 @@ You must install splunk AWS add on and Splunk App for AWS. This search works wit #### Required field +* _time + +* eventName + +* requestParameters.principalArn + +* requestParameters.roleArn + +* requestParameters.roleSessionName + +* recipientAccountId + +* responseElements.issuer + +* sourceIPAddress + +* userAgent + #### ATT&CK @@ -5034,7 +5739,7 @@ _version_: 1 ### AWS SAML Update identity provider This search provides detection of updates to SAML provider in AWS. Updates to SAML provider need to be monitored closely as they may indicate possible perimeter compromise of federated credentials, or backdoor access from another cloud provider set by attacker. -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: - **ATT&CK**: [T1078](https://attack.mitre.org/techniques/T1078/) - **Last Updated**: 2021-01-26 @@ -5060,6 +5765,22 @@ You must install splunk AWS add on and Splunk App for AWS. This search works wit #### Required field +* _time + +* eventName + +* eventType + +* requestParameters.sAMLProviderArn + +* userIdentity.sessionContext.sessionIssuer.arn + +* sourceIPAddress + +* userIdentity.accessKeyId + +* userIdentity.principalId + #### ATT&CK @@ -5091,6 +5812,155 @@ Updating a SAML provider or creating a new one may not necessarily be malicious * https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/update_saml_provider/update_saml_provider.json +_version_: 1 + + +--- + +### AWS SetDefaultPolicyVersion +This search looks for CloudTrail events where a user has set a default policy versions. Attackers have been know to use this technique for Privilege Escalation in case the previous versions of the policy had permissions to access more resources than the current version of the policy + +- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: +- **ATT&CK**: [T1078.004](https://attack.mitre.org/techniques/T1078.004/) +- **Last Updated**: 2021-03-02 + +
+ details + +#### Search +``` +`cloudtrail` eventName=SetDefaultPolicyVersion eventSource = iam.amazonaws.com +| stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.policyArn) as policy_arn by src requestParameters.versionId eventName eventSource aws_account_id errorCode userAgent eventID awsRegion userIdentity.principalId user_arn +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `aws_setdefaultpolicyversion_filter` +``` +#### Associated Analytic Story + +* AWS IAM Privilege Escalation + + +#### How To Implement +You must install splunk AWS add on and Splunk App for AWS. This search works with cloudtrail logs. + +#### Required field + +* _time + +* eventName + +* userAgent + +* errorCode + +* requestParameters.userName + +* eventSource + + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1078.004 | Cloud Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | + + +#### Kill Chain Phase + +* Actions on Objectives + + +#### Known False Positives +While this search has no known false positives, it is possible that an AWS admin has legitimately set a default policy to allow a user to access all resources. That said, AWS strongly advises against granting full control to all AWS resources + +#### Reference + +* https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws + +* https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/ + + +#### Test Dataset + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_setdefaultpolicyversion/aws_cloudtrail_events.json + + +_version_: 1 +
+ +--- + +### AWS UpdateLoginProfile +This search looks for CloudTrail events where a user A who has already permission to update login profile, makes an API call to update login profile for another user B . Attackers have been know to use this technique for Privilege Escalation in case new victim(user B) has more permissions than old victim(user B) + +- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: +- **ATT&CK**: [T1136.003](https://attack.mitre.org/techniques/T1136.003/) +- **Last Updated**: 2021-03-02 + +
+ details + +#### Search +``` +`cloudtrail` eventName = UpdateLoginProfile userAgent !=console.amazonaws.com errorCode = success +| search userName!=requestParameters.userName +| stats count min(_time) as firstTime max(_time) as lastTime by requestParameters.userName src eventName eventSource aws_account_id errorCode userAgent eventID awsRegion userName user_arn +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +|`aws_updateloginprofile_filter` +``` +#### Associated Analytic Story + +* AWS IAM Privilege Escalation + + +#### How To Implement +You must install splunk AWS add on and Splunk App for AWS. This search works with cloudtrail logs. + +#### Required field + +* _time + +* eventName + +* userAgent + +* errorCode + +* requestParameters.userName + + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1136.003 | Cloud Account | Persistence | + + +#### Kill Chain Phase + +* Actions on Objectives + + +#### Known False Positives +While this search has no known false positives, it is possible that an AWS admin has legitimately created keys for another user. + +#### Reference + +* https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws + +* https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/ + + +#### Test Dataset + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_updateloginprofile/aws_cloudtrail_events.json + + _version_: 1
@@ -5132,6 +6002,14 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- #### Required field +* _time + +* eventName + +* errorCode + +* userName + #### ATT&CK @@ -5192,6 +6070,14 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- #### Required field +* _time + +* eventName + +* errorCode + +* src_user + #### ATT&CK @@ -5254,6 +6140,14 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- #### Required field +* _time + +* eventName + +* errorCode + +* userName + #### ATT&CK @@ -5312,6 +6206,14 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- #### Required field +* _time + +* eventName + +* errorCode + +* src_user + #### ATT&CK @@ -5381,6 +6283,14 @@ You must be ingesting your cloud infrastructure logs. You also must run the base #### Required field +* _time + +* All_Changes.command + +* All_Changes.user + +* All_Changes.status + #### ATT&CK @@ -5451,6 +6361,18 @@ You must be ingesting your cloud infrastructure logs. You also must run the base #### Required field +* _time + +* All_Changes.object_id + +* All_Changes.action + +* All_Changes.status + +* All_Changes.object_category + +* All_Changes.user + #### ATT&CK @@ -5521,6 +6443,18 @@ You must be ingesting your cloud infrastructure logs. You also must run the base #### Required field +* _time + +* All_Changes.object_id + +* All_Changes.action + +* All_Changes.status + +* All_Changes.object_category + +* All_Changes.user + #### ATT&CK @@ -5590,6 +6524,16 @@ You must be ingesting your cloud infrastructure logs. You also must run the base #### Required field +* _time + +* All_Changes.command + +* All_Changes.object_category + +* All_Changes.status + +* All_Changes.user + #### ATT&CK @@ -5650,6 +6594,22 @@ This search requires Sysmon Logs and a Sysmon configuration, which includes Even #### Required field +* _time + +* EventCode + +* TargetImage + +* CallTrace + +* Computer + +* TargetProcessId + +* SourceImage + +* SourceProcessId + #### ATT&CK @@ -5712,6 +6672,30 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- #### Required field +* _time + +* user.username + +* verb + +* objectRef.resource + +* requestURI + +* source + +* sourceIPs{} + +* responseStatus.reason + +* responseStatus.code + +* userAgent + +* src_ip + +* user.groups{} + #### ATT&CK @@ -5770,6 +6754,28 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- #### Required field +* _time + +* user.username + +* userAgent + +* sourceIPs{} + +* responseStatus.reason + +* source + +* responseStatus.code + +* verb + +* requestURI + +* src_ip + +* user.groups{} + #### ATT&CK @@ -5793,6 +6799,176 @@ Not all unauthenticated requests are malicious, but frequency, UA and source IPs #### Test Dataset +_version_: 1 + + +--- + +### Any Powershell DownloadFile +The following analytic identifies the use of PowerShell downloading a file using `DownloadFile` method. This particular method is utilized in many different PowerShell frameworks to download files and output to disk. Identify the source (IP/domain) and destination file and triage appropriately. If AMSI logging or PowerShell transaction logs are available, review for further details of the implant. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: Endpoint +- **ATT&CK**: [T1059.001](https://attack.mitre.org/techniques/T1059.001/) +- **Last Updated**: 2021-03-01 + +
+ details + +#### Search +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=powershell.exe OR Processes.process_name=pwsh.exe OR Processes.process_name=PowerShell_ISE.exe) Processes.process=*DownloadFile* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `any_powershell_downloadfile_filter` +``` +#### Associated Analytic Story + +* Malicious PowerShell + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. + +#### Required field + +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_name + +* Processes.process_id + +* Processes.parent_process_id + + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1059.001 | PowerShell | Execution | + + +#### Kill Chain Phase + +* Exploitation + + +#### Known False Positives +False positives may be present and filtering will need to occur by parent process or command line argument. It may be required to modify this query to an EDR product for more granular coverage. + +#### Reference + +* https://docs.microsoft.com/en-us/dotnet/api/system.net.webclient.downloadfile?view=net-5.0 + +* https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/ + +* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md + + +#### Test Dataset + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/windows-sysmon.log + + +_version_: 1 +
+ +--- + +### Any Powershell DownloadString +The following analytic identifies the use of PowerShell downloading a file using `DownloadString` method. This particular method is utilized in many different PowerShell frameworks to download files and output to disk. Identify the source (IP/domain) and destination file and triage appropriately. If AMSI logging or PowerShell transaction logs are available, review for further details of the implant. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: Endpoint +- **ATT&CK**: [T1059.001](https://attack.mitre.org/techniques/T1059.001/) +- **Last Updated**: 2021-03-01 + +
+ details + +#### Search +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=powershell.exe OR Processes.process_name=pwsh.exe OR Processes.process_name=PowerShell_ISE.exe Processes.process=*.DownloadString* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `any_powershell_downloadstring_filter` +``` +#### Associated Analytic Story + +* Malicious PowerShell + +* HAFNIUM Group + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. + +#### Required field + +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_name + +* Processes.process_id + +* Processes.parent_process_id + + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1059.001 | PowerShell | Execution | + + +#### Kill Chain Phase + +* Exploitation + + +#### Known False Positives +False positives may be present and filtering will need to occur by parent process or command line argument. It may be required to modify this query to an EDR product for more granular coverage. + +#### Reference + +* https://docs.microsoft.com/en-us/dotnet/api/system.net.webclient.downloadstring?view=net-5.0 + +* https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/ + +* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md + + +#### Test Dataset + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/windows-sysmon.log + + _version_: 1
@@ -5822,6 +6998,8 @@ This detection indicates use of Mimikatz modules that facilitate Pass-the-Token ``` #### Associated Analytic Story +* Credential Dumping + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -5872,6 +7050,8 @@ None identified. #### Test Dataset +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555/applying_stolen_credentials/logAllMimikatzModules.log + _version_: 1 @@ -5883,7 +7063,7 @@ Stolen credentials are applied by methods such as user impersonation, credential - **Product**: UEBA for Security Cloud - **Datamodel**: -- **ATT&CK**: [T1055](https://attack.mitre.org/techniques/T1055/), [T1068](https://attack.mitre.org/techniques/T1068/), [T1078](https://attack.mitre.org/techniques/T1078/), [T1098](https://attack.mitre.org/techniques/T1098/), [T1134](https://attack.mitre.org/techniques/T1134/), [T1543](https://attack.mitre.org/techniques/T1543/), [T1547](https://attack.mitre.org/techniques/T1547/), [T1548](https://attack.mitre.org/techniques/T1548/), [T1554](https://attack.mitre.org/techniques/T1554/), [T1556](https://attack.mitre.org/techniques/T1556/), [T1558](https://attack.mitre.org/techniques/T1558/) +- **ATT&CK**: [T1055](https://attack.mitre.org/techniques/T1055/), [T1068](https://attack.mitre.org/techniques/T1068/), [T1078](https://attack.mitre.org/techniques/T1078/), [T1098](https://attack.mitre.org/techniques/T1098/), [T1134](https://attack.mitre.org/techniques/T1134/), [T1543](https://attack.mitre.org/techniques/T1543/), [T1547](https://attack.mitre.org/techniques/T1547/), [T1548](https://attack.mitre.org/techniques/T1548/), [T1554](https://attack.mitre.org/techniques/T1554/), [T1555](https://attack.mitre.org/techniques/T1555/), [T1558](https://attack.mitre.org/techniques/T1558/) - **Last Updated**: 2020-11-03
@@ -5902,6 +7082,8 @@ Stolen credentials are applied by methods such as user impersonation, credential ``` #### Associated Analytic Story +* Credential Dumping + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -5931,7 +7113,7 @@ You must be ingesting Windows Security logs from devices of interest, including | T1547 | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | | T1548 | Abuse Elevation Control Mechanism | Defense Evasion, Privilege Escalation | | T1554 | Compromise Client Software Binary | Persistence | -| T1556 | Modify Authentication Process | Credential Access, Defense Evasion | +| T1555 | Credentials from Password Stores | Credential Access | | T1558 | Steal or Forge Kerberos Tickets | Credential Access | @@ -5950,6 +7132,8 @@ None identified. #### Test Dataset +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555/applying_stolen_credentials/logAllPowerSploitModulesWithOldNames.log + _version_: 1
@@ -5980,6 +7164,8 @@ This detection identifies use of DSInternals modules that verify password streng ``` #### Associated Analytic Story +* Credential Dumping + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -6030,7 +7216,7 @@ _version_: 1 --- ### Attempt To Add Certificate To Untrusted Store -Attempt to add a certificate to the certificate store +Attempt To Add Certificate To Untrusted Store - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: Endpoint @@ -6059,6 +7245,16 @@ You must be ingesting data that records process activity from your hosts to popu #### Required field +* _time + +* Processes.process + +* Processes.process_name + +* Processes.parent_process + +* Processes.user + #### ATT&CK @@ -6117,12 +7313,24 @@ Monitor for changes of the ExecutionPolicy in the registry to the values "unrest * Credential Dumping +* HAFNIUM Group + #### How To Implement You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Registry node. You must also be ingesting logs with the fields registry_path, registry_key_name, and registry_value_name from your endpoints. #### Required field +* _time + +* Registry.registry_path + +* Registry.registry_key_name + +* Registry.registry_value_name + +* Registry.dest + #### ATT&CK @@ -6187,6 +7395,16 @@ You must be ingesting data that records the file-system activity from your hosts #### Required field +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + #### ATT&CK @@ -6249,6 +7467,14 @@ You must be ingesting endpoint data that tracks process activity, including pare #### Required field +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + #### ATT&CK @@ -6383,6 +7609,18 @@ You must be ingesting endpoint data that tracks process activity, including pare #### Required field +* _time + +* Processes.process_name + +* Processes.process + +* Processes.parent_process_name + +* Processes.dest + +* Processes.user + #### ATT&CK @@ -6447,6 +7685,16 @@ You must be ingesting data that records the file-system activity from your hosts #### Required field +* _time + +* Filesystem.dest + +* Filesystem.file_name + +* Filesystem.user + +* Filesystem.file_path + #### ATT&CK @@ -6472,6 +7720,244 @@ It is possible for this search to generate a notable event for a batch file writ * https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.002/batch_file_in_system32/windows-sysmon.log +_version_: 1 + + +--- + +### CertUtil Download With URLCache and Split Arguments +Certutil.exe may download a file from a remote destination using `-urlcache`. This behavior does require a URL to be passed on the command-line. In addition, `-f` (force) and `-split` (Split embedded ASN.1 elements, and save to files) will be used. It is not entirely common for `certutil.exe` to contact public IP space. However, it is uncommon for `certutil.exe` to write files to world writeable paths.\ During triage, capture any files on disk and review. Review the reputation of the remote IP or domain in question. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: Endpoint +- **ATT&CK**: [T1105](https://attack.mitre.org/techniques/T1105/) +- **Last Updated**: 2021-03-23 + +
+ details + +#### Search +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=certutil.exe Processes.process=*urlcache* Processes.process=*split* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `certutil_download_with_urlcache_and_split_arguments_filter` +``` +#### Associated Analytic Story + +* Ingress Tool Transfer + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. + +#### Required field + +* _time + +* Processes.process + +* Processes.parent_process + +* Processes.process_name + +* Processes.user + +* Processes.dest + + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1105 | Ingress Tool Transfer | Command and Control | + + +#### Kill Chain Phase + +* Exploitation + + +#### Known False Positives +Limited false positives in most environments, however tune as needed based on parent-child relationship or network connection. + +#### Reference + +* https://attack.mitre.org/techniques/T1105/ + +* https://www.avira.com/en/blog/certutil-abused-by-attackers-to-spread-threats + +* https://www.fireeye.com/blog/threat-research/2019/10/certutil-qualms-they-came-to-drop-fombs.html + + +#### Test Dataset + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-sysmon.log + + +_version_: 1 +
+ +--- + +### CertUtil Download With VerifyCtl and Split Arguments +Certutil.exe may download a file from a remote destination using `-VerifyCtl`. This behavior does require a URL to be passed on the command-line. In addition, `-f` (force) and `-split` (Split embedded ASN.1 elements, and save to files) will be used. It is not entirely common for `certutil.exe` to contact public IP space. \ During triage, capture any files on disk and review. Review the reputation of the remote IP or domain in question. Using `-VerifyCtl`, the file will either be written to the current working directory or `%APPDATA%\..\LocalLow\Microsoft\CryptnetUrlCache\Content\`. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: Endpoint +- **ATT&CK**: [T1105](https://attack.mitre.org/techniques/T1105/) +- **Last Updated**: 2021-03-23 + +
+ details + +#### Search +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=certutil.exe Processes.process=*verifyctl* Processes.process=*split* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `certutil_download_with_verifyctl_and_split_arguments_filter` +``` +#### Associated Analytic Story + +* Ingress Tool Transfer + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. + +#### Required field + +* _time + +* Processes.process + +* Processes.parent_process + +* Processes.process_name + +* Processes.user + +* Processes.dest + + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1105 | Ingress Tool Transfer | Command and Control | + + +#### Kill Chain Phase + +* Exploitation + + +#### Known False Positives +Limited false positives in most environments, however tune as needed based on parent-child relationship or network connection. + +#### Reference + +* https://attack.mitre.org/techniques/T1105/ + +* https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/ + +* https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/cc732443(v=ws.11)#-verifyctl + +* https://www.avira.com/en/blog/certutil-abused-by-attackers-to-spread-threats + + +#### Test Dataset + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-sysmon.log + + +_version_: 1 +
+ +--- + +### CertUtil With Decode Argument +CertUtil.exe may be used to `encode` and `decode` a file, including PE and script code. Encoding will convert a file to base64 with `-----BEGIN CERTIFICATE-----` and `-----END CERTIFICATE-----` tags. Malicious usage will include decoding a encoded file that was downloaded. Once decoded, it will be loaded by a parallel process. Note that there are two additional command switches that may be used - `encodehex` and `decodehex`. Similarly, the file will be encoded in HEX and later decoded for further execution. During triage, identify the source of the file being decoded. Review its contents or execution behavior for further analysis. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: Endpoint +- **ATT&CK**: [T1140](https://attack.mitre.org/techniques/T1140/) +- **Last Updated**: 2021-03-23 + +
+ details + +#### Search +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=certutil.exe Processes.process=*decode* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `certutil_with_decode_argument_filter` +``` +#### Associated Analytic Story + +* Deobfuscate-Decode Files or Information + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. + +#### Required field + +* _time + +* Processes.process + +* Processes.parent_process + +* Processes.process_name + +* Processes.user + +* Processes.dest + + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1140 | Deobfuscate/Decode Files or Information | Defense Evasion | + + +#### Kill Chain Phase + +* Exploitation + + +#### Known False Positives +Typically seen used to `encode` files, but it is possible to see legitimate use of `decode`. Filter based on parent-child relationship, file paths, endpoint or user. + +#### Reference + +* https://attack.mitre.org/techniques/T1140/ + +* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1140/T1140.md + +* https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/certutil + +* https://www.bleepingcomputer.com/news/security/certutilexe-could-allow-attackers-to-download-malware-while-bypassing-av/ + + +#### Test Dataset + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1140/atomic_red_team/windows-sysmon.log + + _version_: 1
@@ -6509,6 +7995,16 @@ This search looks for arguments to certutil.exe indicating the manipulation or e #### Required field +* _time + +* Processes.process + +* Processes.process_name + +* Processes.parent_process + +* Processes.user + @@ -6563,6 +8059,22 @@ You must be ingesting endpoint data that tracks process activity, including pare #### Required field +* _time + +* Processes.process_name + +* Processes.process + +* Processes.parent_process_name + +* Processes.process_name + +* Processes.dest + +* Processes.parent_process + +* Processes.user + #### ATT&CK @@ -6628,6 +8140,14 @@ Detailed documentation on how to create a new field within Incident Review may b #### Required field +* _time + +* DNS.dest + +* DNS.message_type + +* DNS.src + #### ATT&CK @@ -6656,6 +8176,161 @@ _version_: 3 --- +### Clop Common Exec Parameter +The following analytics are designed to identifies some CLOP ransomware variant that using arguments to execute its main code or feature of its code. In this variant if the parameter is "runrun", CLOP ransomware will try to encrypt files in network shares and if it is "temp.dat", it will try to read from some stream pipe or file start encrypting files within the infected local machines. This technique can be also identified as an anti-sandbox technique to make its code non-responsive since it is waiting for some parameter to execute properly. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: Endpoint +- **ATT&CK**: [T1204](https://attack.mitre.org/techniques/T1204/) +- **Last Updated**: 2021-03-17 + +
+ details + +#### Search +``` + +| tstats `security_content_summariesonly` values(Processes.process) as cmdline values(Processes.parent_process_name) as parent_process values(Processes.process_name) count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process = "*runrun*" OR Processes.process = "*temp.dat*" by Processes.parent_process_name Processes.process_name Processes.process Processes.dest Processes.user Processes.process_id Processes.process_guid +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `clop_common_exec_parameter_filter` +``` +#### Associated Analytic Story + +* Clop Ransomware + + +#### How To Implement +To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. + +#### Required field + +* Processes.process + +* Processes.parent_process_name + +* _time + +* Processes.process_name + +* Processes.dest + +* Processes.user + +* Processes.process_id + + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1204 | User Execution | Execution | + + +#### Kill Chain Phase + +* Obfuscation + + +#### Known False Positives +Operators can execute third party tools using these parameters. + +#### Reference + +* https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html + +* https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html + + +#### Test Dataset + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_b/windows-sysmon.log + + +_version_: 1 +
+ +--- + +### Clop Ransomware Known Service Name +This detection is to identify the common service name created by the CLOP ransomware as part of its persistence and high privilege code execution in the infected machine. Ussually CLOP ransomware use StartServiceCtrlDispatcherW API in creating this service entry. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: Endpoint +- **ATT&CK**: [T1543](https://attack.mitre.org/techniques/T1543/) +- **Last Updated**: 2021-03-17 + +
+ details + +#### Search +``` +`wineventlog_system` EventCode=7045 Service_Name IN ("SecurityCenterIBM", "WinCheckDRVs") +| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Service_File_Name Service_Name Service_Start_Type Service_Type +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `clop_ransomware_known_service_name_filter` +``` +#### Associated Analytic Story + +* Clop Ransomware + + +#### How To Implement +To successfully implement this search, you need to be ingesting logs with the Service name, Service File Name Service Start type, and Service Type from your endpoints. + +#### Required field + +* EventCode + +* cmdline + +* _time + +* parent_process_name + +* process_name + +* OriginalFileName + +* process_path + + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1543 | Create or Modify System Process | Persistence, Privilege Escalation | + + +#### Kill Chain Phase + +* Privilege Escalation + + +#### Known False Positives +unknown + +#### Reference + +* https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html + +* https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html + + +#### Test Dataset + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-system.log + + +_version_: 1 +
+ +--- + ### Cloud API Calls From Previously Unseen User Roles This search looks for new commands from each user role. @@ -6692,6 +8367,18 @@ You must be ingesting your cloud infrastructure logs from your cloud provider. #### Required field +* _time + +* All_Changes.user + +* All_Changes.user_type + +* All_Changes.status + +* All_Changes.command + +* All_Changes.object + #### ATT&CK @@ -6755,6 +8442,16 @@ You must be ingesting the appropriate cloud-infrastructure logs Run the "Previou #### Required field +* _time + +* All_Changes.object + +* All_Changes.action + +* All_Changes.user + +* All_Changes.vendor_region + #### ATT&CK @@ -6818,6 +8515,16 @@ You must be ingesting your cloud infrastructure logs from your cloud provider. Y #### Required field +* _time + +* All_Changes.object_id + +* All_Changes.action + +* All_Changes.vendor_region + +* All_Changes.user + #### ATT&CK @@ -6885,6 +8592,16 @@ You must be ingesting your cloud infrastructure logs from your cloud provider. Y #### Required field +* _time + +* All_Changes.object_id + +* All_Changes.action + +* All_Changes.Instance_Changes.image_id + +* All_Changes.user + @@ -6944,6 +8661,16 @@ You must be ingesting your cloud infrastructure logs from your cloud provider. Y #### Required field +* _time + +* All_Changes.object_id + +* All_Changes.action + +* All_Changes.Instance_Changes.instance_type + +* All_Changes.user + @@ -7001,6 +8728,20 @@ This search has a dependency on other searches to create and update a baseline o #### Required field +* _time + +* All_Changes.object_id + +* All_Changes.command + +* All_Changes.action + +* All_Changes.change_type + +* All_Changes.status + +* All_Changes.user + #### ATT&CK @@ -7059,6 +8800,24 @@ You must be ingesting your cloud infrastructure logs from your cloud provider. Y #### Required field +* _time + +* eventName + +* userIdentity.arn + +* errorMessage + +* errorCode + +* userAgent + +* src + +* userName + +* arn + @@ -7118,6 +8877,20 @@ You must be ingesting your cloud infrastructure logs from your cloud provider. #### Required field +* _time + +* All_Changes.action + +* All_Changes.status + +* All_Changes.src + +* All_Changes.user + +* All_Changes.object + +* All_Changes.command + #### ATT&CK @@ -7184,6 +8957,20 @@ You must be ingesting your cloud infrastructure logs from your cloud provider. #### Required field +* _time + +* All_Changes.action + +* All_Changes.status + +* All_Changes.src + +* All_Changes.user + +* All_Changes.object + +* All_Changes.command + #### ATT&CK @@ -7248,6 +9035,20 @@ You must be ingesting your cloud infrastructure logs from your cloud provider. #### Required field +* _time + +* All_Changes.object_id + +* All_Changes.action + +* All_Changes.status + +* All_Changes.src + +* All_Changes.user + +* All_Changes.command + #### ATT&CK @@ -7314,6 +9115,20 @@ You must be ingesting your cloud infrastructure logs from your cloud provider. #### Required field +* _time + +* All_Changes.action + +* All_Changes.status + +* All_Changes.src + +* All_Changes.user + +* All_Changes.object + +* All_Changes.command + #### ATT&CK @@ -7338,6 +9153,91 @@ This is a strictly behavioral search, so we define "false positive" slightly dif * https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/suspicious_behaviour/abnormally_high_cloud_instances_launched/cloudtrail_behavioural_detections.json +_version_: 1 + + +--- + +### Cobalt Strike Named Pipes +The following analytic identifies the use of default or publicly known named pipes used with Cobalt Strike. A named pipe is a named, one-way or duplex pipe for communication between the pipe server and one or more pipe clients. Cobalt Strike uses named pipes in many ways and has default values used with the Artifact Kit and Malleable C2 Profiles. The following query assists with identifying these default named pipes. Each EDR product presents named pipes a little different. Consider taking the values and generating a query based on the product of choice. \ +Upon triage, review the process performing the named pipe. If it is explorer.exe, It is possible it was injected into by another process. Review recent parallel processes to identify suspicious patterns or behaviors. A parallel process may have a network connection, review and follow the connection back to identify any file modifications. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: +- **ATT&CK**: [T1055](https://attack.mitre.org/techniques/T1055/) +- **Last Updated**: 2021-02-22 + +
+ details + +#### Search +``` +`sysmon` EventID=17 OR EventID=18 PipeName IN (\\msagent_*, \\wkssvc*, \\DserNamePipe*, \\srvsvc_*, \\mojo.*, \\postex_*, \\status_*, \\MSSE-*, \\spoolss_*, \\win_svc*, \\ntsvcs*, \\winsock*) +| stats count min(_time) as firstTime max(_time) as lastTime by Computer, process_name, process_id process_path, PipeName +| rename Computer as dest +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `cobalt_strike_named_pipes_filter` +``` +#### Associated Analytic Story + +* Cobalt Strike + + +#### How To Implement +To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. + +#### Required field + +* _time + +* EventID + +* PipeName + +* Computer + +* process_name + +* process_path + +* process_id + + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1055 | Process Injection | Defense Evasion, Privilege Escalation | + + +#### Kill Chain Phase + +* Actions on Objectives + + +#### Known False Positives +The idea of using named pipes with Cobalt Strike is to blend in. Therefore, some of the named pipes identified and added may cause false positives. Filter by process name or pipe name to reduce false positives. + +#### Reference + +* https://attack.mitre.org/techniques/T1218/009/ + +* https://docs.microsoft.com/en-us/windows/win32/ipc/named-pipes + +* https://www.cobaltstrike.com/help-smb-beacon + +* https://blog.cobaltstrike.com/2021/02/09/learn-pipe-fitting-for-all-of-your-offense-projects/ + +* https://gist.github.com/MHaggis/6c600e524045a6d49c35291a21e10752 + + +#### Test Dataset + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log + + _version_: 1
@@ -7369,10 +9269,12 @@ The search looks for file modifications with extensions commonly used by Ransomw * SamSam Ransomware -* Ryuk Ransonware +* Ryuk Ransomware * Ransomware +* Clop Ransomware + #### How To Implement You must be ingesting data that records the filesystem activity from your hosts to populate the Endpoint file-system data model node. If you are using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which you want to collect data.\ @@ -7383,6 +9285,16 @@ Detailed documentation on how to create a new field within Incident Review may b #### Required field +* _time + +* Filesystem.user + +* Filesystem.dest + +* Filesystem.file_path + +* Filesystem.file_name + #### ATT&CK @@ -7442,12 +9354,24 @@ The search looks for files created with names matching those typically used in r * Ryuk Ransomware +* Clop Ransomware + #### How To Implement You must be ingesting data that records file-system activity from your hosts to populate the Endpoint Filesystem data-model node. This is typically populated via endpoint detection-and-response product, such as Carbon Black, or via other endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report file-system reads and writes. #### Required field +* _time + +* Filesystem.user + +* Filesystem.dest + +* Filesystem.file_path + +* Filesystem.file_name + #### ATT&CK @@ -7508,6 +9432,20 @@ This search needs Sysmon Logs with a Sysmon configuration, which includes EventC #### Required field +* _time + +* EventID + +* TargetImage + +* Computer + +* EventCode + +* TargetImage + +* TargetProcessId + #### ATT&CK @@ -7535,6 +9473,81 @@ Other tools can access LSASS for legitimate reasons and generate an event. In th * https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon.log +_version_: 1 + + +--- + +### Create Service In Suspicious File Path +This detection is to identify a creation of "user mode service" where the service file path is located in non-common service folder in windows. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: Endpoint +- **ATT&CK**: [T1569.001, T1569.002](https://attack.mitre.org/techniques/T1569.001, T1569.002/) +- **Last Updated**: 2021-03-12 + +
+ details + +#### Search +``` + `wineventlog_system` EventCode=7045 Service_File_Name = "*\.exe" NOT (Service_File_Name IN ("C:\\Windows\\*", "C:\\Program File*", "C:\\Programdata\\*", "%systemroot%\\*")) Service_Type = "user mode service" +| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Service_File_Name Service_Name Service_Start_Type Service_Type +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `create_service_in_suspicious_file_path_filter` +``` +#### Associated Analytic Story + +* Clop Ransomware + + +#### How To Implement +To successfully implement this search, you need to be ingesting logs with the Service name, Service File Name Service Start type, and Service Type from your endpoints. + +#### Required field + +* EventCode + +* Service_File_Name + +* Service_Type + +* _time + +* Service_Name + +* Service_Start_Type + + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| | | | + + +#### Kill Chain Phase + +* Privilege Escalation + + +#### Known False Positives +unknown + +#### Reference + +* https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html + +* https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html + + +#### Test Dataset + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-system.log + + _version_: 1
@@ -7570,6 +9583,18 @@ You must be ingesting data that records process activity from your hosts to popu #### Required field +* _time + +* Processes.user + +* Processes.parent_process + +* Processes.process_name + +* Processes.process + +* Processes.dest + #### ATT&CK @@ -7635,6 +9660,18 @@ You must be ingesting data that records process activity from your hosts to popu #### Required field +* _time + +* Processes.user + +* Processes.parent_process + +* Processs.process_name + +* Processes.process + +* Processes.dest + #### ATT&CK @@ -7697,6 +9734,22 @@ You must be ingesting endpoint data that tracks process activity, including pare #### Required field +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_id + +* Processes.parent_process_id + #### ATT&CK @@ -7759,6 +9812,16 @@ To successfully implement this search you need to be ingesting information on pr #### Required field +* _time + +* Processes.process_name + +* Processes.process + +* Processes.user + +* Processes.dest + #### ATT&CK @@ -7821,6 +9884,18 @@ This search requires Sysmon Logs and a Sysmon configuration, which includes Even #### Required field +* _time + +* EventID + +* process_name + +* TargetFilename + +* Computer + +* object_category + #### ATT&CK @@ -7887,6 +9962,22 @@ You must be ingesting endpoint data that tracks process activity, including pare #### Required field +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_id + +* Processes.parent_process_id + #### ATT&CK @@ -7949,6 +10040,22 @@ You must be ingesting endpoint data that tracks process activity, including pare #### Required field +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_id + +* Processes.parent_process_id + #### ATT&CK @@ -8005,6 +10112,10 @@ Credential extraction is often an illegal recovery of credential material from s ``` #### Associated Analytic Story +* Unusual Processes + +* Credential Dumping + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -8047,6 +10158,8 @@ None identified. #### Test Dataset +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logFgdump.log + _version_: 1 @@ -8077,6 +10190,10 @@ Credential extraction is often an illegal recovery of credential material from s ``` #### Associated Analytic Story +* Unusual Processes + +* Credential Dumping + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -8117,6 +10234,8 @@ None identified. #### Test Dataset +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logFgdump.log + _version_: 1 @@ -8147,6 +10266,8 @@ Credential extraction is often an illegal recovery of credential material from s ``` #### Associated Analytic Story +* Credential Dumping + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -8184,6 +10305,8 @@ None identified. #### Test Dataset +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logLazagneCredDump.log + _version_: 1 @@ -8214,6 +10337,10 @@ Credential extraction is often an illegal recovery of credential material from s ``` #### Associated Analytic Story +* Credential Dumping + +* Malicious PowerShell + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -8258,6 +10385,8 @@ None identified. #### Test Dataset +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllDSInternalsModules.log + _version_: 1 @@ -8288,6 +10417,10 @@ Credential extraction is often an illegal recovery of credential material from s ``` #### Associated Analytic Story +* Credential Dumping + +* Malicious PowerShell + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -8332,6 +10465,8 @@ None identified. #### Test Dataset +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllDSInternalsModules.log + _version_: 1 @@ -8362,6 +10497,10 @@ Credential extraction is often an illegal recovery of credential material from s ``` #### Associated Analytic Story +* Credential Dumping + +* Unusual Processes + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -8400,6 +10539,8 @@ None identified. #### Test Dataset +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllMimikatzModules.log + _version_: 1 @@ -8430,6 +10571,10 @@ Credential extraction is often an illegal recovery of credential material from s ``` #### Associated Analytic Story +* Credential Dumping + +* Malicious PowerShell + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -8468,6 +10613,8 @@ None identified. #### Test Dataset +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllPowerSploitModulesWithOldNames.log + _version_: 1 @@ -8498,6 +10645,10 @@ Credential extraction is often an illegal recovery of credential material from s ``` #### Associated Analytic Story +* Credential Dumping + +* Unusual Processes + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -8540,6 +10691,8 @@ Although unlikely, using debuggers this way may be indicative of developers anal #### Test Dataset +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logLiveKDFullKernelDump.log + _version_: 1 @@ -8570,6 +10723,10 @@ Credential extraction is often an illegal recovery of credential material from s ``` #### Associated Analytic Story +* Credential Dumping + +* Unusual Processes + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -8608,6 +10765,8 @@ Although unlikely, using debuggers this way may be indicative of developers anal #### Test Dataset +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logLiveKDFullKernelDump.log + _version_: 1 @@ -8639,6 +10798,10 @@ Credential extraction is often an illegal recovery of credential material from s ``` #### Associated Analytic Story +* Credential Dumping + +* Malicious PowerShell + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -8675,6 +10838,8 @@ None identified. #### Test Dataset +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logPowerShellModule.log + _version_: 1 @@ -8728,6 +10893,16 @@ Detailed documentation on how to create a new field within Incident Review may b #### Required field +* _time + +* DNS.src + +* DNS.dest + +* DNS.query + +* DNS.record_type + #### ATT&CK @@ -8793,6 +10968,10 @@ To successfully implement this search, you will need to ensure that DNS data is #### Required field +* _time + +* DNS.query + #### ATT&CK @@ -8857,6 +11036,16 @@ To successfully implement this search you will need to ensure that DNS data is p #### Required field +* _time + +* DNS.dest_category + +* DNS.src_category + +* DNS.src + +* DNS.dest + #### ATT&CK @@ -8932,6 +11121,18 @@ If Splunk>Phantom is also configured in your environment, a Playbook called "DNS #### Required field +* _time + +* DNS.record_type + +* DNS.answer + +* DNS.src + +* DNS.message_type + +* DNS.query + #### ATT&CK @@ -8988,12 +11189,28 @@ The vssadmin.exe utility is used to interact with the Volume Shadow Copy Service * Ransomware +* Clop Ransomware + #### How To Implement You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" field in the Endpoint data model. #### Required field +* _time + +* Processes.process + +* Processes.parent_process + +* Processes.process_name + +* Processes.user + +* Processes.parent_process_name + +* Processes.dest + #### ATT&CK @@ -9063,6 +11280,18 @@ Detailed documentation on how to create a new field within Incident Review may b #### Required field +* _time + +* userIdentity.sessionContext.attributes.mfaAuthenticated + +* eventName + +* userIdentity.arn + +* userIdentity.type + +* user + @@ -9113,6 +11342,22 @@ This search uses a standard SPL query on logs from Cisco Network devices. The ne #### Required field +* _time + +* facility + +* mnemonic + +* disable_cause + +* src_int_prefix_long + +* src_int_suffix + +* host + +* src_interface + #### ATT&CK @@ -9190,6 +11435,16 @@ Detailed documentation on how to create a new field within Incident Review may b #### Required field +* _time + +* errorCode + +* userName + +* eventName + +* user + #### ATT&CK @@ -9252,6 +11507,12 @@ You must install and configure the Splunk Add-on for AWS (version 5.1.0 or later #### Required field +* _time + +* Authentication.signature + +* Authentication.user + @@ -9318,6 +11579,14 @@ You must install and configure the Splunk Add-on for AWS (version 5.1.0 or later #### Required field +* _time + +* Authentication.signature + +* Authentication.user + +* Authentication.src + #### ATT&CK @@ -9390,6 +11659,14 @@ You must install and configure the Splunk Add-on for AWS (version 5.1.0 or later #### Required field +* _time + +* Authentication.signature + +* Authentication.user + +* Authentication.src + #### ATT&CK @@ -9462,6 +11739,14 @@ You must install and configure the Splunk Add-on for AWS (version 5.1.0 or later #### Required field +* _time + +* Authentication.signature + +* Authentication.user + +* Authentication.src + #### ATT&CK @@ -9522,6 +11807,20 @@ To successfully implement this search, you must ingest your Windows Security Eve #### Required field +* _time + +* EventCode + +* Logon_Type + +* Logon_Process + +* WorkstationName + +* user + +* dest + #### ATT&CK @@ -9579,6 +11878,8 @@ Splunk Universal Forwarder running on Linux systems, capturing logs from the /va #### Required field +* _time + #### ATT&CK @@ -9638,6 +11939,10 @@ Splunk Universal Forwarder running on Linux systems (tested on Centos and Ubuntu #### Required field +* _time + +* host + #### ATT&CK @@ -9695,6 +12000,10 @@ OSQuery installed and configured to pick up process events (info at https://osqu #### Required field +* _time + +* columns.cmdline + #### ATT&CK @@ -9752,6 +12061,18 @@ This search requires audit computer account management to be enabled on the syst #### Required field +* _time + +* EventCode + +* TargetUserName + +* LogonType + +* TargetDomainName + +* user + #### ATT&CK @@ -9814,6 +12135,24 @@ This search needs Sysmon Logs and a sysmon configuration, which includes EventCo #### Required field +* _time + +* EventCode + +* TargetImage + +* GrantedAccess + +* Computer + +* SourceImage + +* SourceProcessId + +* TargetImage + +* TargetProcessId + #### ATT&CK @@ -9889,6 +12228,18 @@ If Splunk>Phantom is also configured in your environment, a Playbook called `Let #### Required field +* _time + +* DNS.answer + +* DNS.dest + +* DNS.src + +* DNS.query + +* host + #### ATT&CK @@ -10025,6 +12376,16 @@ If Splunk>Phantom is also configured in your environment, a Playbook called "Exc #### Required field +* _time + +* All_Changes.user + +* nodename + +* All_Changes.result + +* All_Changes.dest + #### ATT&CK @@ -10087,6 +12448,14 @@ ou must ingest your Windows security event logs in the `Change` datamodel under #### Required field +* _time + +* All_Changes.result + +* nodename + +* All_Changes.user + #### ATT&CK @@ -10117,6 +12486,84 @@ _version_: 3 --- +### Detect Exchange Web Shell +The following query identifies suspicious .aspx created in 3 paths identified by Microsoft as known drop locations for Exchange exploitation related to HAFNIUM group. Paths include: `\HttpProxy\owa\auth\`, `\inetpub\wwwroot\aspnet_client\`, and `\HttpProxy\OAB\`. Upon triage, the suspicious .aspx file will likely look obvious on the surface. inspect the contents for script code inside. Identify additional log sources, IIS included, to review source and other potential exploitation. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: Endpoint +- **ATT&CK**: [T1505.003](https://attack.mitre.org/techniques/T1505.003/) +- **Last Updated**: 2021-03-09 + +
+ details + +#### Search +``` + +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=System by _time span=1h Processes.process_id Processes.process_name Processes.dest +| `drop_dm_object_name(Processes)` +| join process_guid, _time [ +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*\\HttpProxy\\owa\\auth\\*", "*\\inetpub\\wwwroot\\aspnet_client\\*", "*\\HttpProxy\\OAB\\*") Filesystem.file_name="*.aspx" by _time span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path +| `drop_dm_object_name(Filesystem)` +| fields _time dest file_create_time file_name file_path process_name process_path process] +| dedup file_create_time +| table dest file_create_time, file_name, file_path, process_name +| `detect_exchange_web_shell_filter` +``` +#### Associated Analytic Story + +* HAFNIUM Group + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node and `Filesystem` node. + +#### Required field + +* _time + +* Filesystem.file_path + +* Filesystem.process_id + +* Filesystem.file_name + +* Filesystem.file_hash + +* Filesystem.user + + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1505.003 | Web Shell | Persistence | + + +#### Kill Chain Phase + +* Exploitation + + +#### Known False Positives +The query is structured in a way that `action` (read, create) is not defined. Review the results of this query, filter, and tune as necessary. It may be necessary to generate this query specific to your endpoint product. + +#### Reference + +* https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Sample%20Data/Feeds/MSTICIoCs-ExchangeServerVulnerabilitiesDisclosedMarch2021.csv + + +#### Test Dataset + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1505.003/windows-sysmon_proxylogon.log + + +_version_: 2 +
+ +--- + ### Detect F5 TMUI RCE CVE-2020-5902 This search detects remote code exploit attempts on F5 BIG-IP, BIG-IQ, and Traffix SDC devices @@ -10145,6 +12592,8 @@ To consistently detect exploit attempts on F5 devices using the vulnerabilities #### Required field +* _time + #### ATT&CK @@ -10222,6 +12671,18 @@ This search relies on the Splunk Add-on for Google Cloud Platform, setting up a #### Required field +* _time + +* sc_status_ + +* cs_object_ + +* c_ip_ + +* cs_uri_ + +* cs_method_ + #### ATT&CK @@ -10280,6 +12741,24 @@ To successfully implement this search, you need to be ingesting logs with the pr #### Required field +* _time + +* EventID + +* OriginalFileName + +* process_name + +* Computer + +* User + +* parent_process_name + +* process_path + +* CommandLine + #### ATT&CK @@ -10346,6 +12825,24 @@ To successfully implement this search you need to be ingesting information on pr #### Required field +* _time + +* Processes.parent_process_name + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_name + +* Processes.process + +* Processes.process_id + +* Processes.parent_process_id + #### ATT&CK @@ -10416,6 +12913,22 @@ To successfully implement this search you need to be ingesting information on pr #### Required field +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_id + +* Processes.parent_process_id + #### ATT&CK @@ -10488,6 +13001,20 @@ To successfully implement this search you need to be ingesting information on pr #### Required field +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_id + #### ATT&CK @@ -10562,6 +13089,28 @@ This search uses a standard SPL query on logs from Cisco Network devices. The ne #### Required field +* _time + +* facility + +* mnemonic + +* src_int_prefix_long + +* src_int_suffix + +* dest_int_prefix_long + +* dest_int_suffix + +* src_mac + +* src_vlan + +* vendor_explanation + +* action + #### ATT&CK @@ -10637,6 +13186,8 @@ This search detects a potential kerberoasting attack via service principal name ``` #### Associated Analytic Story +* Credential Dumping + #### How To Implement The test data is converted from Windows Security Event logs generated from Attach Range simulation and used in SPL search and extended to SPL2 @@ -10716,6 +13267,22 @@ In order to run this search effectively, we highly recommend that you leverage t #### Required field +* _time + +* All_Traffic.action + +* All_Traffic.bytes + +* All_Traffic.dest_category + +* All_Traffic.protocol + +* All_Traffic.transport + +* All_Traffic.src_ip + +* All_Traffic.dest_ip + #### ATT&CK @@ -10780,6 +13347,18 @@ To successfully implement this search you need to ingest data from your DNS logs #### Required field +* _time + +* DNS.message_type + +* DNS.record_type + +* DNS.src + +* DNS.dest + +* DNS.answer + #### ATT&CK @@ -10838,6 +13417,18 @@ To successfully implement this search you need to be ingesting information on pr #### Required field +* _time + +* Processes.process + +* Processes.parent_process + +* Processes.process_name + +* Processes.user + +* Processes.dest + #### ATT&CK @@ -10909,6 +13500,18 @@ This search needs Sysmon Logs and a sysmon configuration, which includes EventCo #### Required field +* _time + +* EventCode + +* ImageLoaded + +* ProcessId + +* Computer + +* Image + #### ATT&CK @@ -10924,7 +13527,7 @@ This search needs Sysmon Logs and a sysmon configuration, which includes EventCo #### Known False Positives -Other tools can import the same DLLs. These tools should be part of a whitelist. +Other tools can import the same DLLs. These tools should be part of a whitelist. False positives may be present with any process that authenticates or uses credentials, PowerShell included. Filter based on parent process. #### Reference @@ -10933,6 +13536,8 @@ Other tools can import the same DLLs. These tools should be part of a whitelist. #### Test Dataset +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/windows-sysmon.log + _version_: 1 @@ -10972,6 +13577,18 @@ You must be ingesting Windows Security logs. You must also enable the account ch #### Required field +* _time + +* signature_id + +* Process_Name + +* Message + +* dest + +* Process_ID + #### ATT&CK @@ -11025,12 +13642,24 @@ This search looks for newly created accounts that have been elevated to local ad * DHS Report TA18-074A +* HAFNIUM Group + #### How To Implement You must be ingesting Windows event logs using the Splunk Windows TA and collecting event code 4720 and 4732 #### Required field +* _time + +* EventCode + +* Group_Name + +* member_id + +* dest + #### ATT&CK @@ -11099,6 +13728,14 @@ To successfully implement this search, you must ensure the network router device #### Required field +* _time + +* Authentication.dest_category + +* Authentication.dest + +* Authentication.user + @@ -11156,6 +13793,26 @@ This search relies on the Splunk Add-on for Google Cloud Platform, setting up a #### Required field +* _time + +* data.resource.type + +* data.protoPayload.methodName + +* data.protoPayload.serviceData.policyDelta.bindingDeltas{}.action + +* data.protoPayload.authenticationInfo.principalEmail + +* data.protoPayload.resourceLocation.currentLocations{} + +* data.protoPayload.requestMetadata.callerIp + +* data.protoPayload.resourceName + +* data.protoPayload.serviceData.policyDelta.bindingDeltas{}.role + +* data.protoPayload.serviceData.policyDelta.bindingDeltas{}.member + #### ATT&CK @@ -11187,7 +13844,7 @@ _version_: 1 ### Detect New Open S3 Buckets over AWS CLI This search looks for CloudTrail events where a user has created an open/public S3 bucket over the aws cli. -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: - **ATT&CK**: [T1530](https://attack.mitre.org/techniques/T1530/) - **Last Updated**: 2021-01-12 @@ -11215,6 +13872,30 @@ This search looks for CloudTrail events where a user has created an open/public #### Required field +* _time + +* eventSource + +* eventName + +* requestParameters.accessControlList.x-amz-grant-read-acp + +* requestParameters.accessControlList.x-amz-grant-write + +* requestParameters.accessControlList.x-amz-grant-write-acp + +* requestParameters.accessControlList.x-amz-grant-full-control + +* requestParameters.bucketName + +* userName + +* userIdentity.principalId + +* userAgent + +* bucketName + #### ATT&CK @@ -11248,7 +13929,7 @@ _version_: 1 ### Detect New Open S3 buckets This search looks for CloudTrail events where a user has created an open/public S3 bucket. -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: - **ATT&CK**: [T1530](https://attack.mitre.org/techniques/T1530/) - **Last Updated**: 2021-01-12 @@ -11283,6 +13964,24 @@ You must install the AWS App for Splunk. #### Required field +* _time + +* eventSource + +* eventName + +* requestParameters.bucketName + +* userName + +* userIdentity.principalId + +* userAgent + +* uri + +* permission + #### ATT&CK @@ -11354,6 +14053,20 @@ You must be ingesting data that records filesystem and process activity from you #### Required field +* _time + +* Processes.process_name + +* Processes.parent_process_id + +* Processes.process_id + +* Processes.dest + +* Processes.parent_process_name + +* Processes.user + #### ATT&CK @@ -11410,7 +14123,7 @@ This search looks for outbound SMB connections made by hosts within your network * DHS Report TA18-074A -* Sunburst Malware +* NOBELIUM Group #### How To Implement @@ -11418,6 +14131,22 @@ In order to run this search effectively, we highly recommend that you leverage t #### Required field +* _time + +* All_Traffic.action + +* All_Traffic.app + +* All_Traffic.dest_ip + +* All_Traffic.dest_port + +* sourcetype + +* All_Traffic.dest_category + +* All_Traffic.src_ip + #### ATT&CK @@ -11473,6 +14202,8 @@ This search looks for specific authentication events from the Windows Security E ``` #### Associated Analytic Story +* Lateral Movement + #### How To Implement The test data is converted from Windows Security Event logs generated from Attach Range simulation and used in SPL search and extended to SPL2 @@ -11535,7 +14266,7 @@ The detection Detect Path Interception By Creation Of program exe is detecting t #### Search ``` -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=services.exe by Processes.user Processes.process_name Processes.process Processes.dest index +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=services.exe by Processes.user Processes.process_name Processes.process Processes.dest | `drop_dm_object_name(Processes)` | rex field=process "^.*?\\\\(?[^\\\\]*\.(?:exe |bat @@ -11558,6 +14289,18 @@ You must be ingesting data that records process activity from your hosts to popu #### Required field +* _time + +* Processes.parent_process_name + +* Processes.user + +* Processes.process_name + +* Processes.process + +* Processes.dest + #### ATT&CK @@ -11620,6 +14363,28 @@ This search uses a standard SPL query on logs from Cisco Network devices. The ne #### Required field +* _time + +* facility + +* mnemonic + +* disable_cause + +* src_int_prefix_long + +* src_int_suffix + +* src_mac + +* src_vlan + +* action + +* host + +* src_interface + #### ATT&CK @@ -11685,7 +14450,7 @@ This search looks for executions of cmd.exe spawned by a process that is often a * Suspicious Zoom Child Processes -* Sunburst Malware +* NOBELIUM Group #### How To Implement @@ -11693,6 +14458,18 @@ You must be ingesting data that records process activity from your hosts and pop #### Required field +* _time + +* Processes.process + +* Processes.process_name + +* Processes.parent_process_name + +* Processes.dest + +* Processes.user + #### ATT&CK @@ -11751,6 +14528,14 @@ This search looks for executions of cmd.exe spawned by a process that is often a ``` #### Associated Analytic Story +* Suspicious Command-Line Executions + +* Suspicious MSHTA Activity + +* Suspicious Zoom Child Processes + +* Sunburst Malware + #### How To Implement You must be ingesting sysmon logs. This search has been modified to process raw sysmon data from attack_range's nxlogs on DSP. @@ -11821,12 +14606,24 @@ This search looks for events where `PsExec.exe` is run with the `accepteula` fla * DHS Report TA18-074A +* HAFNIUM Group + #### How To Implement You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. #### Required field +* _time + +* Processes.process + +* Processes.process_name + +* Processes.dest + +* Processes.parent_process_name + #### ATT&CK @@ -11898,6 +14695,14 @@ To successfully implement this search, you must be ingesting data that records p #### Required field +* _time + +* Processes.dest + +* Processes.user + +* Processes.process_name + @@ -11954,6 +14759,22 @@ To successfully implement this search you need to be ingesting information on pr #### Required field +* _time + +* Processes.parent_process_name + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process + +* Processes.process_id + +* Processes.parent_process_id + #### ATT&CK @@ -12022,6 +14843,24 @@ To successfully implement this search, you need to be ingesting logs with the pr #### Required field +* _time + +* EventID + +* dest_ip + +* process_name + +* Computer + +* User + +* src_ip + +* dest_host + +* dest_ip + #### ATT&CK @@ -12089,6 +14928,28 @@ To successfully implement this search, you need to be ingesting logs with the pr #### Required field +* _time + +* EventID + +* process_name + +* OriginalFileName + +* CommandLine + +* dest + +* User + +* ParentImage + +* ParentCommandLine + +* process_path + +* Computer + #### ATT&CK @@ -12155,6 +15016,24 @@ To successfully implement this search you need to be ingesting information on pr #### Required field +* _time + +* Processes.parent_process_name + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_name + +* Processes.process + +* Processes.process_id + +* Processes.parent_process_id + #### ATT&CK @@ -12221,6 +15100,22 @@ To successfully implement this search, you need to be ingesting logs with the pr #### Required field +* _time + +* EventID + +* dest_ip + +* process_name + +* Computer + +* User + +* src_ip + +* dest_host + #### ATT&CK @@ -12288,6 +15183,30 @@ To successfully implement this search, you need to be ingesting logs with the pr #### Required field +* _time + +* EventID + +* process_name + +* OriginalFileName + +* CommandLine + +* dest + +* User + +* ParentImage + +* ParentCommandLine + +* OriginalFileName + +* process_path + +* Computer + #### ATT&CK @@ -12349,12 +15268,30 @@ Upon investigating, look for network connections to remote destinations (interna * Suspicious Regsvr32 Activity +* Cobalt Strike + #### How To Implement You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints, to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" field in the Endpoint data model. Tune the query by modifying/removing the !=regsv32.exe. #### Required field +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_id + +* Processes.parent_process_id + #### ATT&CK @@ -12422,6 +15359,18 @@ This search uses a standard SPL query on logs from Cisco Network devices. The ne #### Required field +* _time + +* facility + +* mnemonic + +* message_type + +* src_mac + +* host + #### ATT&CK @@ -12486,6 +15435,16 @@ To successfully implement this search you need to be ingesting information on pr #### Required field +* _time + +* Processes.process_name + +* Processes.process + +* Processes.user + +* Processes.dest + #### ATT&CK @@ -12556,6 +15515,16 @@ To successfully implement this search you need to be ingesting information on pr #### Required field +* _time + +* Processes.process + +* Processes.process_name + +* Processes.user + +* Processes.dest + #### ATT&CK @@ -12626,6 +15595,16 @@ To successfully implement this search you need to be ingesting information on pr #### Required field +* _time + +* Processes.process + +* Processes.process_name + +* Processes.user + +* Processes.dest + #### ATT&CK @@ -12690,12 +15669,28 @@ The following analytic identifies "rundll32.exe" execution with inline protocol * Suspicious MSHTA Activity +* NOBELIUM Group + #### How To Implement To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. #### Required field +* _time + +* Processes.process + +* Processes.process_name + +* Processes.user + +* Processes.dest + +* Processes.parent_process_name + +* Processes.parent_process + #### ATT&CK @@ -12770,6 +15765,14 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- #### Required field +* _time + +* http_status + +* bucket_name + +* remote_ip + #### ATT&CK @@ -12838,6 +15841,14 @@ You must be ingesting Zeek SSL data into Splunk. Zeek data should also be gettin #### Required field +* _time + +* server_name + +* src_ip + +* dest_ip + #### ATT&CK @@ -12902,6 +15913,20 @@ This search looks for Network Traffic events to TFTP, FTP or SSH/SCP ports from #### Required field +* _time + +* All_Traffic.transport + +* All_Traffic.dest_port + +* All_Traffic.dest_category + +* All_Traffic.src_category + +* All_Traffic.src + +* All_Traffic.dest + #### ATT&CK @@ -12980,6 +16005,12 @@ Detailed documentation on how to create a new field within Incident Review may b #### Required field +* _time + +* eventType + +* userIdentity.arn + #### ATT&CK @@ -13011,7 +16042,7 @@ _version_: 2 ### Detect Spike in AWS Security Hub Alerts for EC2 Instance This search looks for a spike in number of of AWS security Hub alerts for an EC2 instance in 4 hours intervals -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: - **ATT&CK**: - **Last Updated**: 2021-01-26 @@ -13041,6 +16072,22 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- #### Required field +* _time + +* Resources{}.Type + +* Title + +* Types{} + +* vendor_account + +* vendor_region + +* severity + +* dest + @@ -13097,6 +16144,14 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- #### Required field +* _time + +* findings{}.Resources{}.Type + +* indings{}.Resources{}.Id + +* user + @@ -13161,6 +16216,10 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- #### Required field +* _time + +* userIdentity.arn + #### ATT&CK @@ -13234,6 +16293,12 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- #### Required field +* _time + +* eventName + +* userIdentity.arn + #### ATT&CK @@ -13306,6 +16371,10 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- #### Required field +* _time + +* serIdentity.arn + #### ATT&CK @@ -13379,6 +16448,14 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- #### Required field +* _time + +* action + +* src_ip + +* dest_ip + @@ -13432,6 +16509,14 @@ This search uses a standard SPL query on logs from Cisco Network devices. The ne #### Required field +* _time + +* facility + +* mnemonic + +* host + #### ATT&CK @@ -13494,6 +16579,16 @@ To successfully implement this search, you must ingest Windows Security Event lo #### Required field +* _time + +* All_Changes.result + +* All_Changes.result_id + +* All_Changes.src_priority + +* All_Changes.dest + @@ -13552,6 +16647,14 @@ This search uses the Network_Sessions data model shipped with Enterprise Securit #### Required field +* _time + +* All_Sessions.signature + +* All_Sessions.src_ip + +* All_Sessions.dest_mac + @@ -13610,6 +16713,20 @@ To successfully implement this search, you must be ingesting data that records p #### Required field +* _time + +* Processes.process + +* Processes.parent_process_name + +* Processes.process_name + +* Processes.parent_process + +* Processes.user + +* Processes.dest + #### ATT&CK @@ -13674,6 +16791,8 @@ You must be ingesting Splunk Stream DNS and Splunk Stream TCP. We are detecting #### Required field +* _time + #### ATT&CK @@ -13738,6 +16857,16 @@ You must be ingesting Zeek DNS and Zeek Conn data into Splunk. Zeek data should #### Required field +* _time + +* DNS.query_type + +* DNS.flow_id + +* All_Traffic.bytes_in + +* All_Traffic.flow_id + #### ATT&CK @@ -13797,6 +16926,10 @@ You must be ingesting Zeek DCE-RPC data into Splunk. Zeek data should also be ge #### Required field +* _time + +* operation + #### ATT&CK @@ -13863,6 +16996,16 @@ You must be ingesting data from the web server or network traffic that contains #### Required field +* _time + +* Web.http_method + +* Web.url + +* Web.src + +* Web.dest + #### ATT&CK @@ -13937,6 +17080,14 @@ Detailed documentation on how to create a new field within Incident Review may b #### Required field +* _time + +* DNS.answer + +* DNS.query + +* host + #### ATT&CK @@ -14003,6 +17154,18 @@ You must ingest data from the web server or capture network data that contains w #### Required field +* _time + +* Web.http_method + +* Web.url + +* Web.url_length + +* Web.src + +* Web.dest + @@ -14055,6 +17218,20 @@ To successfully implement this search you need to be ingesting information on pr #### Required field +* _time + +* Processes.process + +* Processes.parent_process + +* Processes.user + +* Processes.process_name + +* Processes.parent_process_name + +* Processes.dest + #### ATT&CK @@ -14121,6 +17298,24 @@ To successfully implement this search, you need to be ingesting logs with the pr #### Required field +* _time + +* EventID + +* OriginalFileName + +* process_name + +* Computer + +* User + +* parent_process_name + +* process_path + +* CommandLine + #### ATT&CK @@ -14147,7 +17342,7 @@ Although unlikely, some legitimate applications may use a moved copy of mshta.ex #### Test Dataset -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127.001/windows-sysmon.log +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-sysmon.log _version_: 1 @@ -14194,6 +17389,18 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- #### Required field +* _time + +* eventType + +* errorCode + +* userIdentity.type + +* userName + +* eventName + #### ATT&CK @@ -14254,6 +17461,12 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- #### Required field +* _time + +* eventName + +* userIdentity.arn + #### ATT&CK @@ -14316,6 +17529,18 @@ You must be ingesting data that records registry activity from your hosts to pop #### Required field +* _time + +* Processes.process + +* Processes.parent_process + +* Processes.dest + +* Processes.process_name + +* Processes.user + #### ATT&CK @@ -14382,6 +17607,16 @@ Detailed documentation on how to create a new field within Incident Review may b #### Required field +* _time + +* Web.url + +* Web.status + +* Web.src + +* Web.dest + #### ATT&CK @@ -14453,6 +17688,16 @@ To successfully implement this search, we must ensure that DNS data is being ing #### Required field +* _time + +* DNS.query + +* DNS.message_type + +* DNS.src_category + +* DNS.src + #### ATT&CK @@ -14513,6 +17758,16 @@ You must be ingesting endpoint data that tracks process activity, including pare #### Required field +* _time + +* Processes.process + +* Processes.parent_process + +* Processes.process_name + +* Processes.user + #### ATT&CK @@ -14573,6 +17828,20 @@ To successfully implement this search, you must be ingesting data that records r #### Required field +* _time + +* Registry.registry_path + +* Registry.registry_value_name + +* Registry.dest + +* Registry.registry_key_name + +* Registry.user + +* Registry.action + #### ATT&CK @@ -14629,12 +17898,24 @@ Detect the usage of comsvcs.dll for dumping the lsass process. * Suspicious Rundll32 Activity +* HAFNIUM Group + #### How To Implement You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints, to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" field in the Endpoint data model. #### Required field +* _time + +* Processes.process_name + +* Processes.process + +* Processes.user + +* Processes.dest + #### ATT&CK @@ -14684,7 +17965,7 @@ During triage, confirm this is procdump.exe executing. If it is the first time a #### Search ``` -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=procdump.exe (Processes.process=*-ma* OR Processes.process=*-mm*) Processes.process=*lsass* by Processes.user Processes.process_name Processes.process Processes.dest +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=procdump.exe OR Processes.process_name=procdump64.exe (Processes.process=*-ma* OR Processes.process=*-mm*) Processes.process=*lsass* by Processes.user Processes.process_name Processes.process Processes.dest | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` @@ -14694,12 +17975,24 @@ During triage, confirm this is procdump.exe executing. If it is the first time a * Credential Dumping +* HAFNIUM Group + #### How To Implement To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. #### Required field +* _time + +* Processes.process_name + +* Processes.process + +* Processes.user + +* Processes.dest + #### ATT&CK @@ -14761,12 +18054,28 @@ During triage, confirm this is procdump.exe executing. If it is the first time a * Credential Dumping +* HAFNIUM Group + #### How To Implement To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. #### Required field +* _time + +* OriginalFileName + +* process_name + +* EventID + +* CommandLine + +* Computer + +* parent_process_name + #### ATT&CK @@ -14843,6 +18152,12 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- #### Required field +* _time + +* errorCode + +* userIdentity.arn + #### ATT&CK @@ -14905,6 +18220,10 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- #### Required field +* _time + +* awsRegion + #### ATT&CK @@ -14972,6 +18291,14 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- #### Required field +* _time + +* eventName + +* errorCode + +* requestParameters.instancesSet.items{}.imageId + @@ -15033,6 +18360,14 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- #### Required field +* _time + +* eventName + +* errorCode + +* requestParameters.instanceType + @@ -15094,6 +18429,14 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- #### Required field +* _time + +* eventName + +* errorCode + +* userIdentity.arn + #### ATT&CK @@ -15157,6 +18500,18 @@ If Splunk Phantom is also configured in your environment, a playbook called "Sus #### Required field +* _time + +* All_Email.recipient + +* All_Email.file_name + +* All_Email.src_user + +* All_Email.file_name + +* All_Email.message_id + @@ -15209,6 +18564,18 @@ To successfully implement this search, you must be ingesting data that records t #### Required field +* _time + +* Filesystem.file_path + +* Filesystem.file_name + +* Filesystem.action + +* Filesystem.process_id + +* Filesystem.dest + #### ATT&CK @@ -15265,12 +18632,22 @@ This search looks for an increase of data transfers from your email server to yo * Collection and Staging +* HAFNIUM Group + #### How To Implement This search requires you to be ingesting your network traffic and populating the Network_Traffic data model. Your email servers must be categorized as "email_server" for the search to work, as well. You may need to adjust the deviation_threshold and minimum_data_samples values based on the network traffic in your environment. The "deviation_threshold" field is a multiplying factor to control how much variation you're willing to tolerate. The "minimum_data_samples" field is the minimum number of connections of data samples required for the statistic to be valid. #### Required field +* _time + +* All_Traffic.bytes_out + +* All_Traffic.src_category + +* All_Traffic.dest_ip + #### ATT&CK @@ -15299,6 +18676,88 @@ _version_: 2 --- +### Eventvwr UAC Bypass +The following search identifies Eventvwr bypass by identifying the registry modification into a specific path that eventvwr.msc looks to (but is not valid) upon execution. A successful attack will include a suspicious command to be executed upon eventvwr.msc loading. Upon triage, review the parallel processes that have executed. Identify any additional registry modifications on the endpoint that may look suspicious. Remediate as necessary. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: Endpoint +- **ATT&CK**: [T1548.002](https://attack.mitre.org/techniques/T1548.002/) +- **Last Updated**: 2021-03-01 + +
+ details + +#### Search +``` + +| tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*mscfile\\shell\\open\\command\\*" by Registry.user, Registry.dest , Registry.registry_value_name +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` +| `drop_dm_object_name(Registry)` +| `eventvwr_uac_bypass_filter` +``` +#### Associated Analytic Story + +* Windows Defense Evasion Tactics + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. + +#### Required field + +* _time + +* Registry.registry_key_name + +* Registry.registry_path + +* Registry.user + +* Registry.dest + +* Registry.registry_value_name + + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1548.002 | Bypass User Account Control | Defense Evasion, Privilege Escalation | + + +#### Kill Chain Phase + +* Exploitation + +* Privilege Escalation + + +#### Known False Positives +Some false positives may be present and will need to be filtered. + +#### Reference + +* https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/ + +* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1548.002/T1548.002.md + +* https://attack.mitre.org/techniques/T1548/002 + +* https://enigma0x3.net/2016/08/15/fileless-uac-bypass-using-eventvwr-exe-and-registry-hijacking/ + + +#### Test Dataset + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.002/atomic_red_team/windows-sysmon.log + + +_version_: 1 +
+ +--- + ### Excessive DNS Failures This search identifies DNS query failures by counting the number of DNS responses that do not indicate success, and trigger on more than 50 occurrences. @@ -15336,6 +18795,14 @@ To successfully implement this search you must ensure that DNS data is populatin #### Required field +* _time + +* DNS.query + +* DNS.reply_code + +* DNS.src + #### ATT&CK @@ -15394,6 +18861,18 @@ To successfully implement this search, you must be ingesting data that records p #### Required field +* _time + +* Processes.process_path + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.process_name + #### ATT&CK @@ -15452,6 +18931,16 @@ To successfully implement this search, you must be ingesting data that records p #### Required field +* _time + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + #### ATT&CK @@ -15514,6 +19003,12 @@ To successfully implement this search you need to first obtain data from your ba #### Required field +* _time + +* MESSAGE + +* COMPUTERNAME + @@ -15566,6 +19061,16 @@ You must be ingesting data that records file-system activity from your hosts to #### Required field +* _time + +* Filesystem.user + +* Filesystem.dest + +* Filesystem.file_path + +* Filesystem.file_name + @@ -15622,6 +19127,22 @@ You must be ingesting data that records process activity from your hosts to popu #### Required field +* _time + +* Processes.parent_process_name + +* Processes.parent_process_id + +* Processes.process_name + +* Processes.process + +* Processes.parent_process_name + +* Processes.process_id + +* Processes.dest + #### ATT&CK @@ -15679,7 +19200,7 @@ This search looks for the first and last time a Windows service is seen running * Orangeworm Attack Group -* Sunburst Malware +* NOBELIUM Group #### How To Implement @@ -15687,6 +19208,14 @@ While this search does not require you to adhere to Splunk CIM, you must be inge #### Required field +* _time + +* EventCode + +* Message + +* dest + #### ATT&CK @@ -15745,6 +19274,8 @@ This search looks for command-line arguments that use a `/c` parameter to execut ``` #### Associated Analytic Story +* Unusual Processes + #### How To Implement You must be populating the endpoint data model for SSA and specifically the process_name and the process fields @@ -15842,6 +19373,16 @@ You must be ingesting data that records process activity from your hosts to popu #### Required field +* _time + +* Processes.process_name + +* Processes.process + +* Processes.parent_process_name + +* Processes.dest + #### ATT&CK @@ -15873,6 +19414,99 @@ _version_: 5 --- +### FodHelper UAC Bypass +Fodhelper.exe has a known UAC bypass as it attempts to look for specific registry keys upon execution, that do not exist. Therefore, an attacker can write its malicious commands in these registry keys to be executed by fodhelper.exe with the highest privilege. \ +1. `HKCU:\Software\Classes\ms-settings\shell\open\command`\ +1. `HKCU:\Software\Classes\ms-settings\shell\open\command\DelegateExecute`\ +1. `HKCU:\Software\Classes\ms-settings\shell\open\command\(default)`\ +Upon triage, fodhelper.exe will have a child process and read access will occur on the registry keys. Isolate the endpoint and review parallel processes for additional behavior. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: Endpoint +- **ATT&CK**: [T1112](https://attack.mitre.org/techniques/T1112/), [T1548.002](https://attack.mitre.org/techniques/T1548.002/) +- **Last Updated**: 2021-03-01 + +
+ details + +#### Search +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=fodhelper.exe by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `fodhelper_uac_bypass_filter` +``` +#### Associated Analytic Story + +* Windows Defense Evasion Tactics + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. + +#### Required field + +* _time + +* Processes.parent_process_name + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_name + +* Processes.process + +* Processes.process_id + +* Processes.parent_process_id + + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1112 | Modify Registry | Defense Evasion | +| T1548.002 | Bypass User Account Control | Defense Evasion, Privilege Escalation | + + +#### Kill Chain Phase + +* Exploitation + +* Privilege Escalation + + +#### Known False Positives +Limited to no false positives are expected. + +#### Reference + +* https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/ + +* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1548.002/T1548.002.md + +* https://github.com/gushmazuko/WinBypass/blob/master/FodhelperBypass.ps1 + +* https://attack.mitre.org/techniques/T1548/002 + + +#### Test Dataset + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.002/atomic_red_team/windows-sysmon.log + + +_version_: 1 +
+ +--- + ### GCP Detect accounts with high risk roles by project This search provides detection of accounts with high risk roles by projects. Compromised accounts with high risk roles can move laterally or even scalate privileges at different projects depending on organization schema. @@ -15900,6 +19534,20 @@ You must install splunk GCP add-on. This search works with gcp:pubsub:message lo #### Required field +* _time + +* data.protoPayload.request.policy.bindings{}.role + +* data.resource.type data.protoPayload.authenticationInfo.principalEmail + +* data.protoPayload.authorizationInfo{}.permission + +* data.protoPayload.authorizationInfo{}.resource + +* data.protoPayload.response.bindings{}.role + +* data.protoPayload.response.bindings{}.members{} + #### ATT&CK @@ -15961,6 +19609,24 @@ You must install splunk GCP add-on. This search works with gcp:pubsub:message lo #### Required field +* _time + +* data.protoPayload.request.function.timeout + +* src + +* src_user + +* data.resource.labels.project_id + +* data.protoPayload.request.function.serviceAccountEmail + +* data.protoPayload.authorizationInfo{}.permission + +* data.protoPayload.request.location + +* http_user_agent + #### ATT&CK @@ -16020,6 +19686,20 @@ You must install splunk GCP add-on. This search works with gcp:pubsub:message lo #### Required field +* _time + +* data.protoPayload.authorizationInfo{}.permission + +* data.protoPayload.requestMetadata.callerIp + +* data.protoPayload.authenticationInfo.principalEmail + +* data.protoPayload.authorizationInfo{}.permission + +* data.protoPayload.response.bindings{}.members{} + +* data.resource.labels.project_id + #### ATT&CK @@ -16082,6 +19762,8 @@ You must install the GCP App for Splunk (version 2.0.0 or later), then configure #### Required field +* _time + #### ATT&CK @@ -16137,6 +19819,24 @@ You must install the GCP App for Splunk (version 2.0.0 or later), then configure #### Required field +* _time + +* category + +* responseStatus.code + +* sourceIPs{} + +* userAgent + +* verb + +* requestURI + +* responseStatus.reason + +* properties.pod + #### ATT&CK @@ -16196,6 +19896,8 @@ You must install the GCP App for Splunk (version 2.0.0 or later), then configure #### Required field +* _time + #### ATT&CK @@ -16256,6 +19958,18 @@ You must be ingesting data that records process activity from your hosts to popu #### Required field +* _time + +* Processes.process + +* Processes.process_name + +* Processes.parent_process + +* Processes.user + +* Processes.dest + #### ATT&CK @@ -16286,6 +20000,84 @@ _version_: 4 --- +### High File Deletion Frequency +This search looks for high frequency of file deletion relative to process name and process id. These events usually happen when the ransomware tries to encrypt the files with the ransomware file extensions and sysmon treat the original files to be deleted as soon it was replace as encrypted data. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: Endpoint +- **ATT&CK**: [T1485](https://attack.mitre.org/techniques/T1485/) +- **Last Updated**: 2021-03-16 + +
+ details + +#### Search +``` +`sysmon` EventCode=23 TargetFilename IN ("*\.cmd", "*\.ini","*\.gif", "*\.jpg", "*\.jpeg", "*\.db", "*\.ps1", "*\.doc*", "*\.xls*", "*\.ppt*", "*\.bmp","*\.zip", "*\.rar", "*\.7z", "*\.chm", "*\.png", "*\.log", "*\.vbs", "*\.js") +| stats values(TargetFilename) as deleted_files min(_time) as firstTime max(_time) as lastTime count by Computer user EventCode Image ProcessID +|where count >=100 +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `high_file_deletion_frequency_filter` +``` +#### Associated Analytic Story + +* Clop Ransomware + + +#### How To Implement +To successfully implement this search, you need to be ingesting logs with the deleted target file name, process name and process id from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. + +#### Required field + +* EventCode + +* TargetFilename + +* Computer + +* user + +* Image + +* ProcessID + +* _time + + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1485 | Data Destruction | Impact | + + +#### Kill Chain Phase + +* Exploitation + + +#### Known False Positives +user may delete bunch of pictures or files in a folder. + +#### Reference + +* https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html + +* https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html + + +#### Test Dataset + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log + + +_version_: 1 +
+ +--- + ### High Number of Login Failures from a single source This search will detect more than 5 login failures in Office365 Azure Active Directory from a single source IP address. Please adjust the threshold value of 5 as suited for your environment. @@ -16314,6 +20106,28 @@ This search will detect more than 5 login failures in Office365 Azure Active Dir #### Required field +* _time + +* Operation + +* record_type + +* app + +* user + +* LogonError + +* authentication_method + +* signature + +* UserAgent + +* src_ip + +* record_type + #### ATT&CK @@ -16337,6 +20151,81 @@ unknown #### Test Dataset +_version_: 1 + + +--- + +### High Process Termination Frequency +This analytics are designed to indentify a high frequency of process termination on a machine which is a common behavior of ransomware malware before encrypting files. This technique is designed to avoid an exception error while accessing (docs, images, database and etc..) in the infected machine for encryption. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: Endpoint +- **ATT&CK**: [T1486](https://attack.mitre.org/techniques/T1486/) +- **Last Updated**: 2021-03-16 + +
+ details + +#### Search +``` +`sysmon` EventCode=5 +|bin _time span=3s +|stats values(Image) as proc_terminated min(_time) as firstTime max(_time) as lastTime count by Computer EventCode ProcessID +| where count >= 15 +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `high_process_termination_frequency_filter` +``` +#### Associated Analytic Story + +* Clop Ransomware + + +#### How To Implement +To successfully implement this search, you need to be ingesting logs with the Image (process full path of terminated process) from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. + +#### Required field + +* EventCode + +* Image + +* Computer + +* _time + +* ProcessID + + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1486 | Data Encrypted for Impact | Impact | + + +#### Kill Chain Phase + +* Exploitation + + +#### Known False Positives +admin or user tool that can terminate multiple process. + +#### Reference + +* https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html + +* https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html + + +#### Test Dataset + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log + + _version_: 1
@@ -16376,6 +20265,14 @@ This search requires you to be ingesting your network traffic and populating the #### Required field +* _time + +* All_Traffic.bytes_in + +* All_Traffic.dest_category + +* All_Traffic.src_ip + #### ATT&CK @@ -16436,6 +20333,8 @@ To successfully implement this search, you need to be populating the Enterprise #### Required field +* _time + #### ATT&CK @@ -16486,6 +20385,8 @@ This detection identifies access to PowerSploit modules that enable illegaly acc ``` #### Associated Analytic Story +* Malicious PowerShell + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -16527,6 +20428,8 @@ None identified. #### Test Dataset +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021/illegal_access_to_content/logAllPowerSploitModulesWithOldNames.log + _version_: 1 @@ -16557,6 +20460,8 @@ This detection identifies access to PowerSploit modules that create accounts ill ``` #### Associated Analytic Story +* Windows Persistence Techniques + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -16595,6 +20500,8 @@ None identified. #### Test Dataset +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1585/illegal_account_creation/logAllPowerSploitModulesWithOldNames.log + _version_: 1 @@ -16625,6 +20532,8 @@ This detection identifies access to PowerSploit modules that delete event logs. ``` #### Associated Analytic Story +* Windows Log Manipulation + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -16663,6 +20572,8 @@ None identified. #### Test Dataset +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070/illegal_log_deletion/logAllMimikatzModules.log + _version_: 1 @@ -16693,6 +20604,8 @@ This detection identifies use of DSInternals modules that enable or disable acco ``` #### Associated Analytic Story +* Windows Persistence Techniques + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -16732,6 +20645,8 @@ None identified. #### Test Dataset +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/logAllDSInternalsModules.log + _version_: 1 @@ -16762,6 +20677,8 @@ This detection identifies use of DSInternals modules for illegal management of A ``` #### Associated Analytic Story +* Windows Persistence Techniques + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -16802,6 +20719,8 @@ None identified. #### Test Dataset +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1484/logAllDSInternalsModules.log + _version_: 1 @@ -16833,6 +20752,8 @@ This detection identifies access to PowerSploit modules that enable illegal mana ``` #### Associated Analytic Story +* Windows Persistence Techniques + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -16873,6 +20794,8 @@ None identified. #### Test Dataset +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1484/logAllPowerSploitModulesWithOldNames.log + _version_: 1 @@ -16903,6 +20826,10 @@ This detection identifies access to PowerSploit modules that illegaly elevate ge ``` #### Associated Analytic Story +* Malicious PowerShell + +* Windows Persistence Techniques + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -16943,6 +20870,8 @@ None identified. #### Test Dataset +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/logAllPowerSploitModulesWithOldNames.log + _version_: 1 @@ -16973,6 +20902,8 @@ This detection identifies use of Mimikatz modules for illegal privilege elevatio ``` #### Associated Analytic Story +* Windows Privilege Escalation + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -17012,6 +20943,8 @@ None identified. #### Test Dataset +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/logAllMimikatzModules.log + _version_: 1 @@ -17042,6 +20975,8 @@ This detection identifies use of Mimikatz modules for illegal control over servi ``` #### Associated Analytic Story +* Windows Service Abuse + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -17082,6 +21017,8 @@ None identified. #### Test Dataset +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1569/logAllMimikatzModules.log + _version_: 1 @@ -17113,6 +21050,10 @@ This detection identifies access to PowerSploit modules that enable illegal cont ``` #### Associated Analytic Story +* Windows Service Abuse + +* Malicious PowerShell + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -17153,6 +21094,8 @@ None identified. #### Test Dataset +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1569/logAllPowerSploitModulesWithOldNames.log + _version_: 1 @@ -17188,6 +21131,20 @@ You must be ingesting endpoint data that tracks process activity, and include th #### Required field +* _time + +* EventCode + +* Ticket_Options + +* Ticket_Encryption_Type + +* dest + +* service + +* service_id + #### ATT&CK @@ -17251,6 +21208,8 @@ You must install splunk AWS add on and Splunk App for AWS. This search works wit #### Required field +* _time + @@ -17301,6 +21260,8 @@ You must install splunk AWS add on and Splunk App for AWS. This search works wit #### Required field +* _time + @@ -17351,6 +21312,8 @@ You must install splunk AWS add on and Splunk App for AWS. This search works wit #### Required field +* _time + @@ -17400,6 +21363,8 @@ You must install splunk AWS add on and Splunk App for AWS. This search works wit #### Required field +* _time + @@ -17450,6 +21415,20 @@ You must install splunk AWS add on and Splunk App for AWS. This search works wit #### Required field +* _time + +* userAgent + +* sourceIPs{} + +* src_user + +* src_ip + +* verb + +* requestURI + @@ -17503,6 +21482,8 @@ You must install the Add-on for Microsoft Cloud Services and Configure Kube-Audi #### Required field +* _time + @@ -17555,6 +21536,8 @@ You must install the Add-on for Microsoft Cloud Services and Configure Kube-Audi #### Required field +* _time + @@ -17607,6 +21590,8 @@ You must install the Add-on for Microsoft Cloud Services and Configure Kube-Audi #### Required field +* _time + @@ -17659,6 +21644,8 @@ You must install the Add-on for Microsoft Cloud Services and Configure Kube-Audi #### Required field +* _time + @@ -17710,6 +21697,8 @@ You must install the Add-on for Microsoft Cloud Services and Configure Kube-Audi #### Required field +* _time + @@ -17763,6 +21752,8 @@ You must install the Add-on for Microsoft Cloud Services and Configure Kube-Audi #### Required field +* _time + @@ -17814,6 +21805,8 @@ You must install the Add-on for Microsoft Cloud Services and Configure Kube-Audi #### Required field +* _time + @@ -17865,6 +21858,8 @@ You must install the Add-on for Microsoft Cloud Services and Configure Kube-Audi #### Required field +* _time + #### ATT&CK @@ -17921,6 +21916,8 @@ You must install splunk AWS add on for GCP. This search works with pubsub messag #### Required field +* _time + @@ -17971,6 +21968,8 @@ You must install splunk GCP add on. This search works with pubsub messaging serv #### Required field +* _time + @@ -18021,6 +22020,8 @@ You must install splunk add on for GCP . This search works with pubsub messaging #### Required field +* _time + @@ -18071,6 +22072,8 @@ You must install splunk add on for GCP. This search works with pubsub messaging #### Required field +* _time + @@ -18121,6 +22124,8 @@ You must install splunk add on for GCP. This search works with pubsub messaging #### Required field +* _time + @@ -18171,6 +22176,8 @@ You must install splunk add on for GCP. This search works with pubsub messaging #### Required field +* _time + @@ -18222,6 +22229,14 @@ To successfully implement this search you must ensure that DNS data is populatin #### Required field +* _time + +* DNS.message_type + +* DNS.record_type + +* DNS.dest + #### ATT&CK @@ -18278,6 +22293,20 @@ In order to properly run this search, Splunk needs to ingest process data from y #### Required field +* _time + +* Processes.process + +* Processes.parent_process + +* Processes.user + +* Processes.process_name + +* Processes.parent_process_name + +* Processes.dest + @@ -18328,12 +22357,26 @@ This search looks for PowerShell processes started with parameters to modify the * Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns +* HAFNIUM Group + #### How To Implement You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. #### Required field +* _time + +* Processes.process + +* Processes.process_name + +* Processes.user + +* Processes.parent_process_name + +* Processes.dest + #### ATT&CK @@ -18390,7 +22433,7 @@ This search looks for PowerShell processes that have encoded the script within t * Malicious PowerShell -* Sunburst Malware +* NOBELIUM Group #### How To Implement @@ -18398,6 +22441,20 @@ You must be ingesting data that records process activity from your hosts to popu #### Required field +* _time + +* Processes.process_name + +* Processes.process + +* Processes.user + +* Processes.parent_process_name + +* Processes.dest + +* Processes.process_id + #### ATT&CK @@ -18454,12 +22511,28 @@ This search looks for PowerShell processes started with parameters used to bypas * DHS Report TA18-074A +* HAFNIUM Group + #### How To Implement You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. #### Required field +* _time + +* Processes.process_id + +* Processes.parent_process_id + +* Processes.process + +* Processes.process_name + +* Processes.user + +* Processes.dest + #### ATT&CK @@ -18523,6 +22596,8 @@ You must be ingesting data that records process activity from your hosts to popu #### Required field +* _time + #### ATT&CK @@ -18585,6 +22660,20 @@ You must be ingesting data that records process activity from your hosts to popu #### Required field +* _time + +* Processes.process + +* Processes.parent_process + +* Processes.process_name + +* Processes.user + +* Processes.parent_process_name + +* Processes.dest + #### ATT&CK @@ -18647,6 +22736,8 @@ You need to ingest data from your DNS logs. Specifically you must ingest the dom #### Required field +* _time + @@ -18708,6 +22799,14 @@ You need to ingest email header data. Specifically the sender's address (src_use #### Required field +* _time + +* All_Email.recipient + +* All_Email.src_user + +* All_Email.message_id + @@ -18760,6 +22859,20 @@ To successfully implement this search, you must be ingesting data that records r #### Required field +* _time + +* Registry.action + +* Registry.registry_path + +* Registry.dest + +* Registry.registry_key_name + +* Registry.user + +* Registry.registry_value_name + #### ATT&CK @@ -18820,6 +22933,12 @@ You need to ingest data from your web traffic. This can be accomplished by index #### Required field +* _time + +* Web.url + +* Web.src + @@ -18869,6 +22988,8 @@ Attacker activity may compromise executing several LOLBAS applications in conjun ``` #### Associated Analytic Story +* Unusual Processes + #### How To Implement Collect endpoint data such as sysmon or 4688 events. @@ -18944,6 +23065,22 @@ This search is specific to Okta and requires Okta logs are being ingested in you #### Required field +* _time + +* outcome.reason + +* client.geographicalContext.country + +* client.geographicalContext.state + +* client.geographicalContext.city + +* user + +* src_ip + +* displayMessage + #### ATT&CK @@ -19000,6 +23137,22 @@ To successfully implement this search you need to be ingesting information on pr #### Required field +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_id + +* Processes.parent_process_id + #### ATT&CK @@ -19072,6 +23225,8 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- #### Required field +* _time + #### ATT&CK @@ -19093,6 +23248,92 @@ Uploading container is a normal behavior from developers or users with access to #### Test Dataset +_version_: 1 + + +--- + +### Nishang PowershellTCPOneLine +This query detects the Nishang Invoke-PowerShellTCPOneLine utility that spawns a call back to a remote command and control server. This is a powershell oneliner. In addition, this will capture on the command-line additional utilities used by Nishang. Triage the endpoint and identify any parallel processes that look suspicious. Review the reputation of the remote IP or domain contacted by the powershell process. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: Endpoint +- **ATT&CK**: [T1059.001](https://attack.mitre.org/techniques/T1059.001/) +- **Last Updated**: 2021-03-03 + +
+ details + +#### Search +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=powershell.exe OR Processes.process_name=pwsh.exe OR Processes.process_name=PowerShell_ISE.exe (Processes.process=*Net.Sockets.TCPClient* AND Processes.process=*System.Text.ASCIIEncoding*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `nishang_powershelltcponeline_filter` +``` +#### Associated Analytic Story + +* HAFNIUM Group + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. + +#### Required field + +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_name + +* Processes.process_id + +* Processes.parent_process_id + + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1059.001 | PowerShell | Execution | + + +#### Kill Chain Phase + +* Exploitation + + +#### Known False Positives +Limited false positives may be present. Filter as needed based on initial analysis. + +#### Reference + +* https://github.com/samratashok/nishang/blob/master/Shells/Invoke-PowerShellTcpOneLine.ps1 + +* https://www.volexity.com/blog/2021/03/02/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities/ + +* https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/ + +* https://blog.rapid7.com/2021/03/03/rapid7s-insightidr-enables-detection-and-response-to-microsoft-exchange-0-day/ + + +#### Test Dataset + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/windows-sysmon.log + + _version_: 1
@@ -19133,6 +23374,14 @@ To successfully implement this search, it requires that the 'Update' data model #### Required field +* _time + +* Updates.status + +* Updates.vendor_product + +* Updates.dest + @@ -19153,7 +23402,7 @@ _version_: 1 --- -### Ntdsutil export ntds +### Ntdsutil Export NTDS Monitor for signs that Ntdsutil is being used to Extract Active Directory database - NTDS.dit, typically used for offline password cracking. It may be used in normal circumstances with no command line arguments or shorthand variations of more common arguments. Ntdsutil.exe is typically seen run on a Windows Server. Typical command used to dump ntds.dit \ ntdsutil "ac i ntds" "ifm" "create full C:\Temp" q q \ This technique uses "Install from Media" (IFM), which will extract a copy of the Active Directory database. A successful export of the Active Directory database will yield a file modification named ntds.dit to the destination. @@ -19179,12 +23428,30 @@ This technique uses "Install from Media" (IFM), which will extract a copy of the * Credential Dumping +* HAFNIUM Group + #### How To Implement You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints, to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" field in the Endpoint data model. #### Required field +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_id + +* Processes.parent_process_id + #### ATT&CK @@ -19226,7 +23493,7 @@ _version_: 1 ### O365 Add App Role Assignment Grant User This search detects the creation of a new Federation setting by alerting about an specific event related to its creation. -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: - **ATT&CK**: [T1136.003](https://attack.mitre.org/techniques/T1136.003/) - **Last Updated**: 2021-01-26 @@ -19254,6 +23521,22 @@ You must install splunk Microsoft Office 365 add-on. This search works with o365 #### Required field +* _time + +* Workload + +* Operation + +* Actor{}.ID + +* Actor{}.Type + +* ActorIpAddress + +* dest + +* ResultStatus + #### ATT&CK @@ -19291,7 +23574,7 @@ _version_: 1 ### O365 Added Service Principal This search detects the creation of a new Federation setting by alerting about an specific event related to its creation. -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: - **ATT&CK**: [T1136.003](https://attack.mitre.org/techniques/T1136.003/) - **Last Updated**: 2021-01-26 @@ -19319,6 +23602,22 @@ You must install splunk Microsoft Office 365 add-on. This search works with o365 #### Required field +* _time + +* Workload + +* signature + +* Actor{}.ID + +* ModifiedProperties{}.Name + +* ModifiedProperties{}.NewValue + +* Target{}.ID + +* ActorIpAddress + #### ATT&CK @@ -19360,7 +23659,7 @@ _version_: 1 ### O365 Bypass MFA via Trusted IP This search detects newly added IP addresses/CIDR blocks to the list of MFA Trusted IPs to bypass multi factor authentication. Attackers are often known to use this technique so that they can bypass the MFA system. -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: - **ATT&CK**: [T1562.007](https://attack.mitre.org/techniques/T1562.007/) - **Last Updated**: 2021-01-12 @@ -19391,6 +23690,28 @@ You must install Splunk Microsoft Office 365 add-on. This search works with o365 #### Required field +* _time + +* signature + +* ModifiedProperties{}.Name + +* ModifiedProperties{}.NewValue + +* ModifiedProperties{}.OldValue + +* user + +* vendor_product + +* vendor_account + +* status + +* user_id + +* action + #### ATT&CK @@ -19428,7 +23749,7 @@ _version_: 1 ### O365 Disable MFA This search detects when multi factor authentication has been disabled, what entitiy performed the action and against what user -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: - **ATT&CK**: [T1556](https://attack.mitre.org/techniques/T1556/) - **Last Updated**: 2020-12-16 @@ -19454,6 +23775,22 @@ You must install splunk Microsoft Office 365 add-on. This search works with o365 #### Required field +* _time + +* Operation + +* UserType + +* user + +* status + +* signature + +* dest + +* ResultStatus + #### ATT&CK @@ -19489,7 +23826,7 @@ _version_: 1 ### O365 Excessive Authentication Failures Alert This search detects when an excessive number of authentication failures occur this search also includes attempts against MFA prompt codes -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: - **ATT&CK**: [T1110](https://attack.mitre.org/techniques/T1110/) - **Last Updated**: 2020-12-16 @@ -19516,6 +23853,20 @@ You must install splunk Microsoft Office 365 add-on. This search works with o365 #### Required field +* _time + +* Workload + +* UserAuthenticationMethod + +* status + +* UserAgent + +* src_ip + +* user + #### ATT&CK @@ -19551,7 +23902,7 @@ _version_: 1 ### O365 Excessive SSO logon errors This search detects accounts with high number of Single Sign ON (SSO) logon errors. Excessive logon errors may indicate attempts to bruteforce of password or single sign on token hijack or reuse. -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: - **ATT&CK**: [T1556](https://attack.mitre.org/techniques/T1556/) - **Last Updated**: 2021-01-26 @@ -19580,6 +23931,18 @@ You must install splunk Microsoft Office 365 add-on. This search works with o365 #### Required field +* _time + +* Workload + +* LogonError + +* ActorIpAddress + +* UserAgent + +* UserId + #### ATT&CK @@ -19615,7 +23978,7 @@ _version_: 1 ### O365 New Federated Domain Added This search detects the addition of a new Federated domain. -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: - **ATT&CK**: [T1136.003](https://attack.mitre.org/techniques/T1136.003/) - **Last Updated**: 2021-01-26 @@ -19643,6 +24006,24 @@ You must install splunk Microsoft Office 365 add-on. This search works with o365 #### Required field +* _time + +* Workload + +* Operation + +* Parameters{}.Value + +* ObjectId + +* OrganizationName + +* OriginatingServer + +* UserId + +* UserKey + #### ATT&CK @@ -19686,7 +24067,7 @@ _version_: 1 ### O365 PST export alert This search detects when a user has performed an Ediscovery search or exported a PST file from the search. This PST file usually has sensitive information including email body content -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: - **ATT&CK**: [T1114](https://attack.mitre.org/techniques/T1114/) - **Last Updated**: 2020-12-16 @@ -19712,6 +24093,20 @@ You must install splunk Microsoft Office 365 add-on. This search works with o365 #### Required field +* _time + +* Category + +* Name + +* Source + +* Severity + +* AlertEntityId + +* Operation + #### ATT&CK @@ -19747,7 +24142,7 @@ _version_: 1 ### O365 Suspicious Admin Email Forwarding This search detects when an admin configured a forwarding rule for multiple mailboxes to the same destination. -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: - **ATT&CK**: [T1114.003](https://attack.mitre.org/techniques/T1114.003/) - **Last Updated**: 2020-12-16 @@ -19773,10 +24168,16 @@ This search detects when an admin configured a forwarding rule for multiple mail #### How To Implement - +You must install splunk Microsoft Office 365 add-on. This search works with o365:management:activity #### Required field +* _time + +* Operation + +* Parameters + #### ATT&CK @@ -19810,7 +24211,7 @@ _version_: 1 ### O365 Suspicious Rights Delegation This search detects the assignment of rights to accesss content from another mailbox. This is usually only assigned to a service account. -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: - **ATT&CK**: [T1114.002](https://attack.mitre.org/techniques/T1114.002/) - **Last Updated**: 2020-12-15 @@ -19835,10 +24236,16 @@ This search detects the assignment of rights to accesss content from another mai #### How To Implement - +You must install splunk Microsoft Office 365 add-on. This search works with o365:management:activity #### Required field +* _time + +* Operation + +* Parameters + #### ATT&CK @@ -19872,7 +24279,7 @@ _version_: 1 ### O365 Suspicious User Email Forwarding This search detects when multiple user configured a forwarding rule to the same destination. -- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: - **ATT&CK**: [T1114.003](https://attack.mitre.org/techniques/T1114.003/) - **Last Updated**: 2020-12-16 @@ -19898,10 +24305,16 @@ This search detects when multiple user configured a forwarding rule to the same #### How To Implement - +You must install splunk Microsoft Office 365 add-on. This search works with o365:management:activity #### Required field +* _time + +* Operation + +* Parameters + #### ATT&CK @@ -19960,6 +24373,16 @@ This search is specific to Okta and requires Okta logs are being ingested in you #### Required field +* _time + +* displayMessage + +* client.geographicalContext.country + +* client.geographicalContext.state + +* client.geographicalContext.city + #### ATT&CK @@ -20015,6 +24438,18 @@ This search is specific to Okta and requires Okta logs are being ingested in you #### Required field +* _time + +* displayMessage + +* app + +* user + +* result + +* src_ip + #### ATT&CK @@ -20071,6 +24506,16 @@ This search is specific to Okta and requires Okta logs are being ingested in you #### Required field +* _time + +* displayMessage + +* client.geographicalContext.city + +* client.geographicalContext.state + +* user + #### ATT&CK @@ -20123,6 +24568,8 @@ No extra steps needed to implement this search. #### Required field +* _time + @@ -20176,6 +24623,8 @@ In order to properly run this search, Splunk needs to ingest data from your osqu #### Required field +* _time + @@ -20230,6 +24679,16 @@ You must be ingesting data that records the filesystem activity from your hosts #### Required field +* _time + +* Filesystem.dest + +* Filesystem.file_path + +* Filesystem.file_name + +* Filesystem.dest + #### ATT&CK @@ -20346,6 +24805,8 @@ This detection identifies use of PowerSploit modules that facilitate access prob ``` #### Associated Analytic Story +* Windows Privilege Escalation + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -20428,6 +24889,22 @@ You must be ingesting data that records filesystem and process activity from you #### Required field +* _time + +* Filesystem.file_name + +* Filesystem.file_path + +* Filesystem.process_id + +* Filesystem.file_name + +* Filesystem.file_path + +* Filesystem.file_hash + +* Filesystem.user + #### ATT&CK @@ -20464,6 +24941,91 @@ _version_: 4 --- +### Process Deleting Its Process File Path +This detection is to identify a suspicious process that tries to delete the process file path related to its process. This technique is known to be defense evasion once a certain condition of malware is satisfied or not. Clop ransomware use this technique where it will try to delete its process file path using a .bat command if the keyboard layout is not the layout it tries to infect. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: Endpoint +- **ATT&CK**: [T1003.002](https://attack.mitre.org/techniques/T1003.002/) +- **Last Updated**: 2021-03-17 + +
+ details + +#### Search +``` +`sysmon` EventCode=1 cmdline = "*/c del*" Image = "*\\cmd.exe" +|eval result = if(like(process,"%".parent_process."%"), "Found", "Not Found") +| stats min(_time) as firstTime max(_time) as lastTime count by Computer user ParentImage ParentCommandLine Image cmdline EventCode ProcessID result +| where result = "Found" +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `process_deleting_its_process_file_path_filter` +``` +#### Associated Analytic Story + +* Clop Ransomware + + +#### How To Implement +You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. + +#### Required field + +* EventCode + +* Computer + +* user + +* ParentImage + +* ParentCommandLine + +* Image + +* cmdline + +* ProcessID + +* result + +* _time + + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1003.002 | Security Account Manager | Credential Access | + + +#### Kill Chain Phase + +* Exploitation + + +#### Known False Positives +unknown + +#### Reference + +* https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html + +* https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html + + +#### Test Dataset + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log + + +_version_: 1 +
+ +--- + ### Process Execution via WMI This search looks for processes launched via WMI. @@ -20494,6 +25056,18 @@ You must be ingesting endpoint data that tracks process activity, including pare #### Required field +* _time + +* Processes.process + +* Processes.parent_process_name + +* Processes.user + +* Processes.dest + +* Processes.process_name + #### ATT&CK @@ -20555,6 +25129,20 @@ In order to properly run this search, Splunk needs to ingest data from your osqu #### Required field +* _time + +* app + +* name + +* columns.cmdline + +* columns.name + +* columns.pid + +* host + @@ -20607,6 +25195,8 @@ To successfully implement this search, you must be ingesting logs with the proce #### Required field +* _time + #### ATT&CK @@ -20669,6 +25259,20 @@ To successfully implement this search, you must be ingesting data that records p #### Required field +* _time + +* Processes.process + +* Processes.parent_process_name + +* Processes.parent_process + +* Processes.process_name + +* Processes.user + +* Processes.dest + #### ATT&CK @@ -20735,6 +25339,16 @@ In order to properly run this search, Splunk needs to ingest data from firewalls #### Required field +* _time + +* All_Traffic.action + +* All_Traffic.src_ip + +* All_Traffic.dest_ip + +* All_Traffic.dest_port + #### ATT&CK @@ -20800,6 +25414,8 @@ To successfully implement this search, you must be ingesting data that records p #### Required field +* _times + @@ -20858,6 +25474,16 @@ Running this search properly requires a technology that can inspect network traf #### Required field +* _time + +* All_Traffic.app + +* All_Traffic.dest_port + +* All_Traffic.src_ip + +* All_Traffic.dest_ip + #### ATT&CK @@ -20916,6 +25542,18 @@ This search requires you to be ingesting your network traffic, and populating th #### Required field +* _time + +* All_Traffic.transport + +* All_Traffic.dest_port + +* All_Traffic.user + +* All_Traffic.src + +* All_Traffic.dest + @@ -20940,6 +25578,84 @@ _version_: 2 --- +### Ransomware Notes bulk creation +The following analytics identifies a big number of instance of ransomware notes (filetype e.g .txt, .html, .hta) file creation to the infected machine. This behavior is a good sensor if the ransomware note filename is quite new for security industry or the ransomware note filename is not in your lookup table list for monitoring. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: Endpoint +- **ATT&CK**: [T1486](https://attack.mitre.org/techniques/T1486/) +- **Last Updated**: 2021-03-12 + +
+ details + +#### Search +``` +`sysmon` EventCode=11 file_name IN ("*\.txt","*\.html","*\.hta") +| stats min(_time) as firstTime max(_time) as lastTime dc(TargetFilename) as unique_readme_path_count values(TargetFilename) as list_of_readme_path by Computer Image file_name +| where unique_readme_path_count >= 50 +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `ransomware_notes_bulk_creation_filter` +``` +#### Associated Analytic Story + +* Clop Ransomware + + +#### How To Implement +You must be ingesting data that records the filesystem activity from your hosts to populate the Endpoint file-system data model node. If you are using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which you want to collect data. + +#### Required field + +* EventCode + +* file_name + +* _time + +* TargetFilename + +* Computer + +* Image + +* user + + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1486 | Data Encrypted for Impact | Impact | + + +#### Kill Chain Phase + +* Obfuscation + + +#### Known False Positives +unknown + +#### Reference + +* https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html + +* https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html + + +#### Test Dataset + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log + + +_version_: 1 +
+ +--- + ### Rare Parent-Child Process Relationship An attacker may use LOLBAS tools spawned from vulnerable applications not typically used by system administrators. This search leverages the Splunk Streaming ML DSP plugin to find rare parent/child relationships. The list of application has been extracted from https://github.com/LOLBAS-Project/LOLBAS/tree/master/yml/OSBinaries @@ -20966,10 +25682,12 @@ An attacker may use LOLBAS tools spawned from vulnerable applications not typica | where label AND quantile<0.1 AND (process_name="powershell.exe" OR process_name="regsvcs.exe" OR process_name="ftp.exe" OR process_name="dfsvc.exe" OR process_name="rasautou.exe" OR process_name="schtasks.exe" OR process_name="xwizard.exe" OR process_name="findstr.exe" OR process_name="esentutl.exe" OR process_name="cscript.exe" OR process_name="reg.exe" OR process_name="csc.exe" OR process_name="atbroker.exe" OR process_name="print.exe" OR process_name="pcwrun.exe" OR process_name="vbc.exe" OR process_name="rpcping.exe" OR process_name="wsreset.exe" OR process_name="ilasm.exe" OR process_name="certutil.exe" OR process_name="replace.exe" OR process_name="mshta.exe" OR process_name="bitsadmin.exe" OR process_name="wscript.exe" OR process_name="ieexec.exe" OR process_name="cmd.exe" OR process_name="microsoft.workflow.compiler.exe" OR process_name="runscripthelper.exe" OR process_name="makecab.exe" OR process_name="forfiles.exe" OR process_name="desktopimgdownldr.exe" OR process_name="control.exe" OR process_name="msbuild.exe" OR process_name="register-cimprovider.exe" OR process_name="tttracer.exe" OR process_name="ie4uinit.exe" OR process_name="sc.exe" OR process_name="bash.exe" OR process_name="hh.exe" OR process_name="cmstp.exe" OR process_name="mmc.exe" OR process_name="jsc.exe" OR process_name="scriptrunner.exe" OR process_name="odbcconf.exe" OR process_name="extexport.exe" OR process_name="msdt.exe" OR process_name="diskshadow.exe" OR process_name="extrac32.exe" OR process_name="eventvwr.exe" OR process_name="mavinject.exe" OR process_name="regasm.exe" OR process_name="gpscript.exe" OR process_name="rundll32.exe" OR process_name="regsvr32.exe" OR process_name="regedit.exe" OR process_name="msiexec.exe" OR process_name="gfxdownloadwrapper.exe" OR process_name="presentationhost.exe" OR process_name="regini.exe" OR process_name="wmic.exe" OR process_name="runonce.exe" OR process_name="syncappvpublishingserver.exe" OR process_name="verclsid.exe" OR process_name="psr.exe" OR process_name="infdefaultinstall.exe" OR process_name="explorer.exe" OR process_name="expand.exe" OR process_name="installutil.exe" OR process_name="netsh.exe" OR process_name="wab.exe" OR process_name="dnscmd.exe" OR process_name="at.exe" OR process_name="pcalua.exe" OR process_name="cmdkey.exe" OR process_name="msconfig.exe") | eval start_time = timestamp, end_time = timestamp, entities = mvappend(dest_device_id, dest_user_id), body = "TBD" -| into write_ssa_detected_events(); +| into write_null(); ``` #### Associated Analytic Story +* Unusual Processes + #### How To Implement Collect endpoint data such as sysmon or 4688 events. @@ -21042,6 +25760,8 @@ This detection identifies access to PowerSploit modules that discover accounts, ``` #### Associated Analytic Story +* Windows Discovery Techniques + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -21112,6 +25832,8 @@ This detection identifies use of Mimikatz modules for discovery of accounts and ``` #### Associated Analytic Story +* Windows Discovery Techniques + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -21182,6 +25904,8 @@ This detection identifies access to PowerSploit modules for reconnaissance and a ``` #### Associated Analytic Story +* Windows Discovery Techniques + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -21254,6 +25978,8 @@ This detection identifies access to PowerSploit modules that discover computers, ``` #### Associated Analytic Story +* Windows Discovery Techniques + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -21324,6 +26050,8 @@ This detection identifies use of Mimikatz modules for discovery of computers and ``` #### Associated Analytic Story +* Windows Discovery Techniques + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -21392,6 +26120,8 @@ This detection identifies access to PowerSploit modules that discover and access ``` #### Associated Analytic Story +* Windows Discovery Techniques + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -21467,6 +26197,8 @@ This detection identifies use of Mimikatz modules for discovery and access to se ``` #### Associated Analytic Story +* Windows Discovery Techniques + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -21537,6 +26269,8 @@ This detection identifies use of Mimikatz modules for discovery and access to ne ``` #### Associated Analytic Story +* Windows Discovery Techniques + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -21607,6 +26341,8 @@ This detection identifies access to PowerSploit modules that discover and access ``` #### Associated Analytic Story +* Windows Discovery Techniques + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -21677,6 +26413,8 @@ This detection identifies use of PowerSploit modules that discover opportunities ``` #### Associated Analytic Story +* Windows Discovery Techniques + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -21750,6 +26488,8 @@ This detection identifies access to PowerSploit modules for reconnaissance of co ``` #### Associated Analytic Story +* Windows Discovery Techniques + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -21820,6 +26560,8 @@ This detection identifies reconnaissance of credential stores and use of CryptoA ``` #### Associated Analytic Story +* Windows Discovery Techniques + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -21893,6 +26635,8 @@ This detection identifies use of PowerSploit modules for assessment of presence ``` #### Associated Analytic Story +* Windows Discovery Techniques + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -21962,6 +26706,8 @@ This detection identifies use of PowerSploit modules for assessment of privilege ``` #### Associated Analytic Story +* Windows Discovery Techniques + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -22032,6 +26778,8 @@ This detection identifies use of Mimikatz modules for discovery of process or se ``` #### Associated Analytic Story +* Windows Discovery Techniques + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -22112,6 +26860,20 @@ To successfully implement this search, you must be ingesting data that records r #### Required field +* _time + +* Processes.process_name + +* Processes.parent_process_name + +* Processes.user + +* Processes.process + +* Processes.process_id + +* Processes.dest + #### ATT&CK @@ -22177,6 +26939,8 @@ You must be ingesting data that records process activity from your hosts to popu #### Required field +* _time + #### ATT&CK @@ -22247,6 +27011,16 @@ To successfully implement this search, you must be ingesting data that records r #### Required field +* _time + +* Registry.registry_key_name + +* Registry.registry_path + +* Registry.dest + +* Registry.user + #### ATT&CK @@ -22311,6 +27085,16 @@ To successfully implement this search, you must be ingesting data that records r #### Required field +* _time + +* Registry.registry_path + +* Registry.registry_key_name + +* Registry.dest + +* Registry.user + #### ATT&CK @@ -22375,6 +27159,16 @@ To successfully implement this search, you must populate the Change_Analysis dat #### Required field +* _time + +* Registry.registry_key_name + +* Registry.registry_path + +* Registry.dest + +* Registry.user + #### ATT&CK @@ -22438,6 +27232,16 @@ You must ensure that your network traffic data is populating the Network_Traffic #### Required field +* _time + +* All_Traffic.app + +* All_Traffic.src + +* All_Traffic.dest + +* All_Traffic.dest_port + #### ATT&CK @@ -22504,6 +27308,20 @@ To successfully implement this search you need to identify systems that commonly #### Required field +* _time + +* All_Traffic.dest_port + +* All_Traffic.dest_category + +* All_Traffic.src_category + +* All_Traffic.src + +* All_Traffic.dest + +* All_Traffic.dest_port + #### ATT&CK @@ -22564,6 +27382,16 @@ To successfully implement this search, you must be ingesting data that records p #### Required field +* _time + +* Processes.process + +* Processes.dest_category + +* Processes.dest + +* Processes.user + #### ATT&CK @@ -22624,6 +27452,18 @@ You must be ingesting data that records process activity from your hosts to popu #### Required field +* _time + +* Processes.process_name + +* Processes.process + +* Processes.parent_process_name + +* Processes.dest + +* Processes.user + #### ATT&CK @@ -22688,6 +27528,8 @@ To successfully implement this search, you must populate the `Endpoint` data mod #### Required field +* _time + @@ -22740,6 +27582,8 @@ You must be ingesting data that records process activity from your hosts to popu #### Required field +* _time + #### ATT&CK @@ -22768,6 +27612,84 @@ _version_: 2 --- +### Resize ShadowStorage volume +The following analytics identifies the resizing of shadowstorage by ransomware malware to avoid the shadow volumes being made again. this technique is an alternative by ransomware attacker than deleting the shadowstorage which is known alert in defensive team. one example of ransomware that use this technique is CLOP ransomware where it drops a .bat file that will resize the shadowstorage to minimum size as much as possible + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: Endpoint +- **ATT&CK**: [T1490](https://attack.mitre.org/techniques/T1490/) +- **Last Updated**: 2021-03-12 + +
+ details + +#### Search +``` + +| tstats `security_content_summariesonly` values(Processes.process) as cmdline values(Processes.parent_process_name) as parent_process values(Processes.process_name) as process_name min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name = "cmd.exe" OR Processes.parent_process_name = "powershell.exe" OR Processes.parent_process_name = "powershell_ise.exe" OR Processes.parent_process_name = "wmic.exe" Processes.process_name = "vssadmin.exe" Processes.process="*resize*" Processes.process="*shadowstorage*" Processes.process="*/maxsize*" by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.dest Processes.user Processes.process_id Processes.process_guid +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +|`security_content_ctime(lastTime)` +| `resize_shadowstorage_volume_filter` +``` +#### Associated Analytic Story + +* Clop Ransomware + + +#### How To Implement +To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. + +#### Required field + +* Processes.process + +* Process.parent_process_name + +* _time + +* Processes.process_name + +* Processes.parent_process + +* Processes.dest + +* Processes.user + + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1490 | Inhibit System Recovery | Impact | + + +#### Kill Chain Phase + +* Exploitation + + +#### Known False Positives +network admin can resize the shadowstorage for valid purposes. + +#### Reference + +* https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html + +* https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html + + +#### Test Dataset + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log + + +_version_: 1 +
+ +--- + ### RunDLL Loading DLL By Ordinal This search looks for executing scripts with rundll32. Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly, may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations. @@ -22798,6 +27720,18 @@ You must be ingesting data that records process activity from your hosts to popu #### Required field +* _time + +* Processes.process_name + +* Processes.parent_process_name + +* Processes.process + +* Processes.dest + +* Processes.user + #### ATT&CK @@ -22858,6 +27792,14 @@ You must be ingesting data that records the filesystem activity from your hosts #### Required field +* _time + +* Filesystem.file_path + +* Filesystem.dest + +* Filesystem.user + #### ATT&CK @@ -22883,6 +27825,92 @@ If there are files with this keywoord as file names it might trigger false possi * https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ryuk/windows-sysmon.log +_version_: 1 + + +--- + +### Ryuk Wake on LAN Command +This Splunk query identifies the use of Wake-on-LAN utilized by Ryuk ransomware. The Ryuk Ransomware uses the Wake-on-Lan feature to turn on powered off devices on a compromised network to have greater success encrypting them. This is a high fidelity indicator of Ryuk ransomware executing on an endpoint. Upon triage, isolate the endpoint. Additional file modification events will be within the users profile (\appdata\roaming) and in public directories (users\public\). Review all Scheduled Tasks on the isolated endpoint and across the fleet. Suspicious Scheduled Tasks will include a path to a unknown binary and those endpoints should be isolated until triaged. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: Endpoint +- **ATT&CK**: [T1059.003](https://attack.mitre.org/techniques/T1059.003/) +- **Last Updated**: 2021-03-01 + +
+ details + +#### Search +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process="*8 LAN*" OR Processes.process="*9 REP*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `ryuk_wake_on_lan_command_filter` +``` +#### Associated Analytic Story + +* Ryuk Ransomware + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. + +#### Required field + +* _time + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_name + +* Processes.process + +* Processes.process_id + +* Processes.parent_process_id + + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1059.003 | Windows Command Shell | Execution | + + +#### Kill Chain Phase + +* Exploitation + +* Lateral Movement + + +#### Known False Positives +Limited to no known false positives. + +#### Reference + +* https://www.bleepingcomputer.com/news/security/ryuk-ransomware-uses-wake-on-lan-to-encrypt-offline-devices/ + +* https://www.bleepingcomputer.com/news/security/ryuk-ransomware-now-self-spreads-to-other-windows-lan-devices/ + +* https://www.cert.ssi.gouv.fr/uploads/CERTFR-2021-CTI-006.pdf + + +#### Test Dataset + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.003/ryuk/windows-sysmon.log + + _version_: 1
@@ -22927,6 +27955,14 @@ This search requires you to be ingesting your network traffic logs and populatin #### Required field +* _time + +* All_Traffic.dest_port + +* All_Traffic.app + +* All_Traffic.src + #### ATT&CK @@ -22999,6 +28035,16 @@ Detailed documentation on how to create a new field within Incident Review is fo #### Required field +* _time + +* All_Traffic.dest_ip + +* All_Traffic.dest_port + +* All_Traffic.app + +* All_Traffic.src + #### ATT&CK @@ -23057,6 +28103,22 @@ To successfully implement this search, you need to be monitoring network communi #### Required field +* _time + +* Web.dest_category + +* Web.url_length + +* Web.http_user_agent_length + +* Web.src + +* Web.dest + +* Web.url + +* Web.http_user_agent + #### ATT&CK @@ -23115,6 +28177,16 @@ You must be ingesting data that records the file-system activity from your hosts #### Required field +* _time + +* Filesystem.user + +* Filesystem.dest + +* Filesystem.file_name + +* Filesystem.file_path + #### ATT&CK @@ -23177,7 +28249,7 @@ This search looks for arguments to sc.exe indicating the creation or modificatio * Disabling Security Tools -* Sunburst Malware +* NOBELIUM Group #### How To Implement @@ -23185,6 +28257,18 @@ To successfully implement this search you need to be ingesting information on pr #### Required field +* _time + +* Processes.process_name + +* Processes.process + +* Processes.parent_process_name + +* Processes.dest + +* Processes.user + #### ATT&CK @@ -23239,7 +28323,7 @@ This search looks for flags passed to schtasks.exe on the command-line that indi * DHS Report TA18-074A -* Sunburst Malware +* NOBELIUM Group #### How To Implement @@ -23247,6 +28331,20 @@ You must be ingesting endpoint data that tracks process activity, including pare #### Required field +* _time + +* Processes.process + +* Processes.parent_process + +* Processes.process_name + +* Processes.user + +* Processes.parent_process_name + +* Processes.dest + #### ATT&CK @@ -23308,6 +28406,8 @@ You must be ingesting data that records process activity from your hosts to popu #### Required field +* _time + #### ATT&CK @@ -23360,7 +28460,7 @@ This search looks for flags passed to schtasks.exe on the command-line that indi * Lateral Movement -* Sunburst Malware +* NOBELIUM Group #### How To Implement @@ -23368,6 +28468,18 @@ You must be ingesting data that records process activity from your hosts to popu #### Required field +* _time + +* Processes.process_name + +* Processes.process + +* Processes.parent_process_name + +* Processes.dest + +* Processes.user + #### ATT&CK @@ -23430,6 +28542,18 @@ To successfully implement this search you need to be ingesting logs with both th #### Required field +* _time + +* Processes.process + +* Processes.process_name + +* Processes.parent_process_name + +* Processes.dest + +* Processes.user + #### ATT&CK @@ -23490,6 +28614,14 @@ You must be ingesting endpoint data that tracks process activity, including pare #### Required field +* _time + +* Processes.process_name + +* Processes.user + +* Processes.dest + #### ATT&CK @@ -23544,6 +28676,8 @@ This detection identifies illegal setting of credentials via DSInternals modules ``` #### Associated Analytic Story +* Windows Persistence Techniques + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -23590,6 +28724,8 @@ None identified. #### Test Dataset +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/logAllDSInternalsModules.log + _version_: 1 @@ -23620,6 +28756,8 @@ This detection identifies illegal setting of credentials via Mimikatz modules. ``` #### Associated Analytic Story +* Windows Persistence Techniques + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -23660,6 +28798,8 @@ None identified. #### Test Dataset +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/logAllMimikatzModules.log + _version_: 1 @@ -23690,6 +28830,8 @@ This detection identifies illegal setting of credentials via PowerSploit modules ``` #### Associated Analytic Story +* Windows Persistence Techniques + #### How To Implement You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -23730,6 +28872,8 @@ None identified. #### Test Dataset +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/logAllPowerSploitModulesWithOldNames.log + _version_: 1 @@ -23766,6 +28910,16 @@ You must be ingesting data that records the filesystem activity from your hosts #### Required field +* _time + +* Filesystem.file_hash + +* Filesystem.file_path + +* Filesystem.file_name + +* Filesystem.dest + #### ATT&CK @@ -23826,6 +28980,16 @@ You must be ingesting data that records process activity from your hosts to popu #### Required field +* _time + +* Processes.process_name + +* Processes.parent_process_name + +* Processes.dest + +* Processes.user + #### ATT&CK @@ -23889,6 +29053,14 @@ This search requires you to have enabled your Group Management Audit Logs in you #### Required field +* _time + +* All_Changes.result_id + +* All_Changes.user + +* All_Changes.dest + #### ATT&CK @@ -23954,6 +29126,16 @@ You must be ingesting data that records process activity from your hosts to popu #### Required field +* _time + +* Processes.dest + +* Processes.user + +* Processes.process + +* Processes.process_name + #### ATT&CK @@ -24014,6 +29196,8 @@ The search requires that you are ingesting your vulnerability-scanner data and t #### Required field +* _time + @@ -24070,6 +29254,12 @@ In order to implement this search, you must populate the Endpoint file-system da #### Required field +* _time + +* Filesystem.action + +* Filesystem.dest + @@ -24123,6 +29313,8 @@ The REST endpoint that exposes system information is also necessary for the prop #### Required field +* _time + @@ -24169,7 +29361,7 @@ The malware sunburst will load the malicious dll by SolarWinds.BusinessLayerHost ``` #### Associated Analytic Story -* Sunburst Malware +* NOBELIUM Group #### How To Implement @@ -24177,6 +29369,14 @@ This detection relies on sysmon logs with the Event ID 7, Driver loaded. Please #### Required field +* _time + +* EventCode + +* ImageLoaded + +* QueryName + #### ATT&CK @@ -24226,7 +29426,7 @@ This search aims to detect the Supernova webshell used in the SUNBURST attack. ``` #### Associated Analytic Story -* Sunburst Malware +* NOBELIUM Group #### How To Implement @@ -24234,6 +29434,20 @@ To successfully implement this search, you need to be monitoring web traffic to #### Required field +* _time + +* Web.url + +* Web.src + +* Web.dest + +* Web.vendor_product + +* Web.user + +* Web.http_user_agent + #### ATT&CK @@ -24302,6 +29516,8 @@ To successfully implement this search you need to be ingesting information on re #### Required field +* _time + #### ATT&CK @@ -24330,6 +29546,171 @@ _version_: 4 --- +### Suspicious Curl Network Connection +The following analytic identifies the use of a curl contacting suspicious remote domains to checkin to command and control servers or download further implants. In the context of Silver Sparrow, curl is identified contacting s3.amazonaws.com. This particular behavior is common with MacOS adware-malicious software. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: Endpoint +- **ATT&CK**: [T1105](https://attack.mitre.org/techniques/T1105/) +- **Last Updated**: 2021-02-22 + +
+ details + +#### Search +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=curl Processes.process=s3.amazonaws.com by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `suspicious_curl_network_connection_filter` +``` +#### Associated Analytic Story + +* Silver Sparrow + +* Ingress Tool Transfer + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. + +#### Required field + +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_id + +* Processes.parent_process_id + + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1105 | Ingress Tool Transfer | Command and Control | + + +#### Kill Chain Phase + +* Actions on Objectives + + +#### Known False Positives +Unknown. Filter as needed. + +#### Reference + +* https://redcanary.com/blog/clipping-silver-sparrows-wings/ + +* https://marcosantadev.com/manage-plist-files-plistbuddy/ + + +#### Test Dataset + + +_version_: 1 +
+ +--- + +### Suspicious DLLHost no Command Line Arguments +The following analytic identifies DLLHost.exe with no command line arguments. It is unusual for DLLHost.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, identify any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. DLLHost.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: +- **ATT&CK**: [T1055](https://attack.mitre.org/techniques/T1055/) +- **Last Updated**: 2021-02-23 + +
+ details + +#### Search +``` +`sysmon` EventID=1 (process_name=dllhost.exe OR OriginalFileName=dllhost.exe) +| regex CommandLine="(dllhost\.exe.{0,4}$)" +| stats count min(_time) as firstTime max(_time) as lastTime by dest, User, ParentImage,ParentCommandLine, process_name, OriginalFileName, process_path, CommandLine +| rename Computer as dest +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `suspicious_dllhost_no_command_line_arguments_filter` +``` +#### Associated Analytic Story + +* Cobalt Strike + + +#### How To Implement +To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. + +#### Required field + +* _time + +* EventID + +* process_name + +* OriginalFileName + +* CommandLine + +* dest + +* User + +* ParentImage + +* ParentCommandLine + +* process_path + + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1055 | Process Injection | Defense Evasion, Privilege Escalation | + + +#### Kill Chain Phase + +* Exploitation + + +#### Known False Positives +Limited false positives may be present in small environments. Tuning may be required based on parent process. + +#### Reference + +* https://raw.githubusercontent.com/threatexpress/malleable-c2/c3385e481159a759f79b8acfe11acf240893b830/jquery-c2.4.2.profile + +* https://blog.cobaltstrike.com/2021/02/09/learn-pipe-fitting-for-all-of-your-offense-projects/ + + +#### Test Dataset + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log + + +_version_: 1 +
+ +--- + ### Suspicious Email - UBA Anomaly This detection looks for emails that are suspicious because of their sender, domain rareness, or behavior differences. This is an anomaly generated by Splunk User Behavior Analytics (UBA). @@ -24361,6 +29742,8 @@ You must be ingesting data from email logs and have Splunk integrated with UBA. #### Required field +* _time + #### ATT&CK @@ -24424,6 +29807,14 @@ If Splunk Phantom is also configured in your environment, a Playbook called "Sus #### Required field +* _time + +* All_Email.file_name + +* All_Email.src_user + +* All_Email.message_id + #### ATT&CK @@ -24483,6 +29874,8 @@ You must be ingesting data that records the filesystem activity from your hosts #### Required field +* _time + @@ -24505,6 +29898,91 @@ _version_: 3 --- +### Suspicious GPUpdate no Command Line Arguments +The following analytic identifies gpupdate.exe with no command line arguments. It is unusual for gpupdate.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, identify any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. gpupdate.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: +- **ATT&CK**: [T1055](https://attack.mitre.org/techniques/T1055/) +- **Last Updated**: 2021-02-23 + +
+ details + +#### Search +``` +`sysmon` EventID=1 (process_name=gpupdate.exe OR OriginalFileName=GPUpdate.exe) +| regex CommandLine="(gpupdate\.exe.{0,4}$)" +| stats count min(_time) as firstTime max(_time) as lastTime by dest, User, ParentImage,ParentCommandLine, process_name, OriginalFileName, process_path, CommandLine +| rename Computer as dest +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `suspicious_gpupdate_no_command_line_arguments_filter` +``` +#### Associated Analytic Story + +* Cobalt Strike + + +#### How To Implement +To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. + +#### Required field + +* _time + +* EventID + +* process_name + +* OriginalFileName + +* CommandLine + +* dest + +* User + +* ParentImage + +* ParentCommandLine + +* process_path + + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1055 | Process Injection | Defense Evasion, Privilege Escalation | + + +#### Kill Chain Phase + +* Exploitation + + +#### Known False Positives +Limited false positives may be present in small environments. Tuning may be required based on parent process. + +#### Reference + +* https://raw.githubusercontent.com/xx0hcd/Malleable-C2-Profiles/0ef8cf4556e26f6d4190c56ba697c2159faa5822/crimeware/trick_ryuk.profile + +* https://blog.cobaltstrike.com/2021/02/09/learn-pipe-fitting-for-all-of-your-offense-projects/ + + +#### Test Dataset + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log + + +_version_: 1 +
+ +--- + ### Suspicious Java Classes This search looks for suspicious Java classes that are often used to exploit remote command execution in common Java frameworks, such as Apache Struts. @@ -24537,6 +30015,24 @@ In order to properly run this search, Splunk needs to ingest data from your web- #### Required field +* _time + +* http_method + +* http_content_length + +* src_ip + +* url + +* status + +* http_user_agent + +* src + +* dest + @@ -24583,12 +30079,32 @@ The following analytic identifies renamed instances of msbuild.exe executing. Ms * Trusted Developer Utilities Proxy Execution MSBuild +* Cobalt Strike + #### How To Implement To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. #### Required field +* _time + +* EventID + +* OriginalFileName + +* process_name + +* Computer + +* User + +* parent_process_name + +* process_path + +* CommandLine + #### ATT&CK @@ -24656,6 +30172,20 @@ To successfully implement this search you need to be ingesting information on pr #### Required field +* _time + +* Processes.process_name + +* Processes.process + +* Processes.parent_process_name + +* Processes.dest + +* Processes.parent_process + +* Processes.user + #### ATT&CK @@ -24685,6 +30215,160 @@ Although unlikely, some legitimate applications may exhibit this behavior, trigg * https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127.001/windows-sysmon.log +_version_: 1 + + +--- + +### Suspicious PlistBuddy Usage +The following analytic identifies the use of a native MacOS utility, PlistBuddy, creating or modifying a properly list (.plist) file. In the instance of Silver Sparrow, the following commands were executed:\ +- PlistBuddy -c "Add :Label string init_verx" ~/Library/Launchagents/init_verx.plist \ +- PlistBuddy -c "Add :RunAtLoad bool true" ~/Library/Launchagents/init_verx.plist \ +- PlistBuddy -c "Add :StartInterval integer 3600" ~/Library/Launchagents/init_verx.plist \ +- PlistBuddy -c "Add :ProgramArguments array" ~/Library/Launchagents/init_verx.plist \ +- PlistBuddy -c "Add :ProgramArguments:0 string /bin/sh" ~/Library/Launchagents/init_verx.plist \ +- PlistBuddy -c "Add :ProgramArguments:1 string -c" ~/Library/Launchagents/init_verx.plist \ +Upon triage, capture the property list file being written to disk and review for further indicators. Contain the endpoint and triage further. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: Endpoint +- **ATT&CK**: [T1543.001](https://attack.mitre.org/techniques/T1543.001/) +- **Last Updated**: 2021-02-22 + +
+ details + +#### Search +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=PlistBuddy (Processes.process=*LaunchAgents* OR Processes.process=*RunAtLoad* OR Processes.process=*true*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `suspicious_plistbuddy_usage_filter` +``` +#### Associated Analytic Story + +* Silver Sparrow + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. + +#### Required field + +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_id + +* Processes.parent_process_id + + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1543.001 | Launch Agent | Persistence, Privilege Escalation | + + +#### Kill Chain Phase + +* Actions on Objectives + + +#### Known False Positives +Some legitimate applications may use PlistBuddy to create or modify property lists and possibly generate false positives. Review the property list being modified or created to confirm. + +#### Reference + +* https://redcanary.com/blog/clipping-silver-sparrows-wings/ + +* https://marcosantadev.com/manage-plist-files-plistbuddy/ + + +#### Test Dataset + + +_version_: 1 +
+ +--- + +### Suspicious PlistBuddy Usage via OSquery +The following analytic identifies the use of a native MacOS utility, PlistBuddy, creating or modifying a properly list (.plist) file. In the instance of Silver Sparrow, the following commands were executed:\ +- PlistBuddy -c "Add :Label string init_verx" ~/Library/Launchagents/init_verx.plist \ +- PlistBuddy -c "Add :RunAtLoad bool true" ~/Library/Launchagents/init_verx.plist \ +- PlistBuddy -c "Add :StartInterval integer 3600" ~/Library/Launchagents/init_verx.plist \ +- PlistBuddy -c "Add :ProgramArguments array" ~/Library/Launchagents/init_verx.plist \ +- PlistBuddy -c "Add :ProgramArguments:0 string /bin/sh" ~/Library/Launchagents/init_verx.plist \ +- PlistBuddy -c "Add :ProgramArguments:1 string -c" ~/Library/Launchagents/init_verx.plist \ +Upon triage, capture the property list file being written to disk and review for further indicators. Contain the endpoint and triage further. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: +- **ATT&CK**: [T1543.001](https://attack.mitre.org/techniques/T1543.001/) +- **Last Updated**: 2021-02-22 + +
+ details + +#### Search +``` +`osquery_process` "columns.cmdline"="*LaunchAgents*" OR "columns.cmdline"="*RunAtLoad*" OR "columns.cmdline"="*true*" +| `suspicious_plistbuddy_usage_via_osquery_filter` +``` +#### Associated Analytic Story + +* Silver Sparrow + + +#### How To Implement +OSQuery must be installed and configured to pick up process events (info at https://osquery.io) as well as using the Splunk OSQuery Add-on https://splunkbase.splunk.com/app/4402. Modify the macro and validate fields are correct. + +#### Required field + +* _time + +* columns.cmdline + + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1543.001 | Launch Agent | Persistence, Privilege Escalation | + + +#### Kill Chain Phase + +* Actions on Objectives + + +#### Known False Positives +Some legitimate applications may use PlistBuddy to create or modify property lists and possibly generate false positives. Review the property list being modified or created to confirm. + +#### Reference + +* https://redcanary.com/blog/clipping-silver-sparrows-wings/ + +* https://marcosantadev.com/manage-plist-files-plistbuddy/ + + +#### Test Dataset + + _version_: 1
@@ -24732,6 +30416,22 @@ You must be ingesting data that records process activity from your hosts to popu #### Required field +* _time + +* Processes.parent_process_name + +* Processes.process_name + +* Processes.user + +* Processes.parent_process_name + +* Processes.dest + +* Processes.process_id + +* Processes.parent_process_id + #### ATT&CK @@ -24794,6 +30494,24 @@ You must be ingesting endpoint data that tracks process activity, including pare #### Required field +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process + +* Processes.process_id + +* Processes.parent_process_id + #### ATT&CK @@ -24864,6 +30582,24 @@ To successfully implement this search, you need to be ingesting logs with the pr #### Required field +* _time + +* EventID + +* OriginalFileName + +* process_name + +* Computer + +* User + +* parent_process_name + +* process_path + +* CommandLine + #### ATT&CK @@ -24933,6 +30669,22 @@ To successfully implement this search you need to be ingesting information on pr #### Required field +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_id + +* Processes.parent_process_id + #### ATT&CK @@ -25003,6 +30755,22 @@ To successfully implement this search you need to be ingesting information on pr #### Required field +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_id + +* Processes.parent_process_id + #### ATT&CK @@ -25047,7 +30815,7 @@ _version_: 1 --- -### Suspicious Rundll32 no CommandLine Arguments +### Suspicious Rundll32 no Command Line Arguments The following analytic identifies rundll32.exe with no command line arguments. It is unusual for rundll32.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, identify any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. Rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud @@ -25066,7 +30834,7 @@ The following analytic identifies rundll32.exe with no command line arguments. I | rename Computer as dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` -| `suspicious_rundll32_no_commandline_arguments_filter` +| `suspicious_rundll32_no_command_line_arguments_filter` ``` #### Associated Analytic Story @@ -25080,6 +30848,26 @@ To successfully implement this search, you need to be ingesting logs with the pr #### Required field +* _time + +* EventID + +* process_name + +* OriginalFileName + +* CommandLine + +* dest + +* User + +* ParentImage + +* ParentCommandLine + +* process_path + #### ATT&CK @@ -25113,6 +30901,253 @@ Although unlikely, some legitimate applications may use a moved copy of rundll32 * https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/atomic_red_team/windows-sysmon.log +_version_: 1 + + +--- + +### Suspicious SQLite3 LSQuarantine Behavior +The following analytic identifies the use of a SQLite3 querying the MacOS preferences to identify the original URL the pkg was downloaded from. This particular behavior is common with MacOS adware-malicious software. Upon triage, review other processes in parallel for suspicious activity. Identify any recent package installations. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: Endpoint +- **ATT&CK**: [T1074](https://attack.mitre.org/techniques/T1074/) +- **Last Updated**: 2021-02-22 + +
+ details + +#### Search +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=sqlite3 Processes.process=*LSQuarantine* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `suspicious_sqlite3_lsquarantine_behavior_filter` +``` +#### Associated Analytic Story + +* Silver Sparrow + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. + +#### Required field + +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_id + +* Processes.parent_process_id + + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1074 | Data Staged | Collection | + + +#### Kill Chain Phase + +* Actions on Objectives + + +#### Known False Positives +Unknown. + +#### Reference + +* https://redcanary.com/blog/clipping-silver-sparrows-wings/ + +* https://marcosantadev.com/manage-plist-files-plistbuddy/ + + +#### Test Dataset + + +_version_: 1 +
+ +--- + +### Suspicious Scheduled Task from Public Directory +The following detection identifies Scheduled Tasks registering (creating a new task) a binary or script to run from a public directory which includes users\public, \programdata\ and \windows\temp. Upon triage, review the binary or script in the command line for legitimacy, whether an approved binary/script or not. In addition, capture the binary or script in question and analyze for further behaviors. Identify the source and contain the endpoint. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: Endpoint +- **ATT&CK**: [T1053.005](https://attack.mitre.org/techniques/T1053.005/) +- **Last Updated**: 2021-03-01 + +
+ details + +#### Search +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=schtasks.exe (Processes.process=*\\users\\public\\* OR Processes.process=*\\programdata\\* OR Processes.process=*windows\\temp*) Processes.process=*/create* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `suspicious_scheduled_task_from_public_directory_filter` +``` +#### Associated Analytic Story + +* Ransomware + +* Ryuk Ransomware + +* Windows Persistence Techniques + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. + +#### Required field + +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_name + +* Processes.process_id + +* Processes.parent_process_id + + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1053.005 | Scheduled Task | Execution, Persistence, Privilege Escalation | + + +#### Kill Chain Phase + +* Exploitation + +* Privilege Escalation + + +#### Known False Positives +Limited false positives may be present. Filter as needed by parent process or command line argument. + +#### Reference + +* https://attack.mitre.org/techniques/T1053/005/ + + +#### Test Dataset + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/schtasks/windows-sysmon.log + + +_version_: 1 +
+ +--- + +### Suspicious SearchProtocolHost no Command Line Arguments +The following analytic identifies searchprotocolhost.exe with no command line arguments. It is unusual for searchprotocolhost.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, identify any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. searchprotocolhost.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: +- **ATT&CK**: [T1055](https://attack.mitre.org/techniques/T1055/) +- **Last Updated**: 2021-02-23 + +
+ details + +#### Search +``` +`sysmon` EventID=1 (process_name=searchprotocolhost.exe OR OriginalFileName=SearchProtocolHost.exe) +| regex CommandLine="(searchprotocolhost\.exe.{0,4}$)" +| stats count min(_time) as firstTime max(_time) as lastTime by dest, User, ParentImage,ParentCommandLine, process_name, OriginalFileName, process_path, CommandLine +| rename Computer as dest +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `suspicious_searchprotocolhost_no_command_line_arguments_filter` +``` +#### Associated Analytic Story + +* Cobalt Strike + + +#### How To Implement +To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. + +#### Required field + +* _time + +* EventID + +* process_name + +* OriginalFileName + +* CommandLine + +* dest + +* User + +* ParentImage + +* ParentCommandLine + +* process_path + + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1055 | Process Injection | Defense Evasion, Privilege Escalation | + + +#### Kill Chain Phase + +* Exploitation + + +#### Known False Positives +Limited false positives may be present in small environments. Tuning may be required based on parent process. + +#### Reference + +* https://github.com/fireeye/red_team_tool_countermeasures/blob/master/rules/PGF/supplemental/hxioc/SUSPICIOUS%20EXECUTION%20OF%20SEARCHPROTOCOLHOST%20(METHODOLOGY).ioc + + +#### Test Dataset + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log + + _version_: 1
@@ -25142,12 +31177,32 @@ The following analytic identifies a renamed instance of microsoft.workflow.compi * Trusted Developer Utilities Proxy Execution +* Cobalt Strike + #### How To Implement To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. #### Required field +* _time + +* EventID + +* OriginalFileName + +* process_name + +* Computer + +* User + +* parent_process_name + +* process_path + +* CommandLine + #### ATT&CK @@ -25213,6 +31268,18 @@ To successfully implement this search you need to be ingesting information on pr #### Required field +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.parent_process + +* Processes.user + #### ATT&CK @@ -25271,12 +31338,28 @@ The following analytic identifies msbuild.exe executing from a non-standard path * Trusted Developer Utilities Proxy Execution MSBuild +* Cobalt Strike + #### How To Implement To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. #### Required field +* _time + +* Processes.process_name + +* Processes.process + +* Processes.process_path + +* Processes.dest + +* Processes.parent_process + +* Processes.user + #### ATT&CK @@ -25342,6 +31425,20 @@ To successfully implement this search, you need to be ingesting logs with the pr #### Required field +* _time + +* Processes.process_name + +* Processes.process + +* Processes.parent_process_name + +* Processes.dest + +* Processes.parent_process + +* Processes.user + #### ATT&CK @@ -25406,6 +31503,20 @@ To successfully implement this search you need to be ingesting information on pr #### Required field +* _time + +* Processes.process_name + +* Processes.process + +* Processes.parent_process_name + +* Processes.dest + +* Processes.parent_process + +* Processes.user + #### ATT&CK @@ -25468,12 +31579,26 @@ The wevtutil.exe application is the windows event log utility. This searches for * Ransomware +* Clop Ransomware + #### How To Implement You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. #### Required field +* _time + +* Processes.process + +* Processes.process_name + +* Processes.parent_process_name + +* Processes.dest + +* Processes.user + #### ATT&CK @@ -25533,6 +31658,8 @@ You need to be ingesting logs with both the process name and command-line from y #### Required field +* _time + #### ATT&CK @@ -25591,6 +31718,26 @@ To successfully implement this search you need to be ingesting information on fi #### Required field +* _time + +* Filesystem.file_path + +* Filesystem.file_name + +* Filesystem.process_id + +* Filesystem.dest + +* Processes.user + +* Processes.process_name + +* Processes.parent_process_name + +* Processes.process_id + +* Processes.dest + #### ATT&CK @@ -25652,6 +31799,16 @@ To successfully implement this search you need to be ingesting information on pr #### Required field +* _time + +* Processes.process + +* Processes.user + +* Processes.process_name + +* Processes.dest + #### ATT&CK @@ -25731,6 +31888,8 @@ $cond_6 = ``` #### Associated Analytic Story +* Windows Defense Evasion Tactics + #### How To Implement Collect endpoint data such as sysmon or 4688 events. @@ -25810,6 +31969,22 @@ To successfully implement this search you need to ingest details about process e #### Required field +* _time + +* Processes.process_path + +* Processes.user + +* Processes.dest + +* Processes.process_name + +* Processes.process_id + +* Processes.parent_process_name + +* Processes.process_hash + #### ATT&CK @@ -25868,7 +32043,7 @@ This search looks for network traffic identified as The Onion Router (TOR), a be * Command and Control -* Sunburst Malware +* NOBELIUM Group #### How To Implement @@ -25876,6 +32051,18 @@ In order to properly run this search, Splunk needs to ingest data from firewalls #### Required field +* _time + +* All_Traffic.app + +* All_Traffic.action + +* All_Traffic.src_ip + +* All_Traffic.dest_ip + +* All_Traffic.dest_port + #### ATT&CK @@ -25937,6 +32124,20 @@ You must be ingesting data that records process activity from your hosts to popu #### Required field +* _time + +* Processes.process + +* Processes.parent_process + +* Processes.process_name + +* Processes.user + +* Processes.parent_process_name + +* Processes.dest + #### ATT&CK @@ -25994,14 +32195,14 @@ This search looks for applications on the endpoint that you have marked as uncom * Unusual Processes -* Cloud Federated Credential Abuse - #### How To Implement You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. This search uses a lookup file `uncommon_processes_default.csv` to track various features of process names that are usually uncommon in most environments. Please consider updating `uncommon_processes_local.csv` to hunt for processes that are uncommon in your environment. #### Required field +* _time + #### ATT&CK @@ -26030,6 +32231,88 @@ _version_: 4 --- +### Unified Messaging Service Spawning a Process +This detection identifies Microsoft Exchange Server's Unified Messaging services, umworkerprocess.exe and umservice.exe, spawning a child process, indicating possible exploitation of CVE-2021-26857 vulnerability. The query filters out werfault.exe and wermgr.exe mostly due to potential false positives, however, if there is an excessive amount of "wermgr.exe" or "WerFault.exe" failures, it may be due to the active exploitation. During triage, identify any additional suspicious parallel processes. Identify any recent out of place file modifications. Review Exchange logs following Microsofts guide. To contain, perform egress filtering or restrict public access to Exchange. In final, patch the vulnerablity and monitor. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: Endpoint +- **ATT&CK**: [T1190](https://attack.mitre.org/techniques/T1190/) +- **Last Updated**: 2021-03-02 + +
+ details + +#### Search +``` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name="umworkerprocess.exe" OR Processes.parent_process_name="UMService.exe" (Processes.process_name!="wermgr.exe" OR Processes.process_name!="werfault.exe") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `unified_messaging_service_spawning_a_process_filter` +``` +#### Associated Analytic Story + +* HAFNIUM Group + + +#### How To Implement +To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. + +#### Required field + +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_id + +* Processes.parent_process_id + + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1190 | Exploit Public-Facing Application | Initial Access | + + +#### Kill Chain Phase + +* Exploitation + + +#### Known False Positives +Unknown. Tune out child processes as needed to limit volume of false positives. + +#### Reference + +* https://www.volexity.com/blog/2021/03/02/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities/ + +* https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/ + +* https://blog.rapid7.com/2021/03/03/rapid7s-insightidr-enables-detection-and-response-to-microsoft-exchange-0-day/ + + +#### Test Dataset + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1505.003/windows-sysmon_umservices.log + + +_version_: 1 +
+ +--- + ### Unload Sysmon Filter Driver Attackers often disable security tools to avoid detection. This search looks for the usage of process `fltMC.exe` to unload a Sysmon Driver that will stop sysmon from collecting the data. @@ -26061,6 +32344,20 @@ You must be ingesting data that records process activity from your hosts to popu #### Required field +* _time + +* Processes.process_name + +* Processes.process + +* Processes.process_id + +* Processes.parent_process_name + +* Processes.dest + +* Processes.user + #### ATT&CK @@ -26121,6 +32418,8 @@ This search needs Sysmon Logs with a sysmon configuration, which includes EventC #### Required field +* _time + #### ATT&CK @@ -26182,6 +32481,8 @@ To successfully implement this search you need to obtain data from your backup s #### Required field +* _time + @@ -26232,6 +32533,8 @@ Command lines that are extremely long may be indicative of malicious activity on ``` #### Associated Analytic Story +* Unusual Processes + #### How To Implement You must be ingesting sysmon endpoint data that monitors command lines. @@ -26311,6 +32614,16 @@ You must be ingesting endpoint data that tracks process activity, including pare #### Required field +* _time + +* Processes.user + +* Processes.dest + +* Processes.process_name + +* Processes.process + @@ -26377,6 +32690,16 @@ You must be ingesting endpoint data that monitors command lines and populates th #### Required field +* _time + +* Processes.user + +* Processes.dest + +* Processes.process_name + +* Processes.process + @@ -26428,6 +32751,18 @@ This particular search leverages data extracted from Stream:HTTP. You must confi #### Required field +* _time + +* cs_content_type + +* endtime + +* src_ip + +* dest_ip + +* url + @@ -26445,6 +32780,80 @@ Very few legitimate Content-Type fields will have a length greater than 100 char #### Test Dataset +_version_: 1 + + +--- + +### W3WP Spawning Shell +This query identifies a shell, PowerShell.exe or Cmd.exe, spawning from W3WP.exe, or IIS. In addition to IIS logs, this behavior with an EDR product will capture potential webshell activity, similar to the HAFNIUM Group abusing CVEs, on publicly available Exchange mail servers. During triage, review the parent process and child process of the shell being spawned. Review the command-line arguments and any file modifications that may occur. Identify additional parallel process, child processes, that may highlight further commands executed. After triaging, work to contain the threat and patch the system that is vulnerable. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: Endpoint +- **ATT&CK**: [T1505.003](https://attack.mitre.org/techniques/T1505.003/) +- **Last Updated**: 2021-03-03 + +
+ details + +#### Search +``` + +| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=w3wp.exe AND Processes.process_name=cmd.exe OR Processes.process_name=powershell.exe by Processes.dest Processes.parent_process Processes.user +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `w3wp_spawning_shell_filter` +``` +#### Associated Analytic Story + +* HAFNIUM Group + + +#### How To Implement +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. + +#### Required field + +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1505.003 | Web Shell | Persistence | + + +#### Kill Chain Phase + +* Exploitation + + +#### Known False Positives +Baseline your environment before production. It is possible build systems using IIS will spawn cmd.exe to perform a software build. Filter as needed. + +#### Reference + +* https://www.microsoft.com/security/blog/2020/02/04/ghost-in-the-shell-investigating-web-shell-attacks/ + + +#### Test Dataset + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1505.003/windows-sysmon.log + + _version_: 1
@@ -26482,6 +32891,18 @@ You must be ingesting endpoint data that tracks process activity, including pare #### Required field +* _time + +* Processes.process_name + +* Processes.process + +* Processes.parent_process_name + +* Processes.dest + +* Processes.user + #### ATT&CK @@ -26553,6 +32974,16 @@ To successfully implement this search, you must be ingesting the Windows WMI act #### Required field +* _time + +* EventCode + +* Message + +* consumer + +* ComputerName + #### ATT&CK @@ -26609,6 +33040,24 @@ To successfully implement this search, you must be collecting Sysmon data using #### Required field +* _time + +* EventCode + +* host + +* user + +* Operation + +* EventType + +* Query + +* Consumer + +* Filter + #### ATT&CK @@ -26671,6 +33120,14 @@ To successfully implement this search, you must be ingesting the Windows WMI act #### Required field +* _time + +* EventCode + +* Message + +* query + #### ATT&CK @@ -26732,6 +33189,14 @@ We start with a dataset that provides visibility into the email address used for #### Required field +* _time + +* http_content_type + +* uri + +* cookie + #### ATT&CK @@ -26795,6 +33260,12 @@ Start with a dataset that allows you to see clickstream data for each user click #### Required field +* _time + +* http_content_type + +* cookie + #### ATT&CK @@ -26863,6 +33334,12 @@ We need to start with a dataset that allows us to see the values of usernames an #### Required field +* _time + +* http_content_type + +* uri + @@ -26921,6 +33398,18 @@ You must be ingesting data that records process activity from your hosts to popu #### Required field +* _time + +* Processes.dest_category + +* Processes.process + +* Processes.process_name + +* Processes.dest + +* Processes.user + #### ATT&CK @@ -26971,7 +33460,7 @@ This search looks for the execution of `adfind.exe` with command-line arguments ``` #### Associated Analytic Story -* Sunburst Malware +* NOBELIUM Group #### How To Implement @@ -26979,6 +33468,22 @@ To successfully implement this search, you need to be ingesting logs with the pr #### Required field +* _time + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.process_name + +* Processes.parent_process + +* Processes.process_id + +* Processes.parent_process_id + #### ATT&CK @@ -27014,12 +33519,12 @@ _version_: 1 --- ### Windows DisableAntiSpyware Registry -The search looks for the Registry Key DisableAntiSpyware set to disable. This is consistent with Ryuk infections across a fleet of endpoints. +The search looks for the Registry Key DisableAntiSpyware set to disable. This is consistent with Ryuk infections across a fleet of endpoints. This particular behavior is typically executed when an ransomware actor gains access to an endpoint and beings to perform execution. Usually, a batch (.bat) will be executed and multiple registry and scheduled task modifications will occur. During triage, review parallel processes and identify any further file modifications. Endpoint should be isolated. - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: Endpoint - **ATT&CK**: [T1562.001](https://attack.mitre.org/techniques/T1562.001/) -- **Last Updated**: 2020-11-06 +- **Last Updated**: 2021-03-02
details @@ -27027,7 +33532,7 @@ The search looks for the Registry Key DisableAntiSpyware set to disable. This is #### Search ``` -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_key_name="DisableAntiSpyware" AND Registry.registry_value_name="DWORD (0x00000000)" by Registry.dest Registry.user Registry.registry_path Registry.registry_value_name +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_key_name="DisableAntiSpyware" AND Registry.registry_value_name="DWORD (0x00000001)" by Registry.dest Registry.user Registry.registry_path Registry.registry_value_name | `drop_dm_object_name(Registry)` | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` @@ -27037,12 +33542,26 @@ The search looks for the Registry Key DisableAntiSpyware set to disable. This is * Ryuk Ransomware +* Windows Defense Evasion Tactics + #### How To Implement -You must be ingesting data that records the process-system activity from your hosts to populate the Endpoint Processes data-model object. If you are using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which you want to collect data. +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. #### Required field +* _time + +* Registry.registry_key_name + +* Registry.registry_value_name + +* Registry.dest + +* Registry.user + +* Registry.registry_path + #### ATT&CK @@ -27058,15 +33577,19 @@ You must be ingesting data that records the process-system activity from your ho #### Known False Positives -It is unusual to turn this feature on a Windows system since it is a default security control, although it is not rare for some policies to disable it. Although no false positives have been identified, use the provided filter macro to tune the search. +It is unusual to turn this feature off a Windows system since it is a default security control, although it is not rare for some policies to disable it. Although no false positives have been identified, use the provided filter macro to tune the search. #### Reference +* https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/ + #### Test Dataset +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/atomic_red_team/windows-sysmon.log -_version_: 1 + +_version_: 2
--- @@ -27096,12 +33619,20 @@ This search looks for Windows events that indicate one of the Windows event logs * Ransomware +* Clop Ransomware + #### How To Implement To successfully implement this search, you need to be ingesting Windows event logs from your hosts. #### Required field +* _time + +* EventCode + +* dest + #### ATT&CK @@ -27164,6 +33695,16 @@ You must be ingesting data that records the process-system activity from your ho #### Required field +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + #### ATT&CK @@ -27224,6 +33765,8 @@ You must be ingesting data that records the process-system activity from your ho #### Required field +* _time + #### ATT&CK @@ -27283,6 +33826,8 @@ To successfully implement this search, you must be ingesting data that records t #### Required field +* _time + @@ -27333,6 +33878,10 @@ You must install splunk AWS add-on and Splunk App for AWS. This search works wit #### Required field +* _time + +* requestParameters.policyArn + #### ATT&CK @@ -27390,6 +33939,28 @@ You must install splunk AWS add on and Splunk App for AWS. This search works wit #### Required field +* _time + +* eventName + +* userIdentity.type + +* sourceIPAddress + +* userName userIdentity.type + +* userAgent + +* action + +* status + +* responseElements.accessKey.createDate + +* esponseElements.accessKey.status + +* responseElements.accessKey.accessKeyId + #### ATT&CK @@ -27445,6 +34016,42 @@ You must install splunk AWS add-on and Splunk App for AWS. This search works wit #### Required field +* _time + +* event_name + +* action + +* userIdentity.type + +* requestParameters.description + +* sourceIPAddress + +* userIdentity.principalId + +* userIdentity.arn + +* action + +* event_name + +* awsRegion + +* http_user_agent + +* mfa_auth + +* msg + +* requestParameters.roleName + +* requestParameters.description + +* responseElements.role.arn + +* responseElements.role.createDate + #### ATT&CK @@ -27500,6 +34107,30 @@ You must install splunk AWS add on and Splunk App for AWS. This search works wit #### Required field +* _time + +* user_type + +* userIdentity.sessionContext.sessionIssuer.type + +* sourceIPAddress + +* userIdentity.arn + +* user_agent + +* user_access_key + +* status + +* action + +* requestParameters.roleName + +* esponseElements.role.roleName + +* esponseElements.role.createDate + #### ATT&CK @@ -27557,6 +34188,28 @@ You must install splunk AWS add-on and Splunk App for AWS. This search works wit #### Required field +* _time + +* userIdentity.type + +* eventName + +* sourceIPAddress + +* eventTime + +* userIdentity.arn + +* userName + +* userAgent + +* user_type + +* status + +* region + #### ATT&CK @@ -27612,6 +34265,8 @@ You must install splunk GCP add-on. This search works with gcp:pubsub:message lo #### Required field +* _time + #### ATT&CK diff --git a/docs/detections.wiki b/docs/detections.wiki index 0a13366eb2..b5ad0eaa18 100644 --- a/docs/detections.wiki +++ b/docs/detections.wiki @@ -11,7 +11,7 @@ The search queries the authentication logs for assets that are categorized as ro * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Authentication -* '''ATT&CK''': +* '''ATT&CK''': * '''Last Updated''': 2017-09-12
@@ -20,11 +20,11 @@ The search queries the authentication logs for assets that are categorized as ro ====Search==== | tstats `security_content_summariesonly` count earliest(_time) as earliest latest(_time) as latest from datamodel=Authentication where Authentication.dest_category=router by Authentication.dest Authentication.user -| eval isOutlier=if(earliest >= relative_time(now(), "-30d@d"), 1, 0) +| eval isOutlier=if(earliest >= relative_time(now(), "-30d@d"), 1, 0) | where isOutlier=1 | `security_content_ctime(earliest)` -| `security_content_ctime(latest)` -| `drop_dm_object_name("Authentication")` +| `security_content_ctime(latest)` +| `drop_dm_object_name("Authentication")` | `detect_new_login_attempts_to_routers_filter` ====Associated Analytic Story==== @@ -37,6 +37,14 @@ To successfully implement this search, you must ensure the network router device ====Required field==== +* _time + +* Authentication.dest_category + +* Authentication.dest + +* Authentication.user + @@ -65,7 +73,7 @@ Attackers often use spaces as a means to obfuscate an attachment's file extensio * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Email -* '''ATT&CK''': +* '''ATT&CK''': * '''Last Updated''': 2017-09-19
@@ -73,13 +81,13 @@ Attackers often use spaces as a means to obfuscate an attachment's file extensio ====Search==== -| tstats `security_content_summariesonly` count values(All_Email.recipient) as recipient_address min(_time) as firstTime max(_time) as lastTime from datamodel=Email where All_Email.file_name="*" by All_Email.src_user, All_Email.file_name All_Email.message_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `drop_dm_object_name("All_Email")` -| eval space_ratio = (mvcount(split(file_name," "))-1)/len(file_name) -| search space_ratio >= 0.1 -| rex field=recipient_address "(?.*)@" +| tstats `security_content_summariesonly` count values(All_Email.recipient) as recipient_address min(_time) as firstTime max(_time) as lastTime from datamodel=Email where All_Email.file_name="*" by All_Email.src_user, All_Email.file_name All_Email.message_id +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `drop_dm_object_name("All_Email")` +| eval space_ratio = (mvcount(split(file_name," "))-1)/len(file_name) +| search space_ratio >= 0.1 +| rex field=recipient_address "(?.*)@" | `email_attachments_with_lots_of_spaces_filter` ====Associated Analytic Story==== @@ -96,6 +104,18 @@ If Splunk Phantom is also configured in your environment, a playbook called "Sus ====Required field==== +* _time + +* All_Email.recipient + +* All_Email.file_name + +* All_Email.src_user + +* All_Email.file_name + +* All_Email.message_id + @@ -132,9 +152,9 @@ The search looks at the change-analysis data model and detects email files creat ====Search==== -| tstats `security_content_summariesonly` count values(Filesystem.file_path) as file_path min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Filesystem where (Filesystem.file_name=*.pst OR Filesystem.file_name=*.ost) Filesystem.file_path != "C:\\Users\\*\\My Documents\\Outlook Files\\*" Filesystem.file_path!="C:\\Users\\*\\AppData\\Local\\Microsoft\\Outlook*" by Filesystem.action Filesystem.process_id Filesystem.file_name Filesystem.dest -| `drop_dm_object_name("Filesystem")` -| `security_content_ctime(firstTime)` +| tstats `security_content_summariesonly` count values(Filesystem.file_path) as file_path min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Filesystem where (Filesystem.file_name=*.pst OR Filesystem.file_name=*.ost) Filesystem.file_path != "C:\\Users\\*\\My Documents\\Outlook Files\\*" Filesystem.file_path!="C:\\Users\\*\\AppData\\Local\\Microsoft\\Outlook*" by Filesystem.action Filesystem.process_id Filesystem.file_name Filesystem.dest +| `drop_dm_object_name("Filesystem")` +| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `email_files_written_outside_of_the_outlook_directory_filter` @@ -148,6 +168,18 @@ To successfully implement this search, you must be ingesting data that records t ====Required field==== +* _time + +* Filesystem.file_path + +* Filesystem.file_name + +* Filesystem.action + +* Filesystem.process_id + +* Filesystem.dest + ====ATT&CK==== @@ -195,26 +227,36 @@ This search looks for an increase of data transfers from your email server to yo ====Search==== -| tstats `security_content_summariesonly` sum(All_Traffic.bytes_out) as bytes_out from datamodel=Network_Traffic where All_Traffic.src_category=email_server by All_Traffic.dest_ip _time span=1d -| `drop_dm_object_name("All_Traffic")` -| eventstats avg(bytes_out) as avg_bytes_out stdev(bytes_out) as stdev_bytes_out -| eventstats count as num_data_samples avg(eval(if(_time < relative_time(now(), "@d"), bytes_out, null))) as per_source_avg_bytes_out stdev(eval(if(_time < relative_time(now(), "@d"), bytes_out, null))) as per_source_stdev_bytes_out by dest_ip -| eval minimum_data_samples = 4, deviation_threshold = 3 -| where num_data_samples >= minimum_data_samples AND bytes_out > (avg_bytes_out + (deviation_threshold * stdev_bytes_out)) AND bytes_out > (per_source_avg_bytes_out + (deviation_threshold * per_source_stdev_bytes_out)) AND _time >= relative_time(now(), "@d") -| eval num_standard_deviations_away_from_server_average = round(abs(bytes_out - avg_bytes_out) / stdev_bytes_out, 2), num_standard_deviations_away_from_client_average = round(abs(bytes_out - per_source_avg_bytes_out) / per_source_stdev_bytes_out, 2) -| table dest_ip, _time, bytes_out, avg_bytes_out, per_source_avg_bytes_out, num_standard_deviations_away_from_server_average, num_standard_deviations_away_from_client_average +| tstats `security_content_summariesonly` sum(All_Traffic.bytes_out) as bytes_out from datamodel=Network_Traffic where All_Traffic.src_category=email_server by All_Traffic.dest_ip _time span=1d +| `drop_dm_object_name("All_Traffic")` +| eventstats avg(bytes_out) as avg_bytes_out stdev(bytes_out) as stdev_bytes_out +| eventstats count as num_data_samples avg(eval(if(_time < relative_time(now(), "@d"), bytes_out, null))) as per_source_avg_bytes_out stdev(eval(if(_time < relative_time(now(), "@d"), bytes_out, null))) as per_source_stdev_bytes_out by dest_ip +| eval minimum_data_samples = 4, deviation_threshold = 3 +| where num_data_samples >= minimum_data_samples AND bytes_out > (avg_bytes_out + (deviation_threshold * stdev_bytes_out)) AND bytes_out > (per_source_avg_bytes_out + (deviation_threshold * per_source_stdev_bytes_out)) AND _time >= relative_time(now(), "@d") +| eval num_standard_deviations_away_from_server_average = round(abs(bytes_out - avg_bytes_out) / stdev_bytes_out, 2), num_standard_deviations_away_from_client_average = round(abs(bytes_out - per_source_avg_bytes_out) / per_source_stdev_bytes_out, 2) +| table dest_ip, _time, bytes_out, avg_bytes_out, per_source_avg_bytes_out, num_standard_deviations_away_from_server_average, num_standard_deviations_away_from_client_average | `email_servers_sending_high_volume_traffic_to_hosts_filter` ====Associated Analytic Story==== * [[Documentation:ESSOC:stories:UseCase#Collection_and_Staging|Collection and Staging]] +* [[Documentation:ESSOC:stories:UseCase#HAFNIUM_Group|HAFNIUM Group]] + ====How To Implement==== This search requires you to be ingesting your network traffic and populating the Network_Traffic data model. Your email servers must be categorized as "email_server" for the search to work, as well. You may need to adjust the deviation_threshold and minimum_data_samples values based on the network traffic in your environment. The "deviation_threshold" field is a multiplying factor to control how much variation you're willing to tolerate. The "minimum_data_samples" field is the minimum number of connections of data samples required for the statistic to be valid. ====Required field==== +* _time + +* All_Traffic.bytes_out + +* All_Traffic.src_category + +* All_Traffic.dest_ip + ====ATT&CK==== @@ -254,7 +296,7 @@ This search looks for emails claiming to be sent from a domain similar to one th * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Email -* '''ATT&CK''': +* '''ATT&CK''': * '''Last Updated''': 2018-01-05
@@ -262,15 +304,15 @@ This search looks for emails claiming to be sent from a domain similar to one th ====Search==== -| tstats `security_content_summariesonly` values(All_Email.recipient) as recipients, min(_time) as firstTime, max(_time) as lastTime from datamodel=Email by All_Email.src_user, All_Email.message_id -| `drop_dm_object_name("All_Email")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| eval temp=split(src_user, "@") -| eval email_domain=mvindex(temp, 1) -| lookup update=true brandMonitoring_lookup domain as email_domain OUTPUT domain_abuse -| search domain_abuse=true -| table message_id, src_user, email_domain, recipients, firstTime, lastTime +| tstats `security_content_summariesonly` values(All_Email.recipient) as recipients, min(_time) as firstTime, max(_time) as lastTime from datamodel=Email by All_Email.src_user, All_Email.message_id +| `drop_dm_object_name("All_Email")` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| eval temp=split(src_user, "@") +| eval email_domain=mvindex(temp, 1) +| lookup update=true brandMonitoring_lookup domain as email_domain OUTPUT domain_abuse +| search domain_abuse=true +| table message_id, src_user, email_domain, recipients, firstTime, lastTime | `monitor_email_for_brand_abuse_filter` ====Associated Analytic Story==== @@ -285,6 +327,14 @@ You need to ingest email header data. Specifically the sender's address (src_use ====Required field==== +* _time + +* All_Email.recipient + +* All_Email.src_user + +* All_Email.message_id + @@ -312,7 +362,7 @@ None at this time This search detects Okta login failures due to bad credentials for multiple users originating from the same ip address. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1078.001/ T1078.001] * '''Last Updated''': 2020-07-21 @@ -320,11 +370,11 @@ This search detects Okta login failures due to bad credentials for multiple user
====Search==== -`okta` outcome.reason=INVALID_CREDENTIALS -| rename client.geographicalContext.country as country, client.geographicalContext.state as state, client.geographicalContext.city as city -| stats min(_time) as firstTime max(_time) as lastTime dc(user) as distinct_users values(user) as users by src_ip, displayMessage, outcome.reason, country, state, city -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +`okta` outcome.reason=INVALID_CREDENTIALS +| rename client.geographicalContext.country as country, client.geographicalContext.state as state, client.geographicalContext.city as city +| stats min(_time) as firstTime max(_time) as lastTime dc(user) as distinct_users values(user) as users by src_ip, displayMessage, outcome.reason, country, state, city +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | search distinct_users > 5 | `multiple_okta_users_with_invalid_credentials_from_the_same_ip_filter` @@ -338,6 +388,22 @@ This search is specific to Okta and requires Okta logs are being ingested in you ====Required field==== +* _time + +* outcome.reason + +* client.geographicalContext.country + +* client.geographicalContext.state + +* client.geographicalContext.city + +* user + +* src_ip + +* displayMessage + ====ATT&CK==== @@ -375,7 +441,7 @@ This search looks for Windows endpoints that have not generated an event indicat * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Updates -* '''ATT&CK''': +* '''ATT&CK''': * '''Last Updated''': 2017-09-15
@@ -383,15 +449,15 @@ This search looks for Windows endpoints that have not generated an event indicat ====Search==== -| tstats `security_content_summariesonly` max(_time) as lastTime from datamodel=Updates where Updates.status=Installed Updates.vendor_product="Microsoft Windows" by Updates.dest Updates.status Updates.vendor_product -| rename Updates.dest as Host -| rename Updates.status as "Update Status" -| rename Updates.vendor_product as Product -| eval isOutlier=if(lastTime <= relative_time(now(), "-60d@d"), 1, 0) -| `security_content_ctime(lastTime)` -| search isOutlier=1 -| rename lastTime as "Last Update Time", -| table Host, "Update Status", Product, "Last Update Time" +| tstats `security_content_summariesonly` max(_time) as lastTime from datamodel=Updates where Updates.status=Installed Updates.vendor_product="Microsoft Windows" by Updates.dest Updates.status Updates.vendor_product +| rename Updates.dest as Host +| rename Updates.status as "Update Status" +| rename Updates.vendor_product as Product +| eval isOutlier=if(lastTime <= relative_time(now(), "-60d@d"), 1, 0) +| `security_content_ctime(lastTime)` +| search isOutlier=1 +| rename lastTime as "Last Update Time", +| table Host, "Update Status", Product, "Last Update Time" | `no_windows_updates_in_a_time_frame_filter` ====Associated Analytic Story==== @@ -404,6 +470,14 @@ To successfully implement this search, it requires that the 'Update' data model ====Required field==== +* _time + +* Updates.status + +* Updates.vendor_product + +* Updates.dest + @@ -429,7 +503,7 @@ None identified Detect Okta user lockout events * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1078.001/ T1078.001] * '''Last Updated''': 2020-07-21 @@ -437,9 +511,9 @@ Detect Okta user lockout events
====Search==== -`okta` displayMessage="Max sign in attempts exceeded" -| rename client.geographicalContext.country as country, client.geographicalContext.state as state, client.geographicalContext.city as city -| table _time, user, country, state, city, src_ip +`okta` displayMessage="Max sign in attempts exceeded" +| rename client.geographicalContext.country as country, client.geographicalContext.state as state, client.geographicalContext.city as city +| table _time, user, country, state, city, src_ip | `okta_account_lockout_events_filter` ====Associated Analytic Story==== @@ -452,6 +526,16 @@ This search is specific to Okta and requires Okta logs are being ingested in you ====Required field==== +* _time + +* displayMessage + +* client.geographicalContext.country + +* client.geographicalContext.state + +* client.geographicalContext.city + ====ATT&CK==== @@ -488,7 +572,7 @@ None. Account lockouts should be followed up on to determine if the actual user Detect failed Okta SSO events * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1078.001/ T1078.001] * '''Last Updated''': 2020-07-21 @@ -496,10 +580,10 @@ Detect failed Okta SSO events
====Search==== -`okta` displayMessage="User attempted unauthorized access to app" -| stats min(_time) as firstTime max(_time) as lastTime values(app) as Apps count by user, result ,displayMessage, src_ip -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +`okta` displayMessage="User attempted unauthorized access to app" +| stats min(_time) as firstTime max(_time) as lastTime values(app) as Apps count by user, result ,displayMessage, src_ip +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `okta_failed_sso_attempts_filter` ====Associated Analytic Story==== @@ -512,6 +596,18 @@ This search is specific to Okta and requires Okta logs are being ingested in you ====Required field==== +* _time + +* displayMessage + +* app + +* user + +* result + +* src_ip + ====ATT&CK==== @@ -548,7 +644,7 @@ There may be a faulty config preventing legitmate users from accessing apps they This search detects logins from the same user from different cities in a 24 hour period. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1078.001/ T1078.001] * '''Last Updated''': 2020-07-21 @@ -556,11 +652,11 @@ This search detects logins from the same user from different cities in a 24 hour
====Search==== -`okta` displayMessage="User login to Okta" client.geographicalContext.city!=null -| stats min(_time) as firstTime max(_time) as lastTime dc(client.geographicalContext.city) as locations values(client.geographicalContext.city) as cities values(client.geographicalContext.state) as states by user +`okta` displayMessage="User login to Okta" client.geographicalContext.city!=null +| stats min(_time) as firstTime max(_time) as lastTime dc(client.geographicalContext.city) as locations values(client.geographicalContext.city) as cities values(client.geographicalContext.state) as states by user | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `okta_user_logins_from_multiple_cities_filter` +| `security_content_ctime(lastTime)` +| `okta_user_logins_from_multiple_cities_filter` | search locations > 1 ====Associated Analytic Story==== @@ -573,6 +669,16 @@ This search is specific to Okta and requires Okta logs are being ingested in you ====Required field==== +* _time + +* displayMessage + +* client.geographicalContext.city + +* client.geographicalContext.state + +* user + ====ATT&CK==== @@ -609,7 +715,7 @@ Users in your enviornment may legitmately be travelling and loggin in from diffe Malicious mails can conduct phishing that induces readers to open attachment, click links or trigger third party service. This detect uses Natural Language Processing (NLP) approach to analyze an email message's content (Sender, Subject and Body) and judge whether it is a phishing email. The detection adopts a deep learning (neural network) model that employs character level embeddings plus LSTM layers to perform classification. The model is pre-trained and then published as ONNX format. Current sample model is trained using the dataset published at https://github.com/splunk/attack_data/tree/master/datasets/T1566_Phishing_Email/splunk_train.json User are expected to re-train the model by combining with their own training data for better accuracy using the provided model file (SMLE notebook). DSP pipeline then processes the email message and passes it as an event to Apply ML Models function, which returns the probability of a phishing email. Current implementation assumes the email is fed to DSP in JSON format contains at least email's sender, subject and its message body, including reply content, if any. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566] * '''Last Updated''': 2020-08-25 @@ -618,16 +724,16 @@ Malicious mails can conduct phishing that induces readers to open attachment, cl ====Search==== -| from read_ssa_enriched_events() -| eval eventLine=concat(ucast(map_get(input_event, "From"), "string", " "), " ", ucast(map_get(input_event, "Subject"), "string", " "), " ", ucast(map_get(input_event, "Content"), "string", " "), " "), _time=map_get(input_event, "_time") -| where eventLine IS NOT NULL +| from read_ssa_enriched_events() +| eval eventLine=concat(ucast(map_get(input_event, "From"), "string", " "), " ", ucast(map_get(input_event, "Subject"), "string", " "), " ", ucast(map_get(input_event, "Content"), "string", " "), " "), _time=map_get(input_event, "_time") +| where eventLine IS NOT NULL | eval mapC={" ": 32, "!": 33, "\"": 34, "#": 35, "$": 36, "%": 37, "&": 38, "`": 39, "(": 40, ")": 41, "*": 42, "+": 43, ",": 44, "-": 45, ".": 46, "/": 47, "0": 48, "1": 49, "2": 50, "3": 51, "4": 52, "5": 53, "6": 54, "7": 55, "8": 56, "9": 57, ":": 58, ";": 59, "<": 60, "=": 61, ">": 62, "?": 63, "@": 64, "A": 65, "B": 66, "C": 67, "D": 68, "E": 69, "F": 70, "G": 71, "H": 72, "I": 73, "J": 74, "K": 75, "L": 76, "M": 77, "N": 78, "O": 79, "P": 80, "Q": 81, "R": 82, "S": 83, "T": 84, "U": 85, "V": 86, "W": 87, "X": 88, "Y": 89, "Z": 90, "[": 91, "\\": 92, "]": 93, "^": 94, "_": 95, "`": 96, "a": 97, "b": 98, "c": 99, "d": 100, "e": 101, "f": 102, "g": 103, "h": 104, "i": 105, "j": 106, "k": 107, "l": 108, "m": 109, "n": 110, "o": 111, "p": 112, "q": 113, "r": 114, "s": 115, "t": 116, "u": 117, "v": 118, "w": 119, "x": 120, "y": 121, "z": 122, "{": 123, " -|": 124, "}": 125, "~": 126}, ml_in = for_each(iterator(mvrange(1,129), "i"), cast(map_get(mapC, substr(eventLine, i, 1)), "float") ) -| apply_model connection_id="YOUR_S3_ONNX_CONNECTOR_ID" name="phishing_email_v8" path="s3://smle-experiments/models/phishing_email" -| eval probability = mvindex(ml_out, 0) -| where probability > 0.5 -| eval start_time=_time, end_time=_time, entities="TBD", body="TBD" -| select probability, body, entities, start_time, end_time +|": 124, "}": 125, "~": 126}, ml_in = for_each(iterator(mvrange(1,129), "i"), cast(map_get(mapC, substr(eventLine, i, 1)), "float") ) +| apply_model connection_id="YOUR_S3_ONNX_CONNECTOR_ID" name="phishing_email_v8" path="s3://smle-experiments/models/phishing_email" +| eval probability = mvindex(ml_out, 0) +| where probability > 0.5 +| eval start_time=_time, end_time=_time, entities="TBD", body="TBD" +| select probability, body, entities, start_time, end_time | into write_ssa_detected_events(); ====Associated Analytic Story==== @@ -672,120 +778,6 @@ Because of imbalance of anomaly data in training, the model will less likely rep ---- -===Spectre and meltdown vulnerable systems=== -The search is used to detect systems that are still vulnerable to the Spectre and Meltdown vulnerabilities. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Vulnerabilities -* '''ATT&CK''': -* '''Last Updated''': 2017-01-07 - -
-
- -====Search==== - -| tstats `security_content_summariesonly` min(_time) as firstTime max(_time) as lastTime from datamodel=Vulnerabilities where Vulnerabilities.cve ="CVE-2017-5753" OR Vulnerabilities.cve ="CVE-2017-5715" OR Vulnerabilities.cve ="CVE-2017-5754" by Vulnerabilities.dest -| `drop_dm_object_name(Vulnerabilities)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `spectre_and_meltdown_vulnerable_systems_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Spectre_And_Meltdown_Vulnerabilities|Spectre And Meltdown Vulnerabilities]] - - -====How To Implement==== -The search requires that you are ingesting your vulnerability-scanner data and that it reports the CVE of the vulnerability identified. - -====Required field==== - - - - -====Kill Chain Phase==== - - -====Known False Positives==== -It is possible that your vulnerability scanner is not detecting that the patches have been applied. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Suspicious email - uba anomaly=== -This detection looks for emails that are suspicious because of their sender, domain rareness, or behavior differences. This is an anomaly generated by Splunk User Behavior Analytics (UBA). - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': UEBA -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566] -* '''Last Updated''': 2020-07-22 - -
-
- -====Search==== - -|tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(All_UEBA_Events.category) as category from datamodel=UEBA where nodename=All_UEBA_Events.UEBA_Anomalies All_UEBA_Events.UEBA_Anomalies.uba_model = "SuspiciousEmailDetectionModel" by All_UEBA_Events.description All_UEBA_Events.severity All_UEBA_Events.user All_UEBA_Events.uba_event_type All_UEBA_Events.link All_UEBA_Events.signature All_UEBA_Events.url All_UEBA_Events.UEBA_Anomalies.uba_model -| `drop_dm_object_name(All_UEBA_Events)` -| `drop_dm_object_name(UEBA_Anomalies)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_email___uba_anomaly_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Suspicious_Emails|Suspicious Emails]] - - -====How To Implement==== -You must be ingesting data from email logs and have Splunk integrated with UBA. This anomaly is raised by a UBA detection model called "SuspiciousEmailDetectionModel." Ensure that this model is enabled on your UBA instance. - -====Required field==== - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1566 -| Phishing -| Initial Access -|} - - -====Kill Chain Phase==== - -* Delivery - - -====Known False Positives==== -This detection model will alert on any sender domain that is seen for the first time. This could be a potential false positive. The next step is to investigate and add the URL to an allow list if you determine that it is a legitimate sender. - -====Reference==== - - -====Test Dataset==== - - -''version'': 3 -
-
- ----- - ===Suspicious email attachment extensions=== This search looks for emails that have attachments with suspicious file extensions. @@ -799,11 +791,11 @@ This search looks for emails that have attachments with suspicious file extensio ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Email where All_Email.file_name="*" by All_Email.src_user, All_Email.file_name All_Email.message_id -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `drop_dm_object_name("All_Email")` -| `suspicious_email_attachments` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Email where All_Email.file_name="*" by All_Email.src_user, All_Email.file_name All_Email.message_id +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `drop_dm_object_name("All_Email")` +| `suspicious_email_attachments` | `suspicious_email_attachment_extensions_filter` ====Associated Analytic Story==== @@ -820,6 +812,14 @@ If Splunk Phantom is also configured in your environment, a Playbook called "Sus ====Required field==== +* _time + +* All_Email.file_name + +* All_Email.src_user + +* All_Email.message_id + ====ATT&CK==== @@ -858,21 +858,21 @@ None identified This search looks for suspicious Java classes that are often used to exploit remote command execution in common Java frameworks, such as Apache Struts. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': +* '''Datamodel''': +* '''ATT&CK''': * '''Last Updated''': 2018-12-06
====Search==== -`stream_http` http_method=POST http_content_length>1 +`stream_http` http_method=POST http_content_length>1 | regex form_data="(?i)java\.lang\.(?:runtime -|processbuilder)" -| rename src_ip as src -| stats count earliest(_time) as firstTime, latest(_time) as lastTime, values(url) as uri, values(status) as status, values(http_user_agent) as http_user_agent by src, dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +|processbuilder)" +| rename src_ip as src +| stats count earliest(_time) as firstTime, latest(_time) as lastTime, values(url) as uri, values(status) as status, values(http_user_agent) as http_user_agent by src, dest +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `suspicious_java_classes_filter` ====Associated Analytic Story==== @@ -885,6 +885,24 @@ In order to properly run this search, Splunk needs to ingest data from your web- ====Required field==== +* _time + +* http_method + +* http_content_length + +* src_ip + +* url + +* status + +* http_user_agent + +* src + +* dest + @@ -922,9 +940,9 @@ This search looks for suspicious processes on all systems labeled as web servers ====Search==== | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.dest_category="web_server" AND (Processes.process="*whoami*" OR Processes.process="*ping*" OR Processes.process="*iptables*" OR Processes.process="*wget*" OR Processes.process="*service*" OR Processes.process="*curl*") by Processes.process Processes.process_name, Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `web_servers_executing_suspicious_processes_filter` ====Associated Analytic Story==== @@ -937,6 +955,18 @@ You must be ingesting data that records process activity from your hosts to popu ====Required field==== +* _time + +* Processes.dest_category + +* Processes.process + +* Processes.process_name + +* Processes.dest + +* Processes.user + ====ATT&CK==== @@ -976,12 +1006,256 @@ Some of these processes may be used legitimately on web servers during maintenan ==Cloud== +===Aws create policy version to allow all resources=== +This search looks for CloudTrail events where a user created a policy version that allows them to access any resource in their account + +* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078.004/ T1078.004] +* '''Last Updated''': 2021-02-22 + +
+
+ +====Search==== +`cloudtrail` eventName=CreatePolicyVersion eventSource = iam.amazonaws.com errorCode = success +| spath input=requestParameters.policyDocument output=key_policy_statements path=Statement{} +| mvexpand key_policy_statements +| spath input=key_policy_statements output=key_policy_action_1 path=Action +| search key_policy_action_1 = "*" +| stats count min(_time) as firstTime max(_time) as lastTime values(key_policy_statements) as policy_added by eventName eventSource aws_account_id errorCode userAgent eventID awsRegion userIdentity.principalId user_arn +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +|`aws_create_policy_version_to_allow_all_resources_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#AWS_IAM_Privilege_Escalation|AWS IAM Privilege Escalation]] + + +====How To Implement==== +You must install splunk AWS add on and Splunk App for AWS. This search works with cloudtrail logs. + +====Required field==== + +* _time + +* eventName + +* userAgent + +* errorCode + +* requestParameters.userName + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1078.004 +| Cloud Accounts +| Defense Evasion, Initial Access, Persistence, Privilege Escalation +|} + + +====Kill Chain Phase==== + +* Actions on Objectives + + +====Known False Positives==== +While this search has no known false positives, it is possible that an AWS admin has legitimately created a policy to allow a user to access all resources. That said, AWS strongly advises against granting full control to all AWS resources + +====Reference==== + +* https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws + +* https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/ + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_create_policy_version/aws_cloudtrail_events.json + + +''version'': 2 +
+
+ +---- + +===Aws createaccesskey=== +This search looks for CloudTrail events where a user A who has already permission to create access keys, makes an API call to create access keys for another user B. Attackers have been know to use this technique for Privilege Escalation in case new victim(user B) has more permissions than old victim(user B) + +* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1136.003/ T1136.003] +* '''Last Updated''': 2021-03-02 + +
+
+ +====Search==== +`cloudtrail` eventName = CreateAccessKey userAgent !=console.amazonaws.com errorCode = success +| search userName!=requestParameters.userName +| stats count min(_time) as firstTime max(_time) as lastTime by requestParameters.userName src eventName eventSource aws_account_id errorCode userAgent eventID awsRegion userIdentity.principalId user_arn +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +|`aws_createaccesskey_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#AWS_IAM_Privilege_Escalation|AWS IAM Privilege Escalation]] + + +====How To Implement==== +You must install splunk AWS add on and Splunk App for AWS. This search works with cloudtrail logs. + +====Required field==== + +* _time + +* eventName + +* userAgent + +* errorCode + +* requestParameters.userName + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1136.003 +| Cloud Account +| Persistence +|} + + +====Kill Chain Phase==== + +* Actions on Objectives + + +====Known False Positives==== +While this search has no known false positives, it is possible that an AWS admin has legitimately created keys for another user. + +====Reference==== + +* https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws + +* https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/ + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_createaccesskey/aws_cloudtrail_events.json + + +''version'': 1 +
+
+ +---- + +===Aws createloginprofile=== +This search looks for CloudTrail events where a user A(victim A) creates a login profile for user B, followed by a AWS Console login event from user B from the same src_ip as user B. This correlated event can be indicative of privilege escalation since both events happened from the same src_ip + +* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1136.003/ T1136.003] +* '''Last Updated''': 2021-03-02 + +
+
+ +====Search==== +`cloudtrail` eventName = CreateLoginProfile +| rename requestParameters.userName as new_login_profile +| table src_ip eventName new_login_profile userName +| join new_login_profile src_ip [ +| search `cloudtrail` eventName = ConsoleLogin +| rename userName as new_login_profile +| stats count values(eventName) min(_time) as firstTime max(_time) as lastTime by eventSource aws_account_id errorCode userAgent eventID awsRegion userIdentity.principalId user_arn new_login_profile src_ip +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)`] +| `aws_createloginprofile_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#AWS_IAM_Privilege_Escalation|AWS IAM Privilege Escalation]] + + +====How To Implement==== +You must install splunk AWS add on and Splunk App for AWS. This search works with cloudtrail logs. + +====Required field==== + +* _time + +* eventName + +* userAgent + +* errorCode + +* requestParameters.userName + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1136.003 +| Cloud Account +| Persistence +|} + + +====Kill Chain Phase==== + +* Actions on Objectives + + +====Known False Positives==== +While this search has no known false positives, it is possible that an AWS admin has legitimately created a login profile for another user. + +====Reference==== + +* https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws + +* https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/ + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_createloginprofile/aws_cloudtrail_events.json + + +''version'': 1 +
+
+ +---- + ===Aws cross account activity from previously unseen account=== This search looks for AssumeRole events where an IAM role in a different account is requested for the first time. This search is deprecated and have been translated to use the latest Authentication Datamodel. * '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Authentication -* '''ATT&CK''': +* '''ATT&CK''': * '''Last Updated''': 2020-05-28
@@ -989,15 +1263,15 @@ This search looks for AssumeRole events where an IAM role in a different account ====Search==== -| tstats min(_time) as firstTime max(_time) as lastTime from datamodel=Authentication where Authentication.signature=AssumeRole by Authentication.vendor_account Authentication.user Authentication.src Authentication.user_role -| `drop_dm_object_name(Authentication)` -| rex field=user_role "arn:aws:sts:*:(?.*):" -| where vendor_account != dest_account -| rename vendor_account as requestingAccountId dest_account as requestedAccountId -| lookup previously_seen_aws_cross_account_activity requestingAccountId, requestedAccountId, OUTPUTNEW firstTime -| eval status = if(firstTime > relative_time(now(), "-24h@h"),"New Cross Account Activity","Previously Seen") -| where status = "New Cross Account Activity" -| `security_content_ctime(firstTime)` +| tstats min(_time) as firstTime max(_time) as lastTime from datamodel=Authentication where Authentication.signature=AssumeRole by Authentication.vendor_account Authentication.user Authentication.src Authentication.user_role +| `drop_dm_object_name(Authentication)` +| rex field=user_role "arn:aws:sts:*:(?.*):" +| where vendor_account != dest_account +| rename vendor_account as requestingAccountId dest_account as requestedAccountId +| lookup previously_seen_aws_cross_account_activity requestingAccountId, requestedAccountId, OUTPUTNEW firstTime +| eval status = if(firstTime > relative_time(now(), "-24h@h"),"New Cross Account Activity","Previously Seen") +| where status = "New Cross Account Activity" +| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_cross_account_activity_from_previously_unseen_account_filter` @@ -1011,6 +1285,18 @@ You must be ingesting your cloud infrastructure logs from your cloud provider. Y ====Required field==== +* _time + +* Authentication.signature + +* Authentication.vendor_account + +* Authentication.user + +* Authentication.user_role + +* Authentication.src + @@ -1039,8 +1325,8 @@ Using multiple AWS accounts and roles is perfectly valid behavior. It's suspicio ===Aws detect users creating keys with encrypt policy without mfa=== This search provides detection of KMS keys which action kms:Encrypt is accessible for everyone (also outside of your organization). This is an identicator that your account is compromised and the attacker uses the encryption key to compromise another company. -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1486/ T1486] * '''Last Updated''': 2021-01-11 @@ -1048,17 +1334,17 @@ This search provides detection of KMS keys which action kms:Encrypt is accessibl
====Search==== -`cloudtrail` eventName=CreateKey OR eventName=PutKeyPolicy -| spath input=requestParameters.policy output=key_policy_statements path=Statement{} -| mvexpand key_policy_statements -| spath input=key_policy_statements output=key_policy_action_1 path=Action -| spath input=key_policy_statements output=key_policy_action_2 path=Action{} -| eval key_policy_action=mvappend(key_policy_action_1, key_policy_action_2) -| spath input=key_policy_statements output=key_policy_principal path=Principal.AWS -| search key_policy_action="kms:Encrypt" AND key_policy_principal="*" -| stats count min(_time) as firstTime max(_time) as lastTime by eventName eventSource eventID awsRegion userIdentity.principalId +`cloudtrail` eventName=CreateKey OR eventName=PutKeyPolicy +| spath input=requestParameters.policy output=key_policy_statements path=Statement{} +| mvexpand key_policy_statements +| spath input=key_policy_statements output=key_policy_action_1 path=Action +| spath input=key_policy_statements output=key_policy_action_2 path=Action{} +| eval key_policy_action=mvappend(key_policy_action_1, key_policy_action_2) +| spath input=key_policy_statements output=key_policy_principal path=Principal.AWS +| search key_policy_action="kms:Encrypt" AND key_policy_principal="*" +| stats count min(_time) as firstTime max(_time) as lastTime by eventName eventSource eventID awsRegion userIdentity.principalId | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` |`aws_detect_users_creating_keys_with_encrypt_policy_without_mfa_filter` ====Associated Analytic Story==== @@ -1071,6 +1357,20 @@ You must install splunk AWS add on and Splunk App for AWS. This search works wit ====Required field==== +* _time + +* eventName + +* eventSource + +* eventID + +* awsRegion + +* requestParameters.policy + +* userIdentity.principalId + ====ATT&CK==== @@ -1114,8 +1414,8 @@ unknown ===Aws detect users with kms keys performing encryption s3=== This search provides detection of users with KMS keys performing encryption specifically against S3 buckets. -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1486/ T1486] * '''Last Updated''': 2021-01-11 @@ -1123,11 +1423,11 @@ This search provides detection of users with KMS keys performing encryption spec
====Search==== -`cloudtrail` eventName=CopyObject requestParameters.x-amz-server-side-encryption="aws:kms" -| rename requestParameters.bucketName AS bucket_name, requestParameters.x-amz-copy-source AS src_file, requestParameters.key AS dest_file -| stats count min(_time) as firstTime max(_time) as lastTime values(src_file) AS src_file values(dest_file) AS dest_file values(userAgent) AS userAgent values(region) AS region values(src) AS src by user +`cloudtrail` eventName=CopyObject requestParameters.x-amz-server-side-encryption="aws:kms" +| rename requestParameters.bucketName AS bucket_name, requestParameters.x-amz-copy-source AS src_file, requestParameters.key AS dest_file +| stats count min(_time) as firstTime max(_time) as lastTime values(src_file) AS src_file values(dest_file) AS dest_file values(userAgent) AS userAgent values(region) AS region values(src) AS src by user | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` |`aws_detect_users_with_kms_keys_performing_encryption_s3_filter` ====Associated Analytic Story==== @@ -1140,6 +1440,22 @@ You must install splunk AWS add on and Splunk App for AWS. This search works wit ====Required field==== +* _time + +* eventName + +* requestParameters.x-amz-server-side-encryption + +* requestParameters.bucketName + +* requestParameters.x-amz-copy-source + +* requestParameters.key + +* userAgent + +* region + ====ATT&CK==== @@ -1174,56 +1490,6 @@ bucket with S3 encryption * https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1486/s3_file_encryption/aws_cloudtrail_events.json -''version'': 1 -
-
- ----- - -===Aws eks kubernetes cluster sensitive object access=== -This search provides information on Kubernetes accounts accessing sensitve objects such as configmaps or secrets - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': -* '''Last Updated''': 2020-06-23 - -
-
- -====Search==== -`aws_cloudwatchlogs_eks` objectRef.resource=secrets OR configmaps sourceIPs{}!=::1 sourceIPs{}!=127.0.0.1 -|table sourceIPs{} user.username user.groups{} objectRef.resource objectRef.namespace objectRef.name annotations.authorization.k8s.io/reason -|dedup user.username user.groups{} -|`aws_eks_kubernetes_cluster_sensitive_object_access_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Sensitive_Object_Access_Activity|Kubernetes Sensitive Object Access Activity]] - - -====How To Implement==== -You must install Splunk Add-on for Amazon Web Services and Splunk App for AWS. This search works with cloudwatch logs. - -====Required field==== - - - - -====Kill Chain Phase==== - -* Lateral Movement - - -====Known False Positives==== -Sensitive object access is not necessarily malicious but user and object context can provide guidance for detection. - -====Reference==== - - -====Test Dataset==== - - ''version'': 1
@@ -1233,8 +1499,8 @@ Sensitive object access is not necessarily malicious but user and object context ===Aws network access control list created with all open ports=== The search looks for CloudTrail events to detect if any network ACLs were created with all the ports open to a specified CIDR. -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1562.007/ T1562.007] * '''Last Updated''': 2021-01-11 @@ -1242,14 +1508,14 @@ The search looks for CloudTrail events to detect if any network ACLs were create
====Search==== -`cloudtrail` eventName=CreateNetworkAclEntry OR eventName=ReplaceNetworkAclEntry requestParameters.ruleAction=allow requestParameters.egress=false requestParameters.aclProtocol=-1 -| append [search `cloudtrail` eventName=CreateNetworkAclEntry OR eventName=ReplaceNetworkAclEntry requestParameters.ruleAction=allow requestParameters.egress=false requestParameters.aclProtocol!=-1 -| eval port_range='requestParameters.portRange.to' - 'requestParameters.portRange.from' -| where port_range>1024] -| fillnull -| stats count min(_time) as firstTime max(_time) as lastTime by userName userIdentity.principalId eventName requestParameters.ruleAction requestParameters.egress requestParameters.aclProtocol requestParameters.portRange.to requestParameters.portRange.from src userAgent requestParameters.cidrBlock +`cloudtrail` eventName=CreateNetworkAclEntry OR eventName=ReplaceNetworkAclEntry requestParameters.ruleAction=allow requestParameters.egress=false requestParameters.aclProtocol=-1 +| append [search `cloudtrail` eventName=CreateNetworkAclEntry OR eventName=ReplaceNetworkAclEntry requestParameters.ruleAction=allow requestParameters.egress=false requestParameters.aclProtocol!=-1 +| eval port_range='requestParameters.portRange.to' - 'requestParameters.portRange.from' +| where port_range>1024] +| fillnull +| stats count min(_time) as firstTime max(_time) as lastTime by userName userIdentity.principalId eventName requestParameters.ruleAction requestParameters.egress requestParameters.aclProtocol requestParameters.portRange.to requestParameters.portRange.from src userAgent requestParameters.cidrBlock | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | `aws_network_access_control_list_created_with_all_open_ports_filter` ====Associated Analytic Story==== @@ -1262,6 +1528,28 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- ====Required field==== +* _time + +* eventName + +* requestParameters.ruleAction + +* requestParameters.egress + +* requestParameters.aclProtocol + +* requestParameters.portRange.to + +* requestParameters.portRange.from + +* requestParameters.cidrBlock + +* userName + +* userIdentity.principalId + +* userAgent + ====ATT&CK==== @@ -1301,8 +1589,8 @@ It's possible that an admin has created this ACL with all ports open for some le ===Aws network access control list deleted=== Enforcing network-access controls is one of the defensive mechanisms used by cloud administrators to restrict access to a cloud instance. After the attacker has gained control of the AWS console by compromising an admin account, they can delete a network ACL and gain access to the instance from anywhere. This search will query the CloudTrail logs to detect users deleting network ACLs. -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1562.007/ T1562.007] * '''Last Updated''': 2021-01-12 @@ -1310,11 +1598,11 @@ Enforcing network-access controls is one of the defensive mechanisms used by clo
====Search==== -`cloudtrail` eventName=DeleteNetworkAclEntry requestParameters.egress=false -| fillnull -| stats count min(_time) as firstTime max(_time) as lastTime by userName userIdentity.principalId eventName requestParameters.egress src userAgent +`cloudtrail` eventName=DeleteNetworkAclEntry requestParameters.egress=false +| fillnull +| stats count min(_time) as firstTime max(_time) as lastTime by userName userIdentity.principalId eventName requestParameters.egress src userAgent | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | `aws_network_access_control_list_deleted_filter` ====Associated Analytic Story==== @@ -1327,6 +1615,20 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- ====Required field==== +* _time + +* eventName + +* requestParameters.egress + +* userName + +* userIdentity.principalId + +* src + +* userAgent + ====ATT&CK==== @@ -1366,8 +1668,8 @@ It's possible that a user has legitimately deleted a network ACL. ===Aws saml access by provider user and principal=== This search provides specific SAML access from specific Service Provider, user and targeted principal at AWS. This search provides specific information to detect abnormal access or potential credential hijack or forgery, specially in federated environments using SAML protocol inside the perimeter or cloud provider. -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078] * '''Last Updated''': 2021-01-26 @@ -1375,10 +1677,10 @@ This search provides specific SAML access from specific Service Provider, user a
====Search==== -`cloudtrail` eventName=Assumerolewithsaml -| stats count min(_time) as firstTime max(_time) as lastTime by requestParameters.principalArn requestParameters.roleArn requestParameters.roleSessionName recipientAccountId responseElements.issuer sourceIPAddress userAgent +`cloudtrail` eventName=Assumerolewithsaml +| stats count min(_time) as firstTime max(_time) as lastTime by requestParameters.principalArn requestParameters.roleArn requestParameters.roleSessionName recipientAccountId responseElements.issuer sourceIPAddress userAgent | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` |`aws_saml_access_by_provider_user_and_principal_filter` ====Associated Analytic Story==== @@ -1391,6 +1693,24 @@ You must install splunk AWS add on and Splunk App for AWS. This search works wit ====Required field==== +* _time + +* eventName + +* requestParameters.principalArn + +* requestParameters.roleArn + +* requestParameters.roleSessionName + +* recipientAccountId + +* responseElements.issuer + +* sourceIPAddress + +* userAgent + ====ATT&CK==== @@ -1436,8 +1756,8 @@ Attacks using a Golden SAML or SAML assertion hijacks or forgeries are very diff ===Aws saml update identity provider=== This search provides detection of updates to SAML provider in AWS. Updates to SAML provider need to be monitored closely as they may indicate possible perimeter compromise of federated credentials, or backdoor access from another cloud provider set by attacker. -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078] * '''Last Updated''': 2021-01-26 @@ -1445,10 +1765,10 @@ This search provides detection of updates to SAML provider in AWS. Updates to SA
====Search==== -`cloudtrail` eventName=UpdateSAMLProvider -| stats count min(_time) as firstTime max(_time) as lastTime by eventType eventName requestParameters.sAMLProviderArn userIdentity.sessionContext.sessionIssuer.arn sourceIPAddress userIdentity.accessKeyId userIdentity.principalId +`cloudtrail` eventName=UpdateSAMLProvider +| stats count min(_time) as firstTime max(_time) as lastTime by eventType eventName requestParameters.sAMLProviderArn userIdentity.sessionContext.sessionIssuer.arn sourceIPAddress userIdentity.accessKeyId userIdentity.principalId | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` |`aws_saml_update_identity_provider_filter` ====Associated Analytic Story==== @@ -1461,6 +1781,22 @@ You must install splunk AWS add on and Splunk App for AWS. This search works wit ====Required field==== +* _time + +* eventName + +* eventType + +* requestParameters.sAMLProviderArn + +* userIdentity.sessionContext.sessionIssuer.arn + +* sourceIPAddress + +* userIdentity.accessKeyId + +* userIdentity.principalId + ====ATT&CK==== @@ -1497,6 +1833,165 @@ Updating a SAML provider or creating a new one may not necessarily be malicious * https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/update_saml_provider/update_saml_provider.json +''version'': 1 +
+
+ +---- + +===Aws setdefaultpolicyversion=== +This search looks for CloudTrail events where a user has set a default policy versions. Attackers have been know to use this technique for Privilege Escalation in case the previous versions of the policy had permissions to access more resources than the current version of the policy + +* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078.004/ T1078.004] +* '''Last Updated''': 2021-03-02 + +
+
+ +====Search==== +`cloudtrail` eventName=SetDefaultPolicyVersion eventSource = iam.amazonaws.com +| stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.policyArn) as policy_arn by src requestParameters.versionId eventName eventSource aws_account_id errorCode userAgent eventID awsRegion userIdentity.principalId user_arn +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `aws_setdefaultpolicyversion_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#AWS_IAM_Privilege_Escalation|AWS IAM Privilege Escalation]] + + +====How To Implement==== +You must install splunk AWS add on and Splunk App for AWS. This search works with cloudtrail logs. + +====Required field==== + +* _time + +* eventName + +* userAgent + +* errorCode + +* requestParameters.userName + +* eventSource + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1078.004 +| Cloud Accounts +| Defense Evasion, Initial Access, Persistence, Privilege Escalation +|} + + +====Kill Chain Phase==== + +* Actions on Objectives + + +====Known False Positives==== +While this search has no known false positives, it is possible that an AWS admin has legitimately set a default policy to allow a user to access all resources. That said, AWS strongly advises against granting full control to all AWS resources + +====Reference==== + +* https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws + +* https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/ + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_setdefaultpolicyversion/aws_cloudtrail_events.json + + +''version'': 1 +
+
+ +---- + +===Aws updateloginprofile=== +This search looks for CloudTrail events where a user A who has already permission to update login profile, makes an API call to update login profile for another user B . Attackers have been know to use this technique for Privilege Escalation in case new victim(user B) has more permissions than old victim(user B) + +* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1136.003/ T1136.003] +* '''Last Updated''': 2021-03-02 + +
+
+ +====Search==== +`cloudtrail` eventName = UpdateLoginProfile userAgent !=console.amazonaws.com errorCode = success +| search userName!=requestParameters.userName +| stats count min(_time) as firstTime max(_time) as lastTime by requestParameters.userName src eventName eventSource aws_account_id errorCode userAgent eventID awsRegion userName user_arn +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +|`aws_updateloginprofile_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#AWS_IAM_Privilege_Escalation|AWS IAM Privilege Escalation]] + + +====How To Implement==== +You must install splunk AWS add on and Splunk App for AWS. This search works with cloudtrail logs. + +====Required field==== + +* _time + +* eventName + +* userAgent + +* errorCode + +* requestParameters.userName + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1136.003 +| Cloud Account +| Persistence +|} + + +====Kill Chain Phase==== + +* Actions on Objectives + + +====Known False Positives==== +While this search has no known false positives, it is possible that an AWS admin has legitimately created keys for another user. + +====Reference==== + +* https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws + +* https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation-part-2/ + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1078/aws_updateloginprofile/aws_cloudtrail_events.json + + ''version'': 1
@@ -1516,21 +2011,21 @@ This search will detect a spike in the number of API calls made to your cloud in ====Search==== -| tstats count as api_calls values(All_Changes.command) as command from datamodel=Change where All_Changes.user!=unknown All_Changes.status=success by All_Changes.user _time span=1h -| `drop_dm_object_name("All_Changes")` -| eval HourOfDay=strftime(_time, "%H") -| eval HourOfDay=floor(HourOfDay/4)*4 -| eval DayOfWeek=strftime(_time, "%w") -| eval isWeekend=if(DayOfWeek >= 1 AND DayOfWeek <= 5, 0, 1) -| join user HourOfDay isWeekend [ summary cloud_excessive_api_calls_v1] -| where cardinality >=16 -| apply cloud_excessive_api_calls_v1 threshold=0.005 -| rename "IsOutlier(api_calls)" as isOutlier -| where isOutlier=1 -| eval expected_upper_threshold = mvindex(split(mvindex(BoundaryRanges, -1), ":"), 0) -| where api_calls > expected_upper_threshold -| eval distance_from_threshold = api_calls - expected_upper_threshold -| table _time, user, command, api_calls, expected_upper_threshold, distance_from_threshold +| tstats count as api_calls values(All_Changes.command) as command from datamodel=Change where All_Changes.user!=unknown All_Changes.status=success by All_Changes.user _time span=1h +| `drop_dm_object_name("All_Changes")` +| eval HourOfDay=strftime(_time, "%H") +| eval HourOfDay=floor(HourOfDay/4)*4 +| eval DayOfWeek=strftime(_time, "%w") +| eval isWeekend=if(DayOfWeek >= 1 AND DayOfWeek <= 5, 0, 1) +| join user HourOfDay isWeekend [ summary cloud_excessive_api_calls_v1] +| where cardinality >=16 +| apply cloud_excessive_api_calls_v1 threshold=0.005 +| rename "IsOutlier(api_calls)" as isOutlier +| where isOutlier=1 +| eval expected_upper_threshold = mvindex(split(mvindex(BoundaryRanges, -1), ":"), 0) +| where api_calls > expected_upper_threshold +| eval distance_from_threshold = api_calls - expected_upper_threshold +| table _time, user, command, api_calls, expected_upper_threshold, distance_from_threshold | `abnormally_high_number_of_cloud_infrastructure_api_calls_filter` ====Associated Analytic Story==== @@ -1543,6 +2038,14 @@ You must be ingesting your cloud infrastructure logs. You also must run the base ====Required field==== +* _time + +* All_Changes.command + +* All_Changes.user + +* All_Changes.status + ====ATT&CK==== @@ -1592,20 +2095,20 @@ This search finds for the number successfully destroyed cloud instances for ever ====Search==== -| tstats count as instances_destroyed values(All_Changes.object_id) as object_id from datamodel=Change where All_Changes.action=deleted AND All_Changes.status=success AND All_Changes.object_category=instance by All_Changes.user _time span=1h -| `drop_dm_object_name("All_Changes")` -| eval HourOfDay=strftime(_time, "%H") -| eval HourOfDay=floor(HourOfDay/4)*4 -| eval DayOfWeek=strftime(_time, "%w") -| eval isWeekend=if(DayOfWeek >= 1 AND DayOfWeek <= 5, 0, 1) -| join HourOfDay isWeekend [summary cloud_excessive_instances_destroyed_v1] -| where cardinality >=16 -| apply cloud_excessive_instances_destroyed_v1 threshold=0.005 -| rename "IsOutlier(instances_destroyed)" as isOutlier -| where isOutlier=1 -| eval expected_upper_threshold = mvindex(split(mvindex(BoundaryRanges, -1), ":"), 0) -| eval distance_from_threshold = instances_destroyed - expected_upper_threshold -| table _time, user, instances_destroyed, expected_upper_threshold, distance_from_threshold, object_id +| tstats count as instances_destroyed values(All_Changes.object_id) as object_id from datamodel=Change where All_Changes.action=deleted AND All_Changes.status=success AND All_Changes.object_category=instance by All_Changes.user _time span=1h +| `drop_dm_object_name("All_Changes")` +| eval HourOfDay=strftime(_time, "%H") +| eval HourOfDay=floor(HourOfDay/4)*4 +| eval DayOfWeek=strftime(_time, "%w") +| eval isWeekend=if(DayOfWeek >= 1 AND DayOfWeek <= 5, 0, 1) +| join HourOfDay isWeekend [summary cloud_excessive_instances_destroyed_v1] +| where cardinality >=16 +| apply cloud_excessive_instances_destroyed_v1 threshold=0.005 +| rename "IsOutlier(instances_destroyed)" as isOutlier +| where isOutlier=1 +| eval expected_upper_threshold = mvindex(split(mvindex(BoundaryRanges, -1), ":"), 0) +| eval distance_from_threshold = instances_destroyed - expected_upper_threshold +| table _time, user, instances_destroyed, expected_upper_threshold, distance_from_threshold, object_id | `abnormally_high_number_of_cloud_instances_destroyed_filter` ====Associated Analytic Story==== @@ -1618,6 +2121,18 @@ You must be ingesting your cloud infrastructure logs. You also must run the base ====Required field==== +* _time + +* All_Changes.object_id + +* All_Changes.action + +* All_Changes.status + +* All_Changes.object_category + +* All_Changes.user + ====ATT&CK==== @@ -1665,20 +2180,20 @@ This search finds for the number successfully created cloud instances for every ====Search==== -| tstats count as instances_launched values(All_Changes.object_id) as object_id from datamodel=Change where (All_Changes.action=created) AND All_Changes.status=success AND All_Changes.object_category=instance by All_Changes.user _time span=1h -| `drop_dm_object_name("All_Changes")` -| eval HourOfDay=strftime(_time, "%H") -| eval HourOfDay=floor(HourOfDay/4)*4 -| eval DayOfWeek=strftime(_time, "%w") -| eval isWeekend=if(DayOfWeek >= 1 AND DayOfWeek <= 5, 0, 1) -| join HourOfDay isWeekend [summary cloud_excessive_instances_created_v1] -| where cardinality >=16 -| apply cloud_excessive_instances_created_v1 threshold=0.005 -| rename "IsOutlier(instances_launched)" as isOutlier -| where isOutlier=1 -| eval expected_upper_threshold = mvindex(split(mvindex(BoundaryRanges, -1), ":"), 0) -| eval distance_from_threshold = instances_launched - expected_upper_threshold -| table _time, user, instances_launched, expected_upper_threshold, distance_from_threshold, object_id +| tstats count as instances_launched values(All_Changes.object_id) as object_id from datamodel=Change where (All_Changes.action=created) AND All_Changes.status=success AND All_Changes.object_category=instance by All_Changes.user _time span=1h +| `drop_dm_object_name("All_Changes")` +| eval HourOfDay=strftime(_time, "%H") +| eval HourOfDay=floor(HourOfDay/4)*4 +| eval DayOfWeek=strftime(_time, "%w") +| eval isWeekend=if(DayOfWeek >= 1 AND DayOfWeek <= 5, 0, 1) +| join HourOfDay isWeekend [summary cloud_excessive_instances_created_v1] +| where cardinality >=16 +| apply cloud_excessive_instances_created_v1 threshold=0.005 +| rename "IsOutlier(instances_launched)" as isOutlier +| where isOutlier=1 +| eval expected_upper_threshold = mvindex(split(mvindex(BoundaryRanges, -1), ":"), 0) +| eval distance_from_threshold = instances_launched - expected_upper_threshold +| table _time, user, instances_launched, expected_upper_threshold, distance_from_threshold, object_id | `abnormally_high_number_of_cloud_instances_launched_filter` ====Associated Analytic Story==== @@ -1693,6 +2208,18 @@ You must be ingesting your cloud infrastructure logs. You also must run the base ====Required field==== +* _time + +* All_Changes.object_id + +* All_Changes.action + +* All_Changes.status + +* All_Changes.object_category + +* All_Changes.user + ====ATT&CK==== @@ -1740,21 +2267,21 @@ This search will detect a spike in the number of API calls made to your cloud in ====Search==== -| tstats count as security_group_api_calls values(All_Changes.command) as command from datamodel=Change where All_Changes.object_category=firewall AND All_Changes.status=success by All_Changes.user _time span=1h -| `drop_dm_object_name("All_Changes")` -| eval HourOfDay=strftime(_time, "%H") -| eval HourOfDay=floor(HourOfDay/4)*4 -| eval DayOfWeek=strftime(_time, "%w") -| eval isWeekend=if(DayOfWeek >= 1 AND DayOfWeek <= 5, 0, 1) -| join user HourOfDay isWeekend [ summary cloud_excessive_security_group_api_calls_v1] -| where cardinality >=16 -| apply cloud_excessive_security_group_api_calls_v1 threshold=0.005 -| rename "IsOutlier(security_group_api_calls)" as isOutlier -| where isOutlier=1 -| eval expected_upper_threshold = mvindex(split(mvindex(BoundaryRanges, -1), ":"), 0) -| where security_group_api_calls > expected_upper_threshold -| eval distance_from_threshold = security_group_api_calls - expected_upper_threshold -| table _time, user, command, security_group_api_calls, expected_upper_threshold, distance_from_threshold +| tstats count as security_group_api_calls values(All_Changes.command) as command from datamodel=Change where All_Changes.object_category=firewall AND All_Changes.status=success by All_Changes.user _time span=1h +| `drop_dm_object_name("All_Changes")` +| eval HourOfDay=strftime(_time, "%H") +| eval HourOfDay=floor(HourOfDay/4)*4 +| eval DayOfWeek=strftime(_time, "%w") +| eval isWeekend=if(DayOfWeek >= 1 AND DayOfWeek <= 5, 0, 1) +| join user HourOfDay isWeekend [ summary cloud_excessive_security_group_api_calls_v1] +| where cardinality >=16 +| apply cloud_excessive_security_group_api_calls_v1 threshold=0.005 +| rename "IsOutlier(security_group_api_calls)" as isOutlier +| where isOutlier=1 +| eval expected_upper_threshold = mvindex(split(mvindex(BoundaryRanges, -1), ":"), 0) +| where security_group_api_calls > expected_upper_threshold +| eval distance_from_threshold = security_group_api_calls - expected_upper_threshold +| table _time, user, command, security_group_api_calls, expected_upper_threshold, distance_from_threshold | `abnormally_high_number_of_cloud_security_group_api_calls_filter` ====Associated Analytic Story==== @@ -1767,6 +2294,16 @@ You must be ingesting your cloud infrastructure logs. You also must run the base ====Required field==== +* _time + +* All_Changes.command + +* All_Changes.object_category + +* All_Changes.status + +* All_Changes.user + ====ATT&CK==== @@ -1807,7 +2344,7 @@ You must be ingesting your cloud infrastructure logs. You also must run the base This search provides detection information on unauthenticated requests against Kubernetes' Pods API * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1526/ T1526] * '''Last Updated''': 2020-04-15 @@ -1815,11 +2352,11 @@ This search provides detection information on unauthenticated requests against K
====Search==== -`aws_cloudwatchlogs_eks` "user.username"="system:anonymous" verb=list objectRef.resource=pods requestURI="/api/v1/pods" -| rename source as cluster_name sourceIPs{} as src_ip -| stats count min(_time) as firstTime max(_time) as lastTime values(responseStatus.reason) values(responseStatus.code) values(userAgent) values(verb) values(requestURI) by src_ip cluster_name user.username user.groups{} -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` +`aws_cloudwatchlogs_eks` "user.username"="system:anonymous" verb=list objectRef.resource=pods requestURI="/api/v1/pods" +| rename source as cluster_name sourceIPs{} as src_ip +| stats count min(_time) as firstTime max(_time) as lastTime values(responseStatus.reason) values(responseStatus.code) values(userAgent) values(verb) values(requestURI) by src_ip cluster_name user.username user.groups{} +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` | `amazon_eks_kubernetes_pod_scan_detection_filter` ====Associated Analytic Story==== @@ -1832,6 +2369,30 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- ====Required field==== +* _time + +* user.username + +* verb + +* objectRef.resource + +* requestURI + +* source + +* sourceIPs{} + +* responseStatus.reason + +* responseStatus.code + +* userAgent + +* src_ip + +* user.groups{} + ====ATT&CK==== @@ -1870,7 +2431,7 @@ Not all unauthenticated requests are malicious, but frequency, UA and source IPs This search provides information of unauthenticated requests via user agent, and authentication data against Kubernetes cluster in AWS * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1526/ T1526] * '''Last Updated''': 2020-04-15 @@ -1878,11 +2439,11 @@ This search provides information of unauthenticated requests via user agent, and
====Search==== -`aws_cloudwatchlogs_eks` "user.username"="system:anonymous" userAgent!="AWS Security Scanner" -| rename sourceIPs{} as src_ip -| stats count min(_time) as firstTime max(_time) as lastTime values(responseStatus.reason) values(source) as cluster_name values(responseStatus.code) values(userAgent) as http_user_agent values(verb) values(requestURI) by src_ip user.username user.groups{} -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` +`aws_cloudwatchlogs_eks` "user.username"="system:anonymous" userAgent!="AWS Security Scanner" +| rename sourceIPs{} as src_ip +| stats count min(_time) as firstTime max(_time) as lastTime values(responseStatus.reason) values(source) as cluster_name values(responseStatus.code) values(userAgent) as http_user_agent values(verb) values(requestURI) by src_ip user.username user.groups{} +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` |`amazon_eks_kubernetes_cluster_scan_detection_filter` ====Associated Analytic Story==== @@ -1895,6 +2456,28 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- ====Required field==== +* _time + +* user.username + +* userAgent + +* sourceIPs{} + +* responseStatus.reason + +* source + +* responseStatus.code + +* verb + +* requestURI + +* src_ip + +* user.groups{} + ====ATT&CK==== @@ -1942,15 +2525,15 @@ This search looks for new commands from each user role. ====Search==== -| tstats earliest(_time) as firstTime, latest(_time) as lastTime from datamodel=Change where All_Changes.user_type=AssumedRole AND All_Changes.status=success by All_Changes.user, All_Changes.command All_Changes.object -| `drop_dm_object_name("All_Changes")` -| lookup previously_seen_cloud_api_calls_per_user_role user as user, command as command OUTPUT firstTimeSeen, enough_data -| eventstats max(enough_data) as enough_data -| where enough_data=1 -| eval firstTimeSeenUserApiCall=min(firstTimeSeen) -| where isnull(firstTimeSeenUserApiCall) OR firstTimeSeenUserApiCall > relative_time(now(),"-24h@h") -| table firstTime, user, object, command -|`security_content_ctime(firstTime)` +| tstats earliest(_time) as firstTime, latest(_time) as lastTime from datamodel=Change where All_Changes.user_type=AssumedRole AND All_Changes.status=success by All_Changes.user, All_Changes.command All_Changes.object +| `drop_dm_object_name("All_Changes")` +| lookup previously_seen_cloud_api_calls_per_user_role user as user, command as command OUTPUT firstTimeSeen, enough_data +| eventstats max(enough_data) as enough_data +| where enough_data=1 +| eval firstTimeSeenUserApiCall=min(firstTimeSeen) +| where isnull(firstTimeSeenUserApiCall) OR firstTimeSeenUserApiCall > relative_time(now(),"-24h@h") +| table firstTime, user, object, command +|`security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `cloud_api_calls_from_previously_unseen_user_roles_filter` @@ -1964,6 +2547,18 @@ You must be ingesting your cloud infrastructure logs from your cloud provider. ====Required field==== +* _time + +* All_Changes.user + +* All_Changes.user_type + +* All_Changes.status + +* All_Changes.command + +* All_Changes.object + ====ATT&CK==== @@ -2011,15 +2606,15 @@ This search looks for cloud compute instances created by users who have not crea ====Search==== -| tstats `security_content_summariesonly` count earliest(_time) as firstTime, latest(_time) as lastTime values(All_Changes.object) as dest from datamodel=Change where All_Changes.action=created by All_Changes.user All_Changes.vendor_region -| `drop_dm_object_name("All_Changes")` -| lookup previously_seen_cloud_compute_creations_by_user user as user OUTPUTNEW firstTimeSeen, enough_data -| eventstats max(enough_data) as enough_data -| where enough_data=1 -| eval firstTimeSeenUser=min(firstTimeSeen) -| where isnull(firstTimeSeenUser) OR firstTimeSeenUser > relative_time(now(), "-24h@h") -| table firstTime, user, dest, count vendor_region -| `security_content_ctime(firstTime)` +| tstats `security_content_summariesonly` count earliest(_time) as firstTime, latest(_time) as lastTime values(All_Changes.object) as dest from datamodel=Change where All_Changes.action=created by All_Changes.user All_Changes.vendor_region +| `drop_dm_object_name("All_Changes")` +| lookup previously_seen_cloud_compute_creations_by_user user as user OUTPUTNEW firstTimeSeen, enough_data +| eventstats max(enough_data) as enough_data +| where enough_data=1 +| eval firstTimeSeenUser=min(firstTimeSeen) +| where isnull(firstTimeSeenUser) OR firstTimeSeenUser > relative_time(now(), "-24h@h") +| table firstTime, user, dest, count vendor_region +| `security_content_ctime(firstTime)` | `cloud_compute_instance_created_by_previously_unseen_user_filter` ====Associated Analytic Story==== @@ -2032,6 +2627,16 @@ You must be ingesting the appropriate cloud-infrastructure logs Run the "Previou ====Required field==== +* _time + +* All_Changes.object + +* All_Changes.action + +* All_Changes.user + +* All_Changes.vendor_region + ====ATT&CK==== @@ -2079,15 +2684,15 @@ This search looks at cloud-infrastructure events where an instance is created in ====Search==== -| tstats earliest(_time) as firstTime latest(_time) as lastTime values(All_Changes.object_id) as dest, count from datamodel=Change where All_Changes.action=created by All_Changes.vendor_region, All_Changes.user -| `drop_dm_object_name("All_Changes")` -| lookup previously_seen_cloud_regions vendor_region as vendor_region OUTPUTNEW firstTimeSeen, enough_data -| eventstats max(enough_data) as enough_data -| where enough_data=1 -| eval firstTimeSeenRegion=min(firstTimeSeen) -| where isnull(firstTimeSeenRegion) OR firstTimeSeenRegion > relative_time(now(), "-24h@h") -| table firstTime, user, dest, count , vendor_region -| `security_content_ctime(firstTime)` +| tstats earliest(_time) as firstTime latest(_time) as lastTime values(All_Changes.object_id) as dest, count from datamodel=Change where All_Changes.action=created by All_Changes.vendor_region, All_Changes.user +| `drop_dm_object_name("All_Changes")` +| lookup previously_seen_cloud_regions vendor_region as vendor_region OUTPUTNEW firstTimeSeen, enough_data +| eventstats max(enough_data) as enough_data +| where enough_data=1 +| eval firstTimeSeenRegion=min(firstTimeSeen) +| where isnull(firstTimeSeenRegion) OR firstTimeSeenRegion > relative_time(now(), "-24h@h") +| table firstTime, user, dest, count , vendor_region +| `security_content_ctime(firstTime)` | `cloud_compute_instance_created_in_previously_unused_region_filter` ====Associated Analytic Story==== @@ -2100,6 +2705,16 @@ You must be ingesting your cloud infrastructure logs from your cloud provider. Y ====Required field==== +* _time + +* All_Changes.object_id + +* All_Changes.action + +* All_Changes.vendor_region + +* All_Changes.user + ====ATT&CK==== @@ -2141,7 +2756,7 @@ This search looks for cloud compute instances being created with previously unse * '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Change -* '''ATT&CK''': +* '''ATT&CK''': * '''Last Updated''': 2018-10-12
@@ -2149,17 +2764,17 @@ This search looks for cloud compute instances being created with previously unse ====Search==== -| tstats count earliest(_time) as firstTime, latest(_time) as lastTime values(All_Changes.object_id) as dest from datamodel=Change where All_Changes.action=created by All_Changes.Instance_Changes.image_id, All_Changes.user -| `drop_dm_object_name("All_Changes")` -| `drop_dm_object_name("Instance_Changes")` -| where image_id != "unknown" -| lookup previously_seen_cloud_compute_images image_id as image_id OUTPUT firstTimeSeen, enough_data -| eventstats max(enough_data) as enough_data -| where enough_data=1 -| eval firstTimeSeenImage=min(firstTimeSeen) -| where isnull(firstTimeSeenImage) OR firstTimeSeenImage > relative_time(now(), "-24h@h") -| table firstTime, user, image_id, count, dest -| `security_content_ctime(firstTime)` +| tstats count earliest(_time) as firstTime, latest(_time) as lastTime values(All_Changes.object_id) as dest from datamodel=Change where All_Changes.action=created by All_Changes.Instance_Changes.image_id, All_Changes.user +| `drop_dm_object_name("All_Changes")` +| `drop_dm_object_name("Instance_Changes")` +| where image_id != "unknown" +| lookup previously_seen_cloud_compute_images image_id as image_id OUTPUT firstTimeSeen, enough_data +| eventstats max(enough_data) as enough_data +| where enough_data=1 +| eval firstTimeSeenImage=min(firstTimeSeen) +| where isnull(firstTimeSeenImage) OR firstTimeSeenImage > relative_time(now(), "-24h@h") +| table firstTime, user, image_id, count, dest +| `security_content_ctime(firstTime)` | `cloud_compute_instance_created_with_previously_unseen_image_filter` ====Associated Analytic Story==== @@ -2172,6 +2787,16 @@ You must be ingesting your cloud infrastructure logs from your cloud provider. Y ====Required field==== +* _time + +* All_Changes.object_id + +* All_Changes.action + +* All_Changes.Instance_Changes.image_id + +* All_Changes.user + @@ -2200,7 +2825,7 @@ Find EC2 instances being created with previously unseen instance types. * '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Change -* '''ATT&CK''': +* '''ATT&CK''': * '''Last Updated''': 2020-09-12
@@ -2208,17 +2833,17 @@ Find EC2 instances being created with previously unseen instance types. ====Search==== -| tstats earliest(_time) as firstTime, latest(_time) as lastTime values(All_Changes.object_id) as dest, count from datamodel=Change where All_Changes.action=created by All_Changes.Instance_Changes.instance_type, All_Changes.user -| `drop_dm_object_name("All_Changes")` -| `drop_dm_object_name("Instance_Changes")` -| where instance_type != "unknown" -| lookup previously_seen_cloud_compute_instance_types instance_type as instance_type OUTPUTNEW firstTimeSeen, enough_data -| eventstats max(enough_data) as enough_data -| where enough_data=1 -| eval firstTimeSeenInstanceType=min(firstTimeSeen) -| where isnull(firstTimeSeenInstanceType) OR firstTimeSeenInstanceType > relative_time(now(), "-24h@h") -| table firstTime, user, dest, count, instance_type -| `security_content_ctime(firstTime)` +| tstats earliest(_time) as firstTime, latest(_time) as lastTime values(All_Changes.object_id) as dest, count from datamodel=Change where All_Changes.action=created by All_Changes.Instance_Changes.instance_type, All_Changes.user +| `drop_dm_object_name("All_Changes")` +| `drop_dm_object_name("Instance_Changes")` +| where instance_type != "unknown" +| lookup previously_seen_cloud_compute_instance_types instance_type as instance_type OUTPUTNEW firstTimeSeen, enough_data +| eventstats max(enough_data) as enough_data +| where enough_data=1 +| eval firstTimeSeenInstanceType=min(firstTimeSeen) +| where isnull(firstTimeSeenInstanceType) OR firstTimeSeenInstanceType > relative_time(now(), "-24h@h") +| table firstTime, user, dest, count, instance_type +| `security_content_ctime(firstTime)` | `cloud_compute_instance_created_with_previously_unseen_instance_type_filter` ====Associated Analytic Story==== @@ -2231,6 +2856,16 @@ You must be ingesting your cloud infrastructure logs from your cloud provider. Y ====Required field==== +* _time + +* All_Changes.object_id + +* All_Changes.action + +* All_Changes.Instance_Changes.instance_type + +* All_Changes.user + @@ -2267,15 +2902,15 @@ This search looks for cloud instances being modified by users who have not previ ====Search==== -| tstats `security_content_summariesonly` count earliest(_time) as firstTime, latest(_time) as lastTime values(All_Changes.object_id) as object_id values(All_Changes.command) as command from datamodel=Change where All_Changes.action=modified All_Changes.change_type=EC2 All_Changes.status=success by All_Changes.user -| `drop_dm_object_name("All_Changes")` -| lookup previously_seen_cloud_instance_modifications_by_user user as user OUTPUTNEW firstTimeSeen, enough_data -| eventstats max(enough_data) as enough_data -| where enough_data=1 -| eval firstTimeSeenUser=min(firstTimeSeen) -| where isnull(firstTimeSeenUser) OR firstTimeSeenUser > relative_time(now(), "-24h@h") -| table firstTime user command object_id count -| `security_content_ctime(firstTime)` +| tstats `security_content_summariesonly` count earliest(_time) as firstTime, latest(_time) as lastTime values(All_Changes.object_id) as object_id values(All_Changes.command) as command from datamodel=Change where All_Changes.action=modified All_Changes.change_type=EC2 All_Changes.status=success by All_Changes.user +| `drop_dm_object_name("All_Changes")` +| lookup previously_seen_cloud_instance_modifications_by_user user as user OUTPUTNEW firstTimeSeen, enough_data +| eventstats max(enough_data) as enough_data +| where enough_data=1 +| eval firstTimeSeenUser=min(firstTimeSeen) +| where isnull(firstTimeSeenUser) OR firstTimeSeenUser > relative_time(now(), "-24h@h") +| table firstTime user command object_id count +| `security_content_ctime(firstTime)` | `cloud_instance_modified_by_previously_unseen_user_filter` ====Associated Analytic Story==== @@ -2288,6 +2923,20 @@ This search has a dependency on other searches to create and update a baseline o ====Required field==== +* _time + +* All_Changes.object_id + +* All_Changes.command + +* All_Changes.action + +* All_Changes.change_type + +* All_Changes.status + +* All_Changes.user + ====ATT&CK==== @@ -2335,17 +2984,17 @@ This search looks for cloud provisioning activities from previously unseen citie ====Search==== -| tstats earliest(_time) as firstTime, latest(_time) as lastTime from datamodel=Change where (All_Changes.action=started OR All_Changes.action=created) All_Changes.status=success by All_Changes.src, All_Changes.user, All_Changes.object, All_Changes.command -| `drop_dm_object_name("All_Changes")` -| iplocation src -| where isnotnull(City) -| lookup previously_seen_cloud_provisioning_activity_sources City as City OUTPUT firstTimeSeen, enough_data -| eventstats max(enough_data) as enough_data -| where enough_data=1 -| eval firstTimeSeenCity=min(firstTimeSeen) -| where isnull(firstTimeSeenCity) OR firstTimeSeenCity > relative_time(now(), `previously_unseen_cloud_provisioning_activity_window`) -| table firstTime, src, City, user, object, command -| `cloud_provisioning_activity_from_previously_unseen_city_filter` +| tstats earliest(_time) as firstTime, latest(_time) as lastTime from datamodel=Change where (All_Changes.action=started OR All_Changes.action=created) All_Changes.status=success by All_Changes.src, All_Changes.user, All_Changes.object, All_Changes.command +| `drop_dm_object_name("All_Changes")` +| iplocation src +| where isnotnull(City) +| lookup previously_seen_cloud_provisioning_activity_sources City as City OUTPUT firstTimeSeen, enough_data +| eventstats max(enough_data) as enough_data +| where enough_data=1 +| eval firstTimeSeenCity=min(firstTimeSeen) +| where isnull(firstTimeSeenCity) OR firstTimeSeenCity > relative_time(now(), `previously_unseen_cloud_provisioning_activity_window`) +| table firstTime, src, City, user, object, command +| `cloud_provisioning_activity_from_previously_unseen_city_filter` | `security_content_ctime(firstTime)` ====Associated Analytic Story==== @@ -2358,6 +3007,20 @@ You must be ingesting your cloud infrastructure logs from your cloud provider. ====Required field==== +* _time + +* All_Changes.action + +* All_Changes.status + +* All_Changes.src + +* All_Changes.user + +* All_Changes.object + +* All_Changes.command + ====ATT&CK==== @@ -2406,17 +3069,17 @@ This search looks for cloud provisioning activities from previously unseen count ====Search==== -| tstats earliest(_time) as firstTime, latest(_time) as lastTime from datamodel=Change where (All_Changes.action=started OR All_Changes.action=created) All_Changes.status=success by All_Changes.src, All_Changes.user, All_Changes.object, All_Changes.command -| `drop_dm_object_name("All_Changes")` -| iplocation src -| where isnotnull(Country) -| lookup previously_seen_cloud_provisioning_activity_sources Country as Country OUTPUT firstTimeSeen, enough_data -| eventstats max(enough_data) as enough_data -| where enough_data=1 -| eval firstTimeSeenCountry=min(firstTimeSeen) -| where isnull(firstTimeSeenCountry) OR firstTimeSeenCountry > relative_time(now(), "-24h@h") -| table firstTime, src, Country, user, object, command -| `cloud_provisioning_activity_from_previously_unseen_country_filter` +| tstats earliest(_time) as firstTime, latest(_time) as lastTime from datamodel=Change where (All_Changes.action=started OR All_Changes.action=created) All_Changes.status=success by All_Changes.src, All_Changes.user, All_Changes.object, All_Changes.command +| `drop_dm_object_name("All_Changes")` +| iplocation src +| where isnotnull(Country) +| lookup previously_seen_cloud_provisioning_activity_sources Country as Country OUTPUT firstTimeSeen, enough_data +| eventstats max(enough_data) as enough_data +| where enough_data=1 +| eval firstTimeSeenCountry=min(firstTimeSeen) +| where isnull(firstTimeSeenCountry) OR firstTimeSeenCountry > relative_time(now(), "-24h@h") +| table firstTime, src, Country, user, object, command +| `cloud_provisioning_activity_from_previously_unseen_country_filter` | `security_content_ctime(firstTime)` ====Associated Analytic Story==== @@ -2429,6 +3092,20 @@ You must be ingesting your cloud infrastructure logs from your cloud provider. ====Required field==== +* _time + +* All_Changes.action + +* All_Changes.status + +* All_Changes.src + +* All_Changes.user + +* All_Changes.object + +* All_Changes.command + ====ATT&CK==== @@ -2477,15 +3154,15 @@ This search looks for cloud provisioning activities from previously unseen IP ad ====Search==== -| tstats earliest(_time) as firstTime, latest(_time) as lastTime, values(All_Changes.object_id) as object_id from datamodel=Change where (All_Changes.action=started OR All_Changes.action=created) All_Changes.status=success by All_Changes.src, All_Changes.user, All_Changes.command -| `drop_dm_object_name("All_Changes")` -| lookup previously_seen_cloud_provisioning_activity_sources src as src OUTPUT firstTimeSeen, enough_data -| eventstats max(enough_data) as enough_data -| where enough_data=1 -| eval firstTimeSeenSrc=min(firstTimeSeen) -| where isnull(firstTimeSeenSrc) OR firstTimeSeenSrc > relative_time(now(), `previously_unseen_cloud_provisioning_activity_window`) -| table firstTime, src, user, object_id, command -| `cloud_provisioning_activity_from_previously_unseen_ip_address_filter` +| tstats earliest(_time) as firstTime, latest(_time) as lastTime, values(All_Changes.object_id) as object_id from datamodel=Change where (All_Changes.action=started OR All_Changes.action=created) All_Changes.status=success by All_Changes.src, All_Changes.user, All_Changes.command +| `drop_dm_object_name("All_Changes")` +| lookup previously_seen_cloud_provisioning_activity_sources src as src OUTPUT firstTimeSeen, enough_data +| eventstats max(enough_data) as enough_data +| where enough_data=1 +| eval firstTimeSeenSrc=min(firstTimeSeen) +| where isnull(firstTimeSeenSrc) OR firstTimeSeenSrc > relative_time(now(), `previously_unseen_cloud_provisioning_activity_window`) +| table firstTime, src, user, object_id, command +| `cloud_provisioning_activity_from_previously_unseen_ip_address_filter` | `security_content_ctime(firstTime)` ====Associated Analytic Story==== @@ -2498,6 +3175,20 @@ You must be ingesting your cloud infrastructure logs from your cloud provider. ====Required field==== +* _time + +* All_Changes.object_id + +* All_Changes.action + +* All_Changes.status + +* All_Changes.src + +* All_Changes.user + +* All_Changes.command + ====ATT&CK==== @@ -2546,17 +3237,17 @@ This search looks for cloud provisioning activities from previously unseen regio ====Search==== -| tstats earliest(_time) as firstTime, latest(_time) as lastTime from datamodel=Change where (All_Changes.action=started OR All_Changes.action=created) All_Changes.status=success by All_Changes.src, All_Changes.user, All_Changes.object, All_Changes.command -| `drop_dm_object_name("All_Changes")` -| iplocation src -| where isnotnull(Region) -| lookup previously_seen_cloud_provisioning_activity_sources Region as Region OUTPUT firstTimeSeen, enough_data -| eventstats max(enough_data) as enough_data -| where enough_data=1 -| eval firstTimeSeenRegion=min(firstTimeSeen) -| where isnull(firstTimeSeenRegion) OR firstTimeSeenRegion > relative_time(now(), `previously_unseen_cloud_provisioning_activity_window`) -| table firstTime, src, Region, user, object, command -| `cloud_provisioning_activity_from_previously_unseen_region_filter` +| tstats earliest(_time) as firstTime, latest(_time) as lastTime from datamodel=Change where (All_Changes.action=started OR All_Changes.action=created) All_Changes.status=success by All_Changes.src, All_Changes.user, All_Changes.object, All_Changes.command +| `drop_dm_object_name("All_Changes")` +| iplocation src +| where isnotnull(Region) +| lookup previously_seen_cloud_provisioning_activity_sources Region as Region OUTPUT firstTimeSeen, enough_data +| eventstats max(enough_data) as enough_data +| where enough_data=1 +| eval firstTimeSeenRegion=min(firstTimeSeen) +| where isnull(firstTimeSeenRegion) OR firstTimeSeenRegion > relative_time(now(), `previously_unseen_cloud_provisioning_activity_window`) +| table firstTime, src, Region, user, object, command +| `cloud_provisioning_activity_from_previously_unseen_region_filter` | `security_content_ctime(firstTime)` ====Associated Analytic Story==== @@ -2569,6 +3260,20 @@ You must be ingesting your cloud infrastructure logs from your cloud provider. ====Required field==== +* _time + +* All_Changes.action + +* All_Changes.status + +* All_Changes.src + +* All_Changes.user + +* All_Changes.object + +* All_Changes.command + ====ATT&CK==== @@ -2609,7 +3314,7 @@ This search looks for CloudTrail events wherein a console login event by a user * '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Authentication -* '''ATT&CK''': +* '''ATT&CK''': * '''Last Updated''': 2020-05-28
@@ -2617,13 +3322,13 @@ This search looks for CloudTrail events wherein a console login event by a user ====Search==== -| tstats earliest(_time) as firstTime latest(_time) as lastTime from datamodel=Authentication where Authentication.signature=ConsoleLogin by Authentication.user -| `drop_dm_object_name(Authentication)` -| inputlookup append=t previously_seen_users_console_logins -| stats min(firstTime) as firstTime max(lastTime) as lastTime by user -| eval userStatus=if(firstTime >=relative_time(now(),"-24h@h"), "First Time Logging into AWS Console", "Previously Seen User") -|where userStatus="First Time Logging into AWS Console" -| `security_content_ctime(firstTime)` +| tstats earliest(_time) as firstTime latest(_time) as lastTime from datamodel=Authentication where Authentication.signature=ConsoleLogin by Authentication.user +| `drop_dm_object_name(Authentication)` +| inputlookup append=t previously_seen_users_console_logins +| stats min(firstTime) as firstTime max(lastTime) as lastTime by user +| eval userStatus=if(firstTime >=relative_time(now(),"-24h@h"), "First Time Logging into AWS Console", "Previously Seen User") +|where userStatus="First Time Logging into AWS Console" +| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `detect_aws_console_login_by_new_user_filter` @@ -2637,6 +3342,12 @@ You must install and configure the Splunk Add-on for AWS (version 5.1.0 or later ====Required field==== +* _time + +* Authentication.signature + +* Authentication.user + @@ -2675,20 +3386,20 @@ This search looks for CloudTrail events wherein a console login event by a user ====Search==== -| tstats earliest(_time) as firstTime latest(_time) as lastTime from datamodel=Authentication where Authentication.signature=ConsoleLogin by Authentication.user Authentication.src -| iplocation Authentication.src -| `drop_dm_object_name(Authentication)` -| table firstTime lastTime user City +| tstats earliest(_time) as firstTime latest(_time) as lastTime from datamodel=Authentication where Authentication.signature=ConsoleLogin by Authentication.user Authentication.src +| iplocation Authentication.src +| `drop_dm_object_name(Authentication)` +| table firstTime lastTime user City | join user type=outer [ -| inputlookup previously_seen_users_console_logins -| stats earliest(firstTime) AS earliestseen by user City -| fields earliestseen user City] -| eval userCity=if(firstTime >= relative_time(now(), "-24h@h"), "New City","Previously Seen City") -| eval userStatus=if(earliestseen >= relative_time(now(), "-24h@h") OR isnull(earliestseen), "New User","Old User") -| where userCity = "New City" AND userStatus != "Old User" -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| table firstTime lastTime user City userStatus userCity +| inputlookup previously_seen_users_console_logins +| stats earliest(firstTime) AS earliestseen by user City +| fields earliestseen user City] +| eval userCity=if(firstTime >= relative_time(now(), "-24h@h"), "New City","Previously Seen City") +| eval userStatus=if(earliestseen >= relative_time(now(), "-24h@h") OR isnull(earliestseen), "New User","Old User") +| where userCity = "New City" AND userStatus != "Old User" +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| table firstTime lastTime user City userStatus userCity | `detect_aws_console_login_by_user_from_new_city_filter` ====Associated Analytic Story==== @@ -2703,6 +3414,14 @@ You must install and configure the Splunk Add-on for AWS (version 5.1.0 or later ====Required field==== +* _time + +* Authentication.signature + +* Authentication.user + +* Authentication.src + ====ATT&CK==== @@ -2752,20 +3471,20 @@ This search looks for CloudTrail events wherein a console login event by a user ====Search==== -| tstats earliest(_time) as firstTime latest(_time) as lastTime from datamodel=Authentication where Authentication.signature=ConsoleLogin by Authentication.user Authentication.src -| iplocation Authentication.src -| `drop_dm_object_name(Authentication)` -| table firstTime lastTime user Country +| tstats earliest(_time) as firstTime latest(_time) as lastTime from datamodel=Authentication where Authentication.signature=ConsoleLogin by Authentication.user Authentication.src +| iplocation Authentication.src +| `drop_dm_object_name(Authentication)` +| table firstTime lastTime user Country | join user type=outer [ -| inputlookup previously_seen_users_console_logins -| stats earliest(firstTime) AS earliestseen by user Country -| fields earliestseen user Country] -| eval userCountry=if(firstTime >= relative_time(now(), "-24h@h"), "New Country","Previously Seen Country") -| eval userStatus=if(earliestseen >= relative_time(now(),"-24h@h") OR isnull(earliestseen), "New User","Old User") -| where userCountry = "New Country" AND userStatus != "Old User" -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| table firstTime lastTime user Country userStatus userCountry +| inputlookup previously_seen_users_console_logins +| stats earliest(firstTime) AS earliestseen by user Country +| fields earliestseen user Country] +| eval userCountry=if(firstTime >= relative_time(now(), "-24h@h"), "New Country","Previously Seen Country") +| eval userStatus=if(earliestseen >= relative_time(now(),"-24h@h") OR isnull(earliestseen), "New User","Old User") +| where userCountry = "New Country" AND userStatus != "Old User" +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| table firstTime lastTime user Country userStatus userCountry | `detect_aws_console_login_by_user_from_new_country_filter` ====Associated Analytic Story==== @@ -2780,6 +3499,14 @@ You must install and configure the Splunk Add-on for AWS (version 5.1.0 or later ====Required field==== +* _time + +* Authentication.signature + +* Authentication.user + +* Authentication.src + ====ATT&CK==== @@ -2829,20 +3556,20 @@ This search looks for CloudTrail events wherein a console login event by a user ====Search==== -| tstats earliest(_time) as firstTime latest(_time) as lastTime from datamodel=Authentication where Authentication.signature=ConsoleLogin by Authentication.user Authentication.src -| iplocation Authentication.src -| `drop_dm_object_name(Authentication)` -| table firstTime lastTime user Region +| tstats earliest(_time) as firstTime latest(_time) as lastTime from datamodel=Authentication where Authentication.signature=ConsoleLogin by Authentication.user Authentication.src +| iplocation Authentication.src +| `drop_dm_object_name(Authentication)` +| table firstTime lastTime user Region | join user type=outer [ -| inputlookup previously_seen_users_console_logins -| stats earliest(firstTime) AS earliestseen by user Region -| fields earliestseen user Region] -| eval userRegion=if(firstTime >= relative_time(now(), "-24h@h"), "New Region","Previously Seen Region") -| eval userStatus=if(earliestseen >= relative_time(now(), "-24h@h") OR isnull(earliestseen), "New User","Old User") -| where userRegion = "New Region" AND userStatus != "Old User" -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| table firstTime lastTime user Region userStatus userRegion +| inputlookup previously_seen_users_console_logins +| stats earliest(firstTime) AS earliestseen by user Region +| fields earliestseen user Region] +| eval userRegion=if(firstTime >= relative_time(now(), "-24h@h"), "New Region","Previously Seen Region") +| eval userStatus=if(earliestseen >= relative_time(now(), "-24h@h") OR isnull(earliestseen), "New User","Old User") +| where userRegion = "New Region" AND userStatus != "Old User" +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| table firstTime lastTime user Region userStatus userRegion | `detect_aws_console_login_by_user_from_new_region_filter` ====Associated Analytic Story==== @@ -2857,6 +3584,14 @@ You must install and configure the Splunk Add-on for AWS (version 5.1.0 or later ====Required field==== +* _time + +* Authentication.signature + +* Authentication.user + +* Authentication.src + ====ATT&CK==== @@ -2897,7 +3632,7 @@ When a legitimate new user logins for the first time, this activity will be dete This search looks at GCP Storage bucket-access logs and detects new or previously unseen remote IP addresses that have successfully accessed a GCP Storage bucket. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1530/ T1530] * '''Last Updated''': 2020-08-10 @@ -2905,24 +3640,24 @@ This search looks at GCP Storage bucket-access logs and detects new or previousl
====Search==== -`google_gcp_pubsub_message` -| multikv -| rename sc_status_ as status -| rename cs_object_ as bucket_name -| rename c_ip_ as remote_ip -| rename cs_uri_ as request_uri -| rename cs_method_ as operation -| search status="\"200\"" -| stats earliest(_time) as firstTime latest(_time) as lastTime by bucket_name remote_ip operation request_uri -| table firstTime, lastTime, bucket_name, remote_ip, operation, request_uri -| inputlookup append=t previously_seen_gcp_storage_access_from_remote_ip.csv -| stats min(firstTime) as firstTime, max(lastTime) as lastTime by bucket_name remote_ip operation request_uri -| outputlookup previously_seen_gcp_storage_access_from_remote_ip.csv -| eval newIP=if(firstTime >= relative_time(now(),"-70m@m"), 1, 0) -| where newIP=1 -| eval first_time=strftime(firstTime,"%m/%d/%y %H:%M:%S") -| eval last_time=strftime(lastTime,"%m/%d/%y %H:%M:%S") -| table first_time last_time bucket_name remote_ip operation request_uri +`google_gcp_pubsub_message` +| multikv +| rename sc_status_ as status +| rename cs_object_ as bucket_name +| rename c_ip_ as remote_ip +| rename cs_uri_ as request_uri +| rename cs_method_ as operation +| search status="\"200\"" +| stats earliest(_time) as firstTime latest(_time) as lastTime by bucket_name remote_ip operation request_uri +| table firstTime, lastTime, bucket_name, remote_ip, operation, request_uri +| inputlookup append=t previously_seen_gcp_storage_access_from_remote_ip.csv +| stats min(firstTime) as firstTime, max(lastTime) as lastTime by bucket_name remote_ip operation request_uri +| outputlookup previously_seen_gcp_storage_access_from_remote_ip.csv +| eval newIP=if(firstTime >= relative_time(now(),"-70m@m"), 1, 0) +| where newIP=1 +| eval first_time=strftime(firstTime,"%m/%d/%y %H:%M:%S") +| eval last_time=strftime(lastTime,"%m/%d/%y %H:%M:%S") +| table first_time last_time bucket_name remote_ip operation request_uri | `detect_gcp_storage_access_from_a_new_ip_filter` ====Associated Analytic Story==== @@ -2935,6 +3670,18 @@ This search relies on the Splunk Add-on for Google Cloud Platform, setting up a ====Required field==== +* _time + +* sc_status_ + +* cs_object_ + +* c_ip_ + +* cs_uri_ + +* cs_method_ + ====ATT&CK==== @@ -2973,7 +3720,7 @@ GCP Storage buckets can be accessed from any IP (if the ACLs are open to allow i This search looks for GCP PubSub events where a user has created an open/public GCP Storage bucket. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1530/ T1530] * '''Last Updated''': 2020-08-05 @@ -2981,16 +3728,16 @@ This search looks for GCP PubSub events where a user has created an open/public
====Search==== -`google_gcp_pubsub_message` data.resource.type=gcs_bucket data.protoPayload.methodName=storage.setIamPermissions -| spath output=action path=data.protoPayload.serviceData.policyDelta.bindingDeltas{}.action -| spath output=user path=data.protoPayload.authenticationInfo.principalEmail -| spath output=location path=data.protoPayload.resourceLocation.currentLocations{} -| spath output=src path=data.protoPayload.requestMetadata.callerIp -| spath output=bucketName path=data.protoPayload.resourceName -| spath output=role path=data.protoPayload.serviceData.policyDelta.bindingDeltas{}.role -| spath output=member path=data.protoPayload.serviceData.policyDelta.bindingDeltas{}.member -| search (member=allUsers AND action=ADD) -| table _time, bucketName, src, user, location, action, role, member +`google_gcp_pubsub_message` data.resource.type=gcs_bucket data.protoPayload.methodName=storage.setIamPermissions +| spath output=action path=data.protoPayload.serviceData.policyDelta.bindingDeltas{}.action +| spath output=user path=data.protoPayload.authenticationInfo.principalEmail +| spath output=location path=data.protoPayload.resourceLocation.currentLocations{} +| spath output=src path=data.protoPayload.requestMetadata.callerIp +| spath output=bucketName path=data.protoPayload.resourceName +| spath output=role path=data.protoPayload.serviceData.policyDelta.bindingDeltas{}.role +| spath output=member path=data.protoPayload.serviceData.policyDelta.bindingDeltas{}.member +| search (member=allUsers AND action=ADD) +| table _time, bucketName, src, user, location, action, role, member | search `detect_new_open_gcp_storage_buckets_filter` ====Associated Analytic Story==== @@ -3003,6 +3750,26 @@ This search relies on the Splunk Add-on for Google Cloud Platform, setting up a ====Required field==== +* _time + +* data.resource.type + +* data.protoPayload.methodName + +* data.protoPayload.serviceData.policyDelta.bindingDeltas{}.action + +* data.protoPayload.authenticationInfo.principalEmail + +* data.protoPayload.resourceLocation.currentLocations{} + +* data.protoPayload.requestMetadata.callerIp + +* data.protoPayload.resourceName + +* data.protoPayload.serviceData.policyDelta.bindingDeltas{}.role + +* data.protoPayload.serviceData.policyDelta.bindingDeltas{}.member + ====ATT&CK==== @@ -3040,8 +3807,8 @@ While this search has no known false positives, it is possible that a GCP admin ===Detect new open s3 buckets over aws cli=== This search looks for CloudTrail events where a user has created an open/public S3 bucket over the aws cli. -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1530/ T1530] * '''Last Updated''': 2021-01-12 @@ -3049,12 +3816,12 @@ This search looks for CloudTrail events where a user has created an open/public
====Search==== -`cloudtrail` eventSource="s3.amazonaws.com" eventName=PutBucketAcl OR requestParameters.accessControlList.x-amz-grant-read-acp IN ("*AuthenticatedUsers","*AllUsers") OR requestParameters.accessControlList.x-amz-grant-write IN ("*AuthenticatedUsers","*AllUsers") OR requestParameters.accessControlList.x-amz-grant-write-acp IN ("*AuthenticatedUsers","*AllUsers") OR requestParameters.accessControlList.x-amz-grant-full-control IN ("*AuthenticatedUsers","*AllUsers") -| rename requestParameters.bucketName AS bucketName -| fillnull -| stats count min(_time) as firstTime max(_time) as lastTime by userName userIdentity.principalId userAgent bucketName requestParameters.accessControlList.x-amz-grant-read requestParameters.accessControlList.x-amz-grant-read-acp requestParameters.accessControlList.x-amz-grant-write requestParameters.accessControlList.x-amz-grant-write-acp requestParameters.accessControlList.x-amz-grant-full-control +`cloudtrail` eventSource="s3.amazonaws.com" eventName=PutBucketAcl OR requestParameters.accessControlList.x-amz-grant-read-acp IN ("*AuthenticatedUsers","*AllUsers") OR requestParameters.accessControlList.x-amz-grant-write IN ("*AuthenticatedUsers","*AllUsers") OR requestParameters.accessControlList.x-amz-grant-write-acp IN ("*AuthenticatedUsers","*AllUsers") OR requestParameters.accessControlList.x-amz-grant-full-control IN ("*AuthenticatedUsers","*AllUsers") +| rename requestParameters.bucketName AS bucketName +| fillnull +| stats count min(_time) as firstTime max(_time) as lastTime by userName userIdentity.principalId userAgent bucketName requestParameters.accessControlList.x-amz-grant-read requestParameters.accessControlList.x-amz-grant-read-acp requestParameters.accessControlList.x-amz-grant-write requestParameters.accessControlList.x-amz-grant-write-acp requestParameters.accessControlList.x-amz-grant-full-control | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | `detect_new_open_s3_buckets_over_aws_cli_filter` ====Associated Analytic Story==== @@ -3067,6 +3834,30 @@ This search looks for CloudTrail events where a user has created an open/public ====Required field==== +* _time + +* eventSource + +* eventName + +* requestParameters.accessControlList.x-amz-grant-read-acp + +* requestParameters.accessControlList.x-amz-grant-write + +* requestParameters.accessControlList.x-amz-grant-write-acp + +* requestParameters.accessControlList.x-amz-grant-full-control + +* requestParameters.bucketName + +* userName + +* userIdentity.principalId + +* userAgent + +* bucketName + ====ATT&CK==== @@ -3106,8 +3897,8 @@ While this search has no known false positives, it is possible that an AWS admin ===Detect new open s3 buckets=== This search looks for CloudTrail events where a user has created an open/public S3 bucket. -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1530/ T1530] * '''Last Updated''': 2021-01-12 @@ -3115,19 +3906,19 @@ This search looks for CloudTrail events where a user has created an open/public
====Search==== -`cloudtrail` eventSource=s3.amazonaws.com eventName=PutBucketAcl -| rex field=_raw "(?{.+})" -| spath input=json_field output=grantees path=requestParameters.AccessControlPolicy.AccessControlList.Grant{} -| search grantees=* -| mvexpand grantees -| spath input=grantees output=uri path=Grantee.URI -| spath input=grantees output=permission path=Permission -| search uri IN ("http://acs.amazonaws.com/groups/global/AllUsers","http://acs.amazonaws.com/groups/global/AuthenticatedUsers") -| search permission IN ("READ","READ_ACP","WRITE","WRITE_ACP","FULL_CONTROL") -| rename requestParameters.bucketName AS bucketName -| stats count min(_time) as firstTime max(_time) as lastTime by userName userIdentity.principalId userAgent uri permission bucketName +`cloudtrail` eventSource=s3.amazonaws.com eventName=PutBucketAcl +| rex field=_raw "(?{.+})" +| spath input=json_field output=grantees path=requestParameters.AccessControlPolicy.AccessControlList.Grant{} +| search grantees=* +| mvexpand grantees +| spath input=grantees output=uri path=Grantee.URI +| spath input=grantees output=permission path=Permission +| search uri IN ("http://acs.amazonaws.com/groups/global/AllUsers","http://acs.amazonaws.com/groups/global/AuthenticatedUsers") +| search permission IN ("READ","READ_ACP","WRITE","WRITE_ACP","FULL_CONTROL") +| rename requestParameters.bucketName AS bucketName +| stats count min(_time) as firstTime max(_time) as lastTime by userName userIdentity.principalId userAgent uri permission bucketName | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | `detect_new_open_s3_buckets_filter` ====Associated Analytic Story==== @@ -3140,6 +3931,24 @@ You must install the AWS App for Splunk. ====Required field==== +* _time + +* eventSource + +* eventName + +* requestParameters.bucketName + +* userName + +* userIdentity.principalId + +* userAgent + +* uri + +* permission + ====ATT&CK==== @@ -3180,7 +3989,7 @@ While this search has no known false positives, it is possible that an AWS admin This search looks at S3 bucket-access logs and detects new or previously unseen remote IP addresses that have successfully accessed an S3 bucket. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1530/ T1530] * '''Last Updated''': 2018-06-28 @@ -3188,19 +3997,19 @@ This search looks at S3 bucket-access logs and detects new or previously unseen
====Search==== -`aws_s3_accesslogs` http_status=200 [search `aws_s3_accesslogs` http_status=200 -| stats earliest(_time) as firstTime latest(_time) as lastTime by bucket_name remote_ip -| inputlookup append=t previously_seen_S3_access_from_remote_ip.csv -| stats min(firstTime) as firstTime, max(lastTime) as lastTime by bucket_name remote_ip -| outputlookup previously_seen_S3_access_from_remote_ip.csv -| eval newIP=if(firstTime >= relative_time(now(), "-70m@m"), 1, 0) -| where newIP=1 +`aws_s3_accesslogs` http_status=200 [search `aws_s3_accesslogs` http_status=200 +| stats earliest(_time) as firstTime latest(_time) as lastTime by bucket_name remote_ip +| inputlookup append=t previously_seen_S3_access_from_remote_ip.csv +| stats min(firstTime) as firstTime, max(lastTime) as lastTime by bucket_name remote_ip +| outputlookup previously_seen_S3_access_from_remote_ip.csv +| eval newIP=if(firstTime >= relative_time(now(), "-70m@m"), 1, 0) +| where newIP=1 | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | table bucket_name remote_ip] -| iplocation remote_ip -|rename remote_ip as src_ip -| table _time bucket_name src_ip City Country operation request_uri +| iplocation remote_ip +|rename remote_ip as src_ip +| table _time bucket_name src_ip City Country operation request_uri | `detect_s3_access_from_a_new_ip_filter` ====Associated Analytic Story==== @@ -3213,6 +4022,14 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- ====Required field==== +* _time + +* http_status + +* bucket_name + +* remote_ip + ====ATT&CK==== @@ -3250,23 +4067,23 @@ S3 buckets can be accessed from any IP, as long as it can make a successful conn ===Detect spike in aws security hub alerts for ec2 instance=== This search looks for a spike in number of of AWS security Hub alerts for an EC2 instance in 4 hours intervals -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': +* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': +* '''ATT&CK''': * '''Last Updated''': 2021-01-26
====Search==== -`aws_securityhub_finding` "Resources{}.Type"=AWSEC2Instance -| bucket span=4h _time -| stats count AS alerts values(Title) as Title values(Types{}) as Types values(vendor_account) as vendor_account values(vendor_region) as vendor_region values(severity) as severity by _time dest -| eventstats avg(alerts) as total_alerts_avg, stdev(alerts) as total_alerts_stdev -| eval threshold_value = 3 -| eval isOutlier=if(alerts > total_alerts_avg+(total_alerts_stdev * threshold_value), 1, 0) -| search isOutlier=1 -| table _time dest alerts Title Types vendor_account vendor_region severity isOutlier total_alerts_avg +`aws_securityhub_finding` "Resources{}.Type"=AWSEC2Instance +| bucket span=4h _time +| stats count AS alerts values(Title) as Title values(Types{}) as Types values(vendor_account) as vendor_account values(vendor_region) as vendor_region values(severity) as severity by _time dest +| eventstats avg(alerts) as total_alerts_avg, stdev(alerts) as total_alerts_stdev +| eval threshold_value = 3 +| eval isOutlier=if(alerts > total_alerts_avg+(total_alerts_stdev * threshold_value), 1, 0) +| search isOutlier=1 +| table _time dest alerts Title Types vendor_account vendor_region severity isOutlier total_alerts_avg | `detect_spike_in_aws_security_hub_alerts_for_ec2_instance_filter` ====Associated Analytic Story==== @@ -3279,6 +4096,22 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- ====Required field==== +* _time + +* Resources{}.Type + +* Title + +* Types{} + +* vendor_account + +* vendor_region + +* severity + +* dest + @@ -3306,23 +4139,23 @@ None This search looks for a spike in number of of AWS security Hub alerts for an AWS IAM User in 4 hours intervals. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': +* '''Datamodel''': +* '''ATT&CK''': * '''Last Updated''': 2021-01-26
====Search==== -`aws_securityhub_finding` "findings{}.Resources{}.Type"= AwsIamUser -| rename findings{}.Resources{}.Id as user -| bucket span=4h _time -| stats count AS alerts by _time user -| eventstats avg(alerts) as total_launched_avg, stdev(alerts) as total_launched_stdev -| eval threshold_value = 2 -| eval isOutlier=if(alerts > total_launched_avg+(total_launched_stdev * threshold_value), 1, 0) -| search isOutlier=1 -| table _time user alerts +`aws_securityhub_finding` "findings{}.Resources{}.Type"= AwsIamUser +| rename findings{}.Resources{}.Id as user +| bucket span=4h _time +| stats count AS alerts by _time user +| eventstats avg(alerts) as total_launched_avg, stdev(alerts) as total_launched_stdev +| eval threshold_value = 2 +| eval isOutlier=if(alerts > total_launched_avg+(total_launched_stdev * threshold_value), 1, 0) +| search isOutlier=1 +| table _time user alerts |`detect_spike_in_aws_security_hub_alerts_for_user_filter` ====Associated Analytic Story==== @@ -3335,6 +4168,14 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- ====Required field==== +* _time + +* findings{}.Resources{}.Type + +* indings{}.Resources{}.Id + +* user + @@ -3360,7 +4201,7 @@ None This search detects users creating spikes in API activity related to deletion of S3 buckets in your AWS environment. It will also update the cache file that factors in the latest data. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1530/ T1530] * '''Last Updated''': 2018-11-27 @@ -3368,26 +4209,26 @@ This search detects users creating spikes in API activity related to deletion of
====Search==== -`cloudtrail` eventName=DeleteBucket [search `cloudtrail` eventName=DeleteBucket -| spath output=arn path=userIdentity.arn -| stats count as apiCalls by arn -| inputlookup s3_deletion_baseline append=t -| fields - latestCount -| stats values(*) as * by arn -| rename apiCalls as latestCount -| eval newAvgApiCalls=avgApiCalls + (latestCount-avgApiCalls)/720 -| eval newStdevApiCalls=sqrt(((pow(stdevApiCalls, 2)*719 + (latestCount-newAvgApiCalls)*(latestCount-avgApiCalls))/720)) -| eval avgApiCalls=coalesce(newAvgApiCalls, avgApiCalls), stdevApiCalls=coalesce(newStdevApiCalls, stdevApiCalls), numDataPoints=if(isnull(latestCount), numDataPoints, numDataPoints+1) -| table arn, latestCount, numDataPoints, avgApiCalls, stdevApiCalls -| outputlookup s3_deletion_baseline -| eval dataPointThreshold = 15, deviationThreshold = 3 -| eval isSpike=if((latestCount > avgApiCalls+deviationThreshold*stdevApiCalls) AND numDataPoints > dataPointThreshold, 1, 0) -| where isSpike=1 -| rename arn as userIdentity.arn -| table userIdentity.arn] -| spath output=user userIdentity.arn -| spath output=bucketName path=requestParameters.bucketName -| stats values(bucketName) as bucketName, count as numberOfApiCalls, dc(eventName) as uniqueApisCalled by user +`cloudtrail` eventName=DeleteBucket [search `cloudtrail` eventName=DeleteBucket +| spath output=arn path=userIdentity.arn +| stats count as apiCalls by arn +| inputlookup s3_deletion_baseline append=t +| fields - latestCount +| stats values(*) as * by arn +| rename apiCalls as latestCount +| eval newAvgApiCalls=avgApiCalls + (latestCount-avgApiCalls)/720 +| eval newStdevApiCalls=sqrt(((pow(stdevApiCalls, 2)*719 + (latestCount-newAvgApiCalls)*(latestCount-avgApiCalls))/720)) +| eval avgApiCalls=coalesce(newAvgApiCalls, avgApiCalls), stdevApiCalls=coalesce(newStdevApiCalls, stdevApiCalls), numDataPoints=if(isnull(latestCount), numDataPoints, numDataPoints+1) +| table arn, latestCount, numDataPoints, avgApiCalls, stdevApiCalls +| outputlookup s3_deletion_baseline +| eval dataPointThreshold = 15, deviationThreshold = 3 +| eval isSpike=if((latestCount > avgApiCalls+deviationThreshold*stdevApiCalls) AND numDataPoints > dataPointThreshold, 1, 0) +| where isSpike=1 +| rename arn as userIdentity.arn +| table userIdentity.arn] +| spath output=user userIdentity.arn +| spath output=bucketName path=requestParameters.bucketName +| stats values(bucketName) as bucketName, count as numberOfApiCalls, dc(eventName) as uniqueApisCalled by user | `detect_spike_in_s3_bucket_deletion_filter` ====Associated Analytic Story==== @@ -3400,6 +4241,12 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- ====Required field==== +* _time + +* eventName + +* userIdentity.arn + ====ATT&CK==== @@ -3438,30 +4285,30 @@ Based on the values of`dataPointThreshold` and `deviationThreshold`, the false p This search will detect spike in blocked outbound network connections originating from within your AWS environment. It will also update the cache file that factors in the latest data. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': +* '''Datamodel''': +* '''ATT&CK''': * '''Last Updated''': 2018-05-07
====Search==== -`cloudwatchlogs_vpcflow` action=blocked (src_ip=10.0.0.0/8 OR src_ip=172.16.0.0/12 OR src_ip=192.168.0.0/16) ( dest_ip!=10.0.0.0/8 AND dest_ip!=172.16.0.0/12 AND dest_ip!=192.168.0.0/16) [search `cloudwatchlogs_vpcflow` action=blocked (src_ip=10.0.0.0/8 OR src_ip=172.16.0.0/12 OR src_ip=192.168.0.0/16) ( dest_ip!=10.0.0.0/8 AND dest_ip!=172.16.0.0/12 AND dest_ip!=192.168.0.0/16) -| stats count as numberOfBlockedConnections by src_ip -| inputlookup baseline_blocked_outbound_connections append=t -| fields - latestCount -| stats values(*) as * by src_ip -| rename numberOfBlockedConnections as latestCount -| eval newAvgBlockedConnections=avgBlockedConnections + (latestCount-avgBlockedConnections)/720 -| eval newStdevBlockedConnections=sqrt(((pow(stdevBlockedConnections, 2)*719 + (latestCount-newAvgBlockedConnections)*(latestCount-avgBlockedConnections))/720)) -| eval avgBlockedConnections=coalesce(newAvgBlockedConnections, avgBlockedConnections), stdevBlockedConnections=coalesce(newStdevBlockedConnections, stdevBlockedConnections), numDataPoints=if(isnull(latestCount), numDataPoints, numDataPoints+1) -| table src_ip, latestCount, numDataPoints, avgBlockedConnections, stdevBlockedConnections -| outputlookup baseline_blocked_outbound_connections -| eval dataPointThreshold = 5, deviationThreshold = 3 -| eval isSpike=if((latestCount > avgBlockedConnections+deviationThreshold*stdevBlockedConnections) AND numDataPoints > dataPointThreshold, 1, 0) -| where isSpike=1 -| table src_ip] -| stats values(dest_ip) as "Blocked Destination IPs", values(interface_id) as "resourceId" count as numberOfBlockedConnections, dc(dest_ip) as uniqueDestConnections by src_ip +`cloudwatchlogs_vpcflow` action=blocked (src_ip=10.0.0.0/8 OR src_ip=172.16.0.0/12 OR src_ip=192.168.0.0/16) ( dest_ip!=10.0.0.0/8 AND dest_ip!=172.16.0.0/12 AND dest_ip!=192.168.0.0/16) [search `cloudwatchlogs_vpcflow` action=blocked (src_ip=10.0.0.0/8 OR src_ip=172.16.0.0/12 OR src_ip=192.168.0.0/16) ( dest_ip!=10.0.0.0/8 AND dest_ip!=172.16.0.0/12 AND dest_ip!=192.168.0.0/16) +| stats count as numberOfBlockedConnections by src_ip +| inputlookup baseline_blocked_outbound_connections append=t +| fields - latestCount +| stats values(*) as * by src_ip +| rename numberOfBlockedConnections as latestCount +| eval newAvgBlockedConnections=avgBlockedConnections + (latestCount-avgBlockedConnections)/720 +| eval newStdevBlockedConnections=sqrt(((pow(stdevBlockedConnections, 2)*719 + (latestCount-newAvgBlockedConnections)*(latestCount-avgBlockedConnections))/720)) +| eval avgBlockedConnections=coalesce(newAvgBlockedConnections, avgBlockedConnections), stdevBlockedConnections=coalesce(newStdevBlockedConnections, stdevBlockedConnections), numDataPoints=if(isnull(latestCount), numDataPoints, numDataPoints+1) +| table src_ip, latestCount, numDataPoints, avgBlockedConnections, stdevBlockedConnections +| outputlookup baseline_blocked_outbound_connections +| eval dataPointThreshold = 5, deviationThreshold = 3 +| eval isSpike=if((latestCount > avgBlockedConnections+deviationThreshold*stdevBlockedConnections) AND numDataPoints > dataPointThreshold, 1, 0) +| where isSpike=1 +| table src_ip] +| stats values(dest_ip) as "Blocked Destination IPs", values(interface_id) as "resourceId" count as numberOfBlockedConnections, dc(dest_ip) as uniqueDestConnections by src_ip | `detect_spike_in_blocked_outbound_traffic_from_your_aws_filter` ====Associated Analytic Story==== @@ -3478,6 +4325,14 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- ====Required field==== +* _time + +* action + +* src_ip + +* dest_ip + @@ -3497,72 +4352,6 @@ The false-positive rate may vary based on the values of`dataPointThreshold` and ====Test Dataset==== -''version'': 1 -
-
- ----- - -===Gcp detect accounts with high risk roles by project=== -This search provides detection of accounts with high risk roles by projects. Compromised accounts with high risk roles can move laterally or even scalate privileges at different projects depending on organization schema. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078] -* '''Last Updated''': 2020-10-09 - -
-
- -====Search==== -`google_gcp_pubsub_message` data.protoPayload.request.policy.bindings{}.role=roles/owner OR roles/editor OR roles/iam.serviceAccountUser OR roles/iam.serviceAccountAdmin OR roles/iam.serviceAccountTokenCreator OR roles/dataflow.developer OR roles/dataflow.admin OR roles/composer.admin OR roles/dataproc.admin OR roles/dataproc.editor -| table data.resource.type data.protoPayload.authenticationInfo.principalEmail data.protoPayload.authorizationInfo{}.permission data.protoPayload.authorizationInfo{}.resource data.protoPayload.response.bindings{}.role data.protoPayload.response.bindings{}.members{} -| `gcp_detect_accounts_with_high_risk_roles_by_project_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#GCP_Cross_Account_Activity|GCP Cross Account Activity]] - - -====How To Implement==== -You must install splunk GCP add-on. This search works with gcp:pubsub:message logs - -====Required field==== - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1078 -| Valid Accounts -| Defense Evasion, Initial Access, Persistence, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Lateral Movement - - -====Known False Positives==== -Accounts with high risk roles should be reduced to the minimum number needed, however specific tasks and setups may be simply expected behavior within organization - -====Reference==== - -* https://github.com/dxa4481/gcploit - -* https://www.youtube.com/watch?v=Ml09R38jpok - -* https://cloud.google.com/iam/docs/understanding-roles - - -====Test Dataset==== - - ''version'': 1
@@ -3573,7 +4362,7 @@ Accounts with high risk roles should be reduced to the minimum number needed, ho This search provides detection of GCPloit exploitation framework. This framework can be used to escalate privileges and move laterally from compromised high privilege accounts. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078] * '''Last Updated''': 2020-10-08 @@ -3581,8 +4370,8 @@ This search provides detection of GCPloit exploitation framework. This framework
====Search==== -`google_gcp_pubsub_message` data.protoPayload.request.function.timeout=539s -| table src src_user data.resource.labels.project_id data.protoPayload.request.function.serviceAccountEmail data.protoPayload.authorizationInfo{}.permission data.protoPayload.request.location http_user_agent +`google_gcp_pubsub_message` data.protoPayload.request.function.timeout=539s +| table src src_user data.resource.labels.project_id data.protoPayload.request.function.serviceAccountEmail data.protoPayload.authorizationInfo{}.permission data.protoPayload.request.location http_user_agent | `gcp_detect_gcploit_framework_filter` ====Associated Analytic Story==== @@ -3595,6 +4384,24 @@ You must install splunk GCP add-on. This search works with gcp:pubsub:message lo ====Required field==== +* _time + +* data.protoPayload.request.function.timeout + +* src + +* src_user + +* data.resource.labels.project_id + +* data.protoPayload.request.function.serviceAccountEmail + +* data.protoPayload.authorizationInfo{}.permission + +* data.protoPayload.request.location + +* http_user_agent + ====ATT&CK==== @@ -3627,72 +4434,6 @@ Payload.request.function.timeout value can possibly be match with other function ====Test Dataset==== -''version'': 1 -
-
- ----- - -===Gcp detect high risk permissions by resource and account=== -This search provides detection of high risk permissions by resource and accounts. These are permissions that can allow attackers with compromised accounts to move laterally and escalate privileges. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078] -* '''Last Updated''': 2020-10-09 - -
-
- -====Search==== -`google_gcp_pubsub_message` data.protoPayload.authorizationInfo{}.permission=iam.serviceAccounts.getaccesstoken OR iam.serviceAccounts.setIamPolicy OR iam.serviceAccounts.actas OR dataflow.jobs.create OR composer.environments.create OR dataproc.clusters.create -|table data.protoPayload.requestMetadata.callerIp data.protoPayload.authenticationInfo.principalEmail data.protoPayload.authorizationInfo{}.permission data.protoPayload.response.bindings{}.members{} data.resource.labels.project_id -| `gcp_detect_high_risk_permissions_by_resource_and_account_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#GCP_Cross_Account_Activity|GCP Cross Account Activity]] - - -====How To Implement==== -You must install splunk GCP add-on. This search works with gcp:pubsub:message logs - -====Required field==== - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1078 -| Valid Accounts -| Defense Evasion, Initial Access, Persistence, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Lateral Movement - - -====Known False Positives==== -High risk permissions are part of any GCP environment, however it is important to track resource and accounts usage, this search may produce false positives. - -====Reference==== - -* https://github.com/dxa4481/gcploit - -* https://www.youtube.com/watch?v=Ml09R38jpok - -* https://cloud.google.com/iam/docs/permissions-reference - - -====Test Dataset==== - - ''version'': 1
@@ -3703,7 +4444,7 @@ High risk permissions are part of any GCP environment, however it is important t This search provides information of unauthenticated requests via user agent, and authentication data against Kubernetes cluster's pods * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1526/ T1526] * '''Last Updated''': 2020-07-17 @@ -3711,10 +4452,10 @@ This search provides information of unauthenticated requests via user agent, and
====Search==== -`google_gcp_pubsub_message` category=kube-audit -|spath input=properties.log -|search responseStatus.code=401 -|table sourceIPs{} userAgent verb requestURI responseStatus.reason properties.pod +`google_gcp_pubsub_message` category=kube-audit +|spath input=properties.log +|search responseStatus.code=401 +|table sourceIPs{} userAgent verb requestURI responseStatus.reason properties.pod | `gcp_kubernetes_cluster_pod_scan_detection_filter` ====Associated Analytic Story==== @@ -3727,6 +4468,24 @@ You must install the GCP App for Splunk (version 2.0.0 or later), then configure ====Required field==== +* _time + +* category + +* responseStatus.code + +* sourceIPs{} + +* userAgent + +* verb + +* requestURI + +* responseStatus.reason + +* properties.pod + ====ATT&CK==== @@ -3755,70 +4514,6 @@ Not all unauthenticated requests are malicious, but frequency, User Agent, sourc ====Test Dataset==== -''version'': 1 -
-
- ----- - -===Gcp kubernetes cluster scan detection=== -This search provides information of unauthenticated requests via user agent, and authentication data against Kubernetes cluster - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1526/ T1526] -* '''Last Updated''': 2020-04-15 - -
-
- -====Search==== -`google_gcp_pubsub_message` data.protoPayload.requestMetadata.callerIp!=127.0.0.1 data.protoPayload.requestMetadata.callerIp!=::1 "data.labels.authorization.k8s.io/decision"=forbid "data.protoPayload.status.message"=PERMISSION_DENIED data.protoPayload.authenticationInfo.principalEmail="system:anonymous" -| rename data.protoPayload.requestMetadata.callerIp as src_ip -| stats count min(_time) as firstTime max(_time) as lastTime values(data.protoPayload.methodName) as method_name values(data.protoPayload.resourceName) as resource_name values(data.protoPayload.requestMetadata.callerSuppliedUserAgent) as http_user_agent by src_ip data.resource.labels.cluster_name -| rename data.resource.labels.cluster_name as cluster_name -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `gcp_kubernetes_cluster_scan_detection_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Scanning_Activity|Kubernetes Scanning Activity]] - - -====How To Implement==== -You must install the GCP App for Splunk (version 2.0.0 or later), then configure stackdriver and set a Pub/Sub subscription to be imported to Splunk. You must also install Cloud Infrastructure data model.Customize the macro kubernetes_gcp_scan_fingerprint_attack_detection to filter out FPs. - -====Required field==== - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1526 -| Cloud Service Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Not all unauthenticated requests are malicious, but frequency, User Agent and source IPs will provide context. - -====Reference==== - - -====Test Dataset==== - - ''version'': 1
@@ -3829,7 +4524,7 @@ Not all unauthenticated requests are malicious, but frequency, User Agent and so This search will detect more than 5 login failures in Office365 Azure Active Directory from a single source IP address. Please adjust the threshold value of 5 as suited for your environment. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1110.001/ T1110.001] * '''Last Updated''': 2020-12-16 @@ -3837,8 +4532,8 @@ This search will detect more than 5 login failures in Office365 Azure Active Dir
====Search==== -`o365_management_activity` Operation=UserLoginFailed record_type=AzureActiveDirectoryStsLogon app=AzureActiveDirectory -| stats count dc(user) as accounts_locked values(user) as user values(LogonError) as LogonError values(authentication_method) as authentication_method values(signature) as signature values(UserAgent) as UserAgent by src_ip record_type Operation app +`o365_management_activity` Operation=UserLoginFailed record_type=AzureActiveDirectoryStsLogon app=AzureActiveDirectory +| stats count dc(user) as accounts_locked values(user) as user values(LogonError) as LogonError values(authentication_method) as authentication_method values(signature) as signature values(UserAgent) as UserAgent by src_ip record_type Operation app | search accounts_locked >= 5 | `high_number_of_login_failures_from_a_single_source_filter` @@ -3852,6 +4547,28 @@ This search will detect more than 5 login failures in Office365 Azure Active Dir ====Required field==== +* _time + +* Operation + +* record_type + +* app + +* user + +* LogonError + +* authentication_method + +* signature + +* UserAgent + +* src_ip + +* record_type + ====ATT&CK==== @@ -3880,206 +4597,6 @@ unknown ====Test Dataset==== -''version'': 1 -
-
- ----- - -===Kubernetes aws detect rbac authorization by account=== -This search provides information on Kubernetes RBAC authorizations by accounts, this search can be modified by adding top to see both extremes of RBAC by accounts occurrences - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': -* '''Last Updated''': 2020-06-23 - -
-
- -====Search==== -`aws_cloudwatchlogs_eks` annotations.authorization.k8s.io/reason=* -| table sourceIPs{} user.username userAgent annotations.authorization.k8s.io/reason -| stats count by user.username annotations.authorization.k8s.io/reason -| rare user.username annotations.authorization.k8s.io/reason -|`kubernetes_aws_detect_rbac_authorization_by_account_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Sensitive_Role_Activity|Kubernetes Sensitive Role Activity]] - - -====How To Implement==== -You must install splunk AWS add on and Splunk App for AWS. This search works with cloudwatch logs - -====Required field==== - - - - -====Kill Chain Phase==== - -* Lateral Movement - - -====Known False Positives==== -Not all RBAC Authorications are malicious. RBAC authorizations can uncover malicious activity specially if sensitive Roles have been granted. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Kubernetes aws detect most active service accounts by pod=== -This search provides information on Kubernetes service accounts,accessing pods by IP address, verb and decision - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': -* '''Last Updated''': 2020-06-23 - -
-
- -====Search==== -`aws_cloudwatchlogs_eks` user.groups{}=system:serviceaccounts objectRef.resource=pods -| table sourceIPs{} user.username userAgent verb annotations.authorization.k8s.io/decision -| top sourceIPs{} user.username verb annotations.authorization.k8s.io/decision -|`kubernetes_aws_detect_most_active_service_accounts_by_pod_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Sensitive_Role_Activity|Kubernetes Sensitive Role Activity]] - - -====How To Implement==== -You must install splunk AWS add on and Splunk App for AWS. This search works with cloudwatch logs - -====Required field==== - - - - -====Kill Chain Phase==== - -* Lateral Movement - - -====Known False Positives==== -Not all service accounts interactions are malicious. Analyst must consider IP, verb and decision context when trying to detect maliciousness. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Kubernetes aws detect sensitive role access=== -This search provides information on Kubernetes accounts accessing sensitve objects such as configmpas or secrets - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': -* '''Last Updated''': 2020-06-23 - -
-
- -====Search==== -`aws_cloudwatchlogs_eks` objectRef.resource=clusterroles OR clusterrolebindings sourceIPs{}!=::1 sourceIPs{}!=127.0.0.1 -| table sourceIPs{} user.username user.groups{} objectRef.namespace requestURI annotations.authorization.k8s.io/reason -| dedup user.username user.groups{} -|`kubernetes_aws_detect_sensitive_role_access_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Sensitive_Role_Activity|Kubernetes Sensitive Role Activity]] - - -====How To Implement==== -You must install splunk AWS add on and Splunk App for AWS. This search works with cloudwatch logs. - -====Required field==== - - - - -====Kill Chain Phase==== - -* Lateral Movement - - -====Known False Positives==== -Sensitive role resource access is necessary for cluster operation, however source IP, namespace and user group may indicate possible malicious use. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Kubernetes aws detect service accounts forbidden failure access=== -This search provides information on Kubernetes service accounts with failure or forbidden access status, this search can be extended by using top or rare operators to find trends or rarities in failure status, user agents, source IPs and request URI - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': -* '''Last Updated''': 2020-06-23 - -
-
- -====Search==== -`aws_cloudwatchlogs_eks` user.groups{}=system:serviceaccounts responseStatus.status = Failure -| table sourceIPs{} user.username userAgent verb responseStatus.status requestURI -| `kubernetes_aws_detect_service_accounts_forbidden_failure_access_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Sensitive_Object_Access_Activity|Kubernetes Sensitive Object Access Activity]] - - -====How To Implement==== -You must install splunk AWS add on and Splunk App for AWS. This search works with cloudwatch logs. - -====Required field==== - - - - -====Kill Chain Phase==== - -* Lateral Movement - - -====Known False Positives==== -This search can give false positives as there might be inherent issues with authentications and permissions at cluster. - -====Reference==== - - -====Test Dataset==== - - ''version'': 1
@@ -4090,17 +4607,17 @@ This search can give false positives as there might be inherent issues with auth This search provides information on anonymous Kubectl calls with IP, verb namespace and object access context * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': +* '''Datamodel''': +* '''ATT&CK''': * '''Last Updated''': 2020-06-23
====Search==== -`aws_cloudwatchlogs_eks` userAgent=kubectl* sourceIPs{}!=127.0.0.1 sourceIPs{}!=::1 src_user=system:anonymous -| table src_ip src_user verb userAgent requestURI -| stats count by src_ip src_user verb userAgent requestURI +`aws_cloudwatchlogs_eks` userAgent=kubectl* sourceIPs{}!=127.0.0.1 sourceIPs{}!=::1 src_user=system:anonymous +| table src_ip src_user verb userAgent requestURI +| stats count by src_ip src_user verb userAgent requestURI |`kubernetes_aws_detect_suspicious_kubectl_calls_filter` ====Associated Analytic Story==== @@ -4113,6 +4630,20 @@ You must install splunk AWS add on and Splunk App for AWS. This search works wit ====Required field==== +* _time + +* userAgent + +* sourceIPs{} + +* src_user + +* src_ip + +* verb + +* requestURI + @@ -4130,732 +4661,6 @@ Kubectl calls are not malicious by nature. However source IP, verb and Object ca ====Test Dataset==== -''version'': 1 -
-
- ----- - -===Kubernetes azure detect rbac authorization by account=== -This search provides information on Kubernetes RBAC authorizations by accounts, this search can be modified by adding rare or top to see both extremes of RBAC by accounts occurrences - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': -* '''Last Updated''': 2020-05-26 - -
-
- -====Search==== -`kubernetes_azure` category=kube-audit -| spath input=properties.log -| search annotations.authorization.k8s.io/reason=* -| table sourceIPs{} user.username userAgent annotations.authorization.k8s.io/reason -|stats count by user.username annotations.authorization.k8s.io/reason -| rare user.username annotations.authorization.k8s.io/reason -|`kubernetes_azure_detect_rbac_authorization_by_account_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Sensitive_Role_Activity|Kubernetes Sensitive Role Activity]] - - -====How To Implement==== -You must install the Add-on for Microsoft Cloud Services and Configure Kube-Audit data diagnostics - -====Required field==== - - - - -====Kill Chain Phase==== - -* Lateral Movement - - -====Known False Positives==== -Not all RBAC Authorications are malicious. RBAC authorizations can uncover malicious activity specially if sensitive Roles have been granted. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Kubernetes azure detect most active service accounts by pod namespace=== -This search provides information on Kubernetes service accounts,accessing pods and namespaces by IP address and verb - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': -* '''Last Updated''': 2020-05-26 - -
-
- -====Search==== -`kubernetes_azure` category=kube-audit -| spath input=properties.log -| search user.groups{}=system:serviceaccounts* OR user.username=system.anonymous OR annotations.authorization.k8s.io/decision=allow -| table sourceIPs{} user.username userAgent verb responseStatus.reason responseStatus.status properties.pod objectRef.namespace -| top sourceIPs{} user.username verb responseStatus.status properties.pod objectRef.namespace -|`kubernetes_azure_detect_most_active_service_accounts_by_pod_namespace_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Sensitive_Role_Activity|Kubernetes Sensitive Role Activity]] - - -====How To Implement==== -You must install the Add-on for Microsoft Cloud Services and Configure Kube-Audit data diagnostics - -====Required field==== - - - - -====Kill Chain Phase==== - -* Lateral Movement - - -====Known False Positives==== -Not all service accounts interactions are malicious. Analyst must consider IP and verb context when trying to detect maliciousness. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Kubernetes azure detect sensitive object access=== -This search provides information on Kubernetes accounts accessing sensitve objects such as configmpas or secrets - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': -* '''Last Updated''': 2020-05-20 - -
-
- -====Search==== -`kubernetes_azure` category=kube-audit -| spath input=properties.log -| search objectRef.resource=secrets OR configmaps user.username=system.anonymous OR annotations.authorization.k8s.io/decision=allow -|table user.username user.groups{} objectRef.resource objectRef.namespace objectRef.name annotations.authorization.k8s.io/reason -|dedup user.username user.groups{} -|`kubernetes_azure_detect_sensitive_object_access_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Sensitive_Object_Access_Activity|Kubernetes Sensitive Object Access Activity]] - - -====How To Implement==== -You must install the Add-on for Microsoft Cloud Services and Configure Kube-Audit data diagnostics - -====Required field==== - - - - -====Kill Chain Phase==== - -* Lateral Movement - - -====Known False Positives==== -Sensitive object access is not necessarily malicious but user and object context can provide guidance for detection. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Kubernetes azure detect sensitive role access=== -This search provides information on Kubernetes accounts accessing sensitve objects such as configmpas or secrets - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': -* '''Last Updated''': 2020-05-20 - -
-
- -====Search==== -`kubernetes_azure` category=kube-audit -| spath input=properties.log -| search objectRef.resource=clusterroles OR clusterrolebindings -| table sourceIPs{} user.username user.groups{} objectRef.namespace requestURI annotations.authorization.k8s.io/reason -| dedup user.username user.groups{} -|`kubernetes_azure_detect_sensitive_role_access_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Sensitive_Role_Activity|Kubernetes Sensitive Role Activity]] - - -====How To Implement==== -You must install the Add-on for Microsoft Cloud Services and Configure Kube-Audit data diagnostics - -====Required field==== - - - - -====Kill Chain Phase==== - -* Lateral Movement - - -====Known False Positives==== -Sensitive role resource access is necessary for cluster operation, however source IP, namespace and user group may indicate possible malicious use. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Kubernetes azure detect service accounts forbidden failure access=== -This search provides information on Kubernetes service accounts with failure or forbidden access status - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': -* '''Last Updated''': 2020-05-20 - -
-
- -====Search==== -`kubernetes_azure` category=kube-audit -| spath input=properties.log -| search user.groups{}=system:serviceaccounts* responseStatus.reason=Forbidden -| table sourceIPs{} user.username userAgent verb responseStatus.reason responseStatus.status properties.pod objectRef.namespace -|`kubernetes_azure_detect_service_accounts_forbidden_failure_access_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Sensitive_Object_Access_Activity|Kubernetes Sensitive Object Access Activity]] - - -====How To Implement==== -You must install the Add-on for Microsoft Cloud Services and Configure Kube-Audit data diagnostics - -====Required field==== - - - - -====Kill Chain Phase==== - -* Lateral Movement - - -====Known False Positives==== -This search can give false positives as there might be inherent issues with authentications and permissions at cluster. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Kubernetes azure detect suspicious kubectl calls=== -This search provides information on rare Kubectl calls with IP, verb namespace and object access context - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': -* '''Last Updated''': 2020-05-26 - -
-
- -====Search==== -`kubernetes_azure` category=kube-audit -| spath input=properties.log -| spath input=responseObject.metadata.annotations.kubectl.kubernetes.io/last-applied-configuration -| search userAgent=kubectl* sourceIPs{}!=127.0.0.1 sourceIPs{}!=::1 -| table sourceIPs{} verb userAgent user.groups{} objectRef.resource objectRef.namespace requestURI -| rare sourceIPs{} verb userAgent user.groups{} objectRef.resource objectRef.namespace requestURI -|`kubernetes_azure_detect_suspicious_kubectl_calls_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Sensitive_Object_Access_Activity|Kubernetes Sensitive Object Access Activity]] - - -====How To Implement==== -You must install the Add-on for Microsoft Cloud Services and Configure Kube-Audit data diagnostics - -====Required field==== - - - - -====Kill Chain Phase==== - -* Lateral Movement - - -====Known False Positives==== -Kubectl calls are not malicious by nature. However source IP, verb and Object can reveal potential malicious activity, specially suspicious IPs and sensitive objects such as configmaps or secrets - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Kubernetes azure pod scan fingerprint=== -This search provides information of unauthenticated requests via source IP user agent, request URI and response status data against Kubernetes cluster pod in Azure - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': -* '''Last Updated''': 2020-05-20 - -
-
- -====Search==== -`kubernetes_azure` category=kube-audit -| spath input=properties.log -| search responseStatus.code=401 -| table sourceIPs{} userAgent verb requestURI responseStatus.reason properties.pod -|`kubernetes_azure_pod_scan_fingerprint_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Scanning_Activity|Kubernetes Scanning Activity]] - - -====How To Implement==== -You must install the Add-on for Microsoft Cloud Services and Configure Kube-Audit data diagnostics - -====Required field==== - - - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Not all unauthenticated requests are malicious, but source IPs, userAgent, verb, request URI and response status will provide context. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Kubernetes azure scan fingerprint=== -This search provides information of unauthenticated requests via source IP user agent, request URI and response status data against Kubernetes cluster in Azure - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1526/ T1526] -* '''Last Updated''': 2020-05-19 - -
-
- -====Search==== -`kubernetes_azure` category=kube-audit -| spath input=properties.log -| search responseStatus.code=401 -| table sourceIPs{} userAgent verb requestURI responseStatus.reason -|`kubernetes_azure_scan_fingerprint_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Scanning_Activity|Kubernetes Scanning Activity]] - - -====How To Implement==== -You must install the Add-on for Microsoft Cloud Services and Configure Kube-Audit data diagnostics - -====Required field==== - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1526 -| Cloud Service Discovery -| Discovery -|} - - -====Kill Chain Phase==== - -* Reconnaissance - - -====Known False Positives==== -Not all unauthenticated requests are malicious, but source IPs, userAgent, verb, request URI and response status will provide context. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Kubernetes gcp detect rbac authorizations by account=== -This search provides information on Kubernetes RBAC authorizations by accounts, this search can be modified by adding top to see both extremes of RBAC by accounts occurrences - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': -* '''Last Updated''': 2020-07-11 - -
-
- -====Search==== -`google_gcp_pubsub_message` data.labels.authorization.k8s.io/reason=ClusterRoleBinding OR Clusterrole -| table src_ip src_user data.labels.authorization.k8s.io/decision data.labels.authorization.k8s.io/reason -| rare src_user data.labels.authorization.k8s.io/reason -|`kubernetes_gcp_detect_rbac_authorizations_by_account_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Sensitive_Role_Activity|Kubernetes Sensitive Role Activity]] - - -====How To Implement==== -You must install splunk AWS add on for GCP. This search works with pubsub messaging service logs - -====Required field==== - - - - -====Kill Chain Phase==== - -* Lateral Movement - - -====Known False Positives==== -Not all RBAC Authorications are malicious. RBAC authorizations can uncover malicious activity specially if sensitive Roles have been granted. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Kubernetes gcp detect most active service accounts by pod=== -This search provides information on Kubernetes service accounts,accessing pods by IP address, verb and decision - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': -* '''Last Updated''': 2020-07-10 - -
-
- -====Search==== -`google_gcp_pubsub_message` data.protoPayload.request.spec.group{}=system:serviceaccounts -| table src_ip src_user http_user_agent data.protoPayload.request.spec.nonResourceAttributes.verb data.labels.authorization.k8s.io/decision data.protoPayload.response.spec.resourceAttributes.resource -| top src_ip src_user http_user_agent data.labels.authorization.k8s.io/decision data.protoPayload.response.spec.resourceAttributes.resource -|`kubernetes_gcp_detect_most_active_service_accounts_by_pod_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Sensitive_Role_Activity|Kubernetes Sensitive Role Activity]] - - -====How To Implement==== -You must install splunk GCP add on. This search works with pubsub messaging service logs - -====Required field==== - - - - -====Kill Chain Phase==== - -* Lateral Movement - - -====Known False Positives==== -Not all service accounts interactions are malicious. Analyst must consider IP, verb and decision context when trying to detect maliciousness. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Kubernetes gcp detect sensitive object access=== -This search provides information on Kubernetes accounts accessing sensitve objects such as configmaps or secrets - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': -* '''Last Updated''': 2020-07-11 - -
-
- -====Search==== -`google_gcp_pubsub_message` data.protoPayload.authorizationInfo{}.resource=configmaps OR secrets -| table data.protoPayload.requestMetadata.callerIp src_user data.resource.labels.cluster_name data.protoPayload.request.metadata.namespace data.labels.authorization.k8s.io/decision -| dedup data.protoPayload.requestMetadata.callerIp src_user data.resource.labels.cluster_name -|`kubernetes_gcp_detect_sensitive_object_access_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Sensitive_Object_Access_Activity|Kubernetes Sensitive Object Access Activity]] - - -====How To Implement==== -You must install splunk add on for GCP . This search works with pubsub messaging service logs. - -====Required field==== - - - - -====Kill Chain Phase==== - -* Lateral Movement - - -====Known False Positives==== -Sensitive object access is not necessarily malicious but user and object context can provide guidance for detection. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Kubernetes gcp detect sensitive role access=== -This search provides information on Kubernetes accounts accessing sensitve objects such as configmpas or secrets - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': -* '''Last Updated''': 2020-07-11 - -
-
- -====Search==== -`google_gcp_pubsub_message` data.labels.authorization.k8s.io/reason=ClusterRoleBinding OR Clusterrole dest=apis/rbac.authorization.k8s.io/v1 src_ip!=::1 -| table src_ip src_user http_user_agent data.labels.authorization.k8s.io/decision data.labels.authorization.k8s.io/reason -| dedup src_ip src_user -|`kubernetes_gcp_detect_sensitive_role_access_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Sensitive_Role_Activity|Kubernetes Sensitive Role Activity]] - - -====How To Implement==== -You must install splunk add on for GCP. This search works with pubsub messaging servicelogs. - -====Required field==== - - - - -====Kill Chain Phase==== - -* Lateral Movement - - -====Known False Positives==== -Sensitive role resource access is necessary for cluster operation, however source IP, user agent, decision and reason may indicate possible malicious use. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Kubernetes gcp detect service accounts forbidden failure access=== -This search provides information on Kubernetes service accounts with failure or forbidden access status, this search can be extended by using top or rare operators to find trends or rarities in failure status, user agents, source IPs and request URI - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': -* '''Last Updated''': 2020-06-23 - -
-
- -====Search==== -`google_gcp_pubsub_message` system:serviceaccounts data.protoPayload.response.status.allowed!=* -| table src_ip src_user http_user_agent data.protoPayload.response.spec.resourceAttributes.namespace data.resource.labels.cluster_name data.protoPayload.response.spec.resourceAttributes.verb data.protoPayload.request.status.allowed data.protoPayload.response.status.reason data.labels.authorization.k8s.io/decision -| dedup src_ip src_user -| `kubernetes_gcp_detect_service_accounts_forbidden_failure_access_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Sensitive_Object_Access_Activity|Kubernetes Sensitive Object Access Activity]] - - -====How To Implement==== -You must install splunk add on for GCP. This search works with pubsub messaging service logs. - -====Required field==== - - - - -====Kill Chain Phase==== - -* Lateral Movement - - -====Known False Positives==== -This search can give false positives as there might be inherent issues with authentications and permissions at cluster. - -====Reference==== - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Kubernetes gcp detect suspicious kubectl calls=== -This search provides information on anonymous Kubectl calls with IP, verb namespace and object access context - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': -* '''Last Updated''': 2020-07-11 - -
-
- -====Search==== -`google_gcp_pubsub_message` data.protoPayload.requestMetadata.callerSuppliedUserAgent=kubectl* src_user=system:unsecured OR src_user=system:anonymous -| table src_ip src_user data.protoPayload.requestMetadata.callerSuppliedUserAgent data.protoPayload.authorizationInfo{}.granted object_path -|dedup src_ip src_user -|`kubernetes_gcp_detect_suspicious_kubectl_calls_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Sensitive_Object_Access_Activity|Kubernetes Sensitive Object Access Activity]] - - -====How To Implement==== -You must install splunk add on for GCP. This search works with pubsub messaging logs. - -====Required field==== - - - - -====Kill Chain Phase==== - -* Lateral Movement - - -====Known False Positives==== -Kubectl calls are not malicious by nature. However source IP, source user, user agent, object path, and authorization context can reveal potential malicious activity, specially anonymous suspicious IPs and sensitive objects such as configmaps or secrets - -====Reference==== - - -====Test Dataset==== - - ''version'': 1
@@ -4866,7 +4671,7 @@ Kubectl calls are not malicious by nature. However source IP, source user, user This searches show information on uploaded containers including source user, image id, source IP user type, http user agent, region, first time, last time of operation (PutImage). These searches are based on Cloud Infrastructure Data Model. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1525/ T1525] * '''Last Updated''': 2020-02-20 @@ -4875,8 +4680,8 @@ This searches show information on uploaded containers including source user, ima ====Search==== -| tstats count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Cloud_Infrastructure.Compute where Compute.user_type!="AssumeRole" AND Compute.http_user_agent="AWS Internal" AND Compute.event_name="PutImage" by Compute.image_id Compute.src_user Compute.src Compute.region Compute.msg Compute.user_type -| `drop_dm_object_name("Compute")` +| tstats count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Cloud_Infrastructure.Compute where Compute.user_type!="AssumeRole" AND Compute.http_user_agent="AWS Internal" AND Compute.event_name="PutImage" by Compute.image_id Compute.src_user Compute.src Compute.region Compute.msg Compute.user_type +| `drop_dm_object_name("Compute")` | `new_container_uploaded_to_aws_ecr_filter` ====Associated Analytic Story==== @@ -4889,6 +4694,8 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- ====Required field==== +* _time + ====ATT&CK==== @@ -4924,8 +4731,8 @@ Uploading container is a normal behavior from developers or users with access to ===O365 add app role assignment grant user=== This search detects the creation of a new Federation setting by alerting about an specific event related to its creation. -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1136.003/ T1136.003] * '''Last Updated''': 2021-01-26 @@ -4933,10 +4740,10 @@ This search detects the creation of a new Federation setting by alerting about a
====Search==== -`o365_management_activity` Workload=AzureActiveDirectory Operation="Add app role assignment grant to user." -| stats count min(_time) as firstTime max(_time) as lastTime values(Actor{}.ID) as Actor.ID values(Actor{}.Type) as Actor.Type by ActorIpAddress dest ResultStatus +`o365_management_activity` Workload=AzureActiveDirectory Operation="Add app role assignment grant to user." +| stats count min(_time) as firstTime max(_time) as lastTime values(Actor{}.ID) as Actor.ID values(Actor{}.Type) as Actor.Type by ActorIpAddress dest ResultStatus | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | `o365_add_app_role_assignment_grant_user_filter` ====Associated Analytic Story==== @@ -4951,6 +4758,22 @@ You must install splunk Microsoft Office 365 add-on. This search works with o365 ====Required field==== +* _time + +* Workload + +* Operation + +* Actor{}.ID + +* Actor{}.Type + +* ActorIpAddress + +* dest + +* ResultStatus + ====ATT&CK==== @@ -4994,8 +4817,8 @@ The creation of a new Federation is not necessarily malicious, however this even ===O365 added service principal=== This search detects the creation of a new Federation setting by alerting about an specific event related to its creation. -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1136.003/ T1136.003] * '''Last Updated''': 2021-01-26 @@ -5003,10 +4826,10 @@ This search detects the creation of a new Federation setting by alerting about a
====Search==== -`o365_management_activity` Workload=AzureActiveDirectory signature="Add service principal credentials." -| stats min(_time) as firstTime max(_time) as lastTime values(Actor{}.ID) as Actor.ID values(ModifiedProperties{}.Name) as ModifiedProperties.Name values(ModifiedProperties{}.NewValue) as ModifiedProperties.NewValue values(Target{}.ID) as Target.ID by ActorIpAddress signature +`o365_management_activity` Workload=AzureActiveDirectory signature="Add service principal credentials." +| stats min(_time) as firstTime max(_time) as lastTime values(Actor{}.ID) as Actor.ID values(ModifiedProperties{}.Name) as ModifiedProperties.Name values(ModifiedProperties{}.NewValue) as ModifiedProperties.NewValue values(Target{}.ID) as Target.ID by ActorIpAddress signature | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | `o365_added_service_principal_filter` ====Associated Analytic Story==== @@ -5021,6 +4844,22 @@ You must install splunk Microsoft Office 365 add-on. This search works with o365 ====Required field==== +* _time + +* Workload + +* signature + +* Actor{}.ID + +* ModifiedProperties{}.Name + +* ModifiedProperties{}.NewValue + +* Target{}.ID + +* ActorIpAddress + ====ATT&CK==== @@ -5068,8 +4907,8 @@ The creation of a new Federation is not necessarily malicious, however these eve ===O365 bypass mfa via trusted ip=== This search detects newly added IP addresses/CIDR blocks to the list of MFA Trusted IPs to bypass multi factor authentication. Attackers are often known to use this technique so that they can bypass the MFA system. -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1562.007/ T1562.007] * '''Last Updated''': 2021-01-12 @@ -5077,13 +4916,13 @@ This search detects newly added IP addresses/CIDR blocks to the list of MFA Trus
====Search==== -`o365_management_activity` signature="Set Company Information." ModifiedProperties{}.Name=StrongAuthenticationPolicy -| rex max_match=100 field=ModifiedProperties{}.NewValue "(?\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\/\d{1,2})" -| rex max_match=100 field=ModifiedProperties{}.OldValue "(?\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\/\d{1,2})" -| eval ip_addresses_old=if(isnotnull(ip_addresses_old),ip_addresses_old,"0") -| mvexpand ip_addresses_new_added -| where isnull(mvfind(ip_addresses_old,ip_addresses_new_added)) -|stats count min(_time) as firstTime max(_time) as lastTime values(ip_addresses_old) as ip_addresses_old by user ip_addresses_new_added signature vendor_product vendor_account status user_id action +`o365_management_activity` signature="Set Company Information." ModifiedProperties{}.Name=StrongAuthenticationPolicy +| rex max_match=100 field=ModifiedProperties{}.NewValue "(?\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\/\d{1,2})" +| rex max_match=100 field=ModifiedProperties{}.OldValue "(?\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\/\d{1,2})" +| eval ip_addresses_old=if(isnotnull(ip_addresses_old),ip_addresses_old,"0") +| mvexpand ip_addresses_new_added +| where isnull(mvfind(ip_addresses_old,ip_addresses_new_added)) +|stats count min(_time) as firstTime max(_time) as lastTime values(ip_addresses_old) as ip_addresses_old by user ip_addresses_new_added signature vendor_product vendor_account status user_id action | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `o365_bypass_mfa_via_trusted_ip_filter` @@ -5098,6 +4937,28 @@ You must install Splunk Microsoft Office 365 add-on. This search works with o365 ====Required field==== +* _time + +* signature + +* ModifiedProperties{}.Name + +* ModifiedProperties{}.NewValue + +* ModifiedProperties{}.OldValue + +* user + +* vendor_product + +* vendor_account + +* status + +* user_id + +* action + ====ATT&CK==== @@ -5141,8 +5002,8 @@ Unless it is a special case, it is uncommon to continually update Trusted IPs to ===O365 disable mfa=== This search detects when multi factor authentication has been disabled, what entitiy performed the action and against what user -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1556/ T1556] * '''Last Updated''': 2020-12-16 @@ -5150,10 +5011,10 @@ This search detects when multi factor authentication has been disabled, what ent
====Search==== -`o365_management_activity` Operation="Disable Strong Authentication." -| stats count earliest(_time) as firstTime latest(_time) as lastTime by UserType Operation user status signature dest ResultStatus -|`security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` +`o365_management_activity` Operation="Disable Strong Authentication." +| stats count earliest(_time) as firstTime latest(_time) as lastTime by UserType Operation user status signature dest ResultStatus +|`security_content_ctime(firstTime)` +|`security_content_ctime(lastTime)` | `o365_disable_mfa_filter` ====Associated Analytic Story==== @@ -5166,6 +5027,22 @@ You must install splunk Microsoft Office 365 add-on. This search works with o365 ====Required field==== +* _time + +* Operation + +* UserType + +* user + +* status + +* signature + +* dest + +* ResultStatus + ====ATT&CK==== @@ -5207,8 +5084,8 @@ Unless it is a special case, it is uncommon to disable MFA or Strong Authenticat ===O365 excessive authentication failures alert=== This search detects when an excessive number of authentication failures occur this search also includes attempts against MFA prompt codes -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1110/ T1110] * '''Last Updated''': 2020-12-16 @@ -5216,11 +5093,11 @@ This search detects when an excessive number of authentication failures occur th
====Search==== -`o365_management_activity` Workload=AzureActiveDirectory UserAuthenticationMethod=* status=Failed -| stats count earliest(_time) as firstTime latest(_time) values(UserAuthenticationMethod) AS UserAuthenticationMethod values(UserAgent) AS UserAgent values(status) AS status values(src_ip) AS src_ip by user -| where count > 10 -|`security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` +`o365_management_activity` Workload=AzureActiveDirectory UserAuthenticationMethod=* status=Failed +| stats count earliest(_time) as firstTime latest(_time) values(UserAuthenticationMethod) AS UserAuthenticationMethod values(UserAgent) AS UserAgent values(status) AS status values(src_ip) AS src_ip by user +| where count > 10 +|`security_content_ctime(firstTime)` +|`security_content_ctime(lastTime)` | `o365_excessive_authentication_failures_alert_filter` ====Associated Analytic Story==== @@ -5233,6 +5110,20 @@ You must install splunk Microsoft Office 365 add-on. This search works with o365 ====Required field==== +* _time + +* Workload + +* UserAuthenticationMethod + +* status + +* UserAgent + +* src_ip + +* user + ====ATT&CK==== @@ -5274,8 +5165,8 @@ The threshold for alert is above 10 attempts and this should reduce the number o ===O365 excessive sso logon errors=== This search detects accounts with high number of Single Sign ON (SSO) logon errors. Excessive logon errors may indicate attempts to bruteforce of password or single sign on token hijack or reuse. -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1556/ T1556] * '''Last Updated''': 2021-01-26 @@ -5283,11 +5174,11 @@ This search detects accounts with high number of Single Sign ON (SSO) logon erro
====Search==== -`o365_management_activity` Workload=AzureActiveDirectory LogonError=SsoArtifactInvalidOrExpired -| stats count min(_time) as firstTime max(_time) as lastTime by LogonError ActorIpAddress UserAgent UserId -| where count > 5 +`o365_management_activity` Workload=AzureActiveDirectory LogonError=SsoArtifactInvalidOrExpired +| stats count min(_time) as firstTime max(_time) as lastTime by LogonError ActorIpAddress UserAgent UserId +| where count > 5 | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | `o365_excessive_sso_logon_errors_filter` ====Associated Analytic Story==== @@ -5302,6 +5193,18 @@ You must install splunk Microsoft Office 365 add-on. This search works with o365 ====Required field==== +* _time + +* Workload + +* LogonError + +* ActorIpAddress + +* UserAgent + +* UserId + ====ATT&CK==== @@ -5343,8 +5246,8 @@ Logon errors may not be malicious in nature however it may indicate attempts to ===O365 new federated domain added=== This search detects the addition of a new Federated domain. -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1136.003/ T1136.003] * '''Last Updated''': 2021-01-26 @@ -5352,10 +5255,10 @@ This search detects the addition of a new Federated domain.
====Search==== -`o365_management_activity` Workload=Exchange Operation="Add-FederatedDomain" -| stats count min(_time) as firstTime max(_time) as lastTime values(Parameters{}.Value) as Parameters.Value by ObjectId Operation OrganizationName OriginatingServer UserId UserKey -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +`o365_management_activity` Workload=Exchange Operation="Add-FederatedDomain" +| stats count min(_time) as firstTime max(_time) as lastTime values(Parameters{}.Value) as Parameters.Value by ObjectId Operation OrganizationName OriginatingServer UserId UserKey +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `o365_new_federated_domain_added_filter` ====Associated Analytic Story==== @@ -5370,6 +5273,24 @@ You must install splunk Microsoft Office 365 add-on. This search works with o365 ====Required field==== +* _time + +* Workload + +* Operation + +* Parameters{}.Value + +* ObjectId + +* OrganizationName + +* OriginatingServer + +* UserId + +* UserKey + ====ATT&CK==== @@ -5419,8 +5340,8 @@ The creation of a new Federated domain is not necessarily malicious, however the ===O365 pst export alert=== This search detects when a user has performed an Ediscovery search or exported a PST file from the search. This PST file usually has sensitive information including email body content -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1114/ T1114] * '''Last Updated''': 2020-12-16 @@ -5428,10 +5349,10 @@ This search detects when a user has performed an Ediscovery search or exported a
====Search==== -`o365_management_activity` Category=ThreatManagement Name="eDiscovery search started or exported" -| stats count earliest(_time) as firstTime latest(_time) as lastTime by Source Severity AlertEntityId Operation Name -|`security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` +`o365_management_activity` Category=ThreatManagement Name="eDiscovery search started or exported" +| stats count earliest(_time) as firstTime latest(_time) as lastTime by Source Severity AlertEntityId Operation Name +|`security_content_ctime(firstTime)` +|`security_content_ctime(lastTime)` | `o365_pst_export_alert_filter` ====Associated Analytic Story==== @@ -5444,6 +5365,20 @@ You must install splunk Microsoft Office 365 add-on. This search works with o365 ====Required field==== +* _time + +* Category + +* Name + +* Source + +* Severity + +* AlertEntityId + +* Operation + ====ATT&CK==== @@ -5485,8 +5420,8 @@ PST export can be done for legitimate purposes but due to the sensitive nature o ===O365 suspicious admin email forwarding=== This search detects when an admin configured a forwarding rule for multiple mailboxes to the same destination. -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1114.003/ T1114.003] * '''Last Updated''': 2020-12-16 @@ -5494,14 +5429,14 @@ This search detects when an admin configured a forwarding rule for multiple mail
====Search==== -`o365_management_activity` Operation=Set-Mailbox -| spath input=Parameters -| rename Identity AS src_user -| search ForwardingAddress=* -| stats dc(src_user) AS count_src_user earliest(_time) as firstTime latest(_time) as lastTime values(src_user) AS src_user values(user) AS user by ForwardingAddress -| where count_src_user > 1 -|`security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` +`o365_management_activity` Operation=Set-Mailbox +| spath input=Parameters +| rename Identity AS src_user +| search ForwardingAddress=* +| stats dc(src_user) AS count_src_user earliest(_time) as firstTime latest(_time) as lastTime values(src_user) AS src_user values(user) AS user by ForwardingAddress +| where count_src_user > 1 +|`security_content_ctime(firstTime)` +|`security_content_ctime(lastTime)` |`o365_suspicious_admin_email_forwarding_filter` ====Associated Analytic Story==== @@ -5510,10 +5445,16 @@ This search detects when an admin configured a forwarding rule for multiple mail ====How To Implement==== - +You must install splunk Microsoft Office 365 add-on. This search works with o365:management:activity ====Required field==== +* _time + +* Operation + +* Parameters + ====ATT&CK==== @@ -5553,8 +5494,8 @@ unknown ===O365 suspicious rights delegation=== This search detects the assignment of rights to accesss content from another mailbox. This is usually only assigned to a service account. -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1114.002/ T1114.002] * '''Last Updated''': 2020-12-15 @@ -5562,13 +5503,13 @@ This search detects the assignment of rights to accesss content from another mai
====Search==== -`o365_management_activity` Operation=Add-MailboxPermission -| spath input=Parameters -| rename User AS src_user, Identity AS dest_user -| search AccessRights=FullAccess OR AccessRights=SendAs OR AccessRights=SendOnBehalf -| stats count earliest(_time) as firstTime latest(_time) as lastTime by user src_user dest_user Operation AccessRights -|`security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` +`o365_management_activity` Operation=Add-MailboxPermission +| spath input=Parameters +| rename User AS src_user, Identity AS dest_user +| search AccessRights=FullAccess OR AccessRights=SendAs OR AccessRights=SendOnBehalf +| stats count earliest(_time) as firstTime latest(_time) as lastTime by user src_user dest_user Operation AccessRights +|`security_content_ctime(firstTime)` +|`security_content_ctime(lastTime)` |`o365_suspicious_rights_delegation_filter` ====Associated Analytic Story==== @@ -5577,10 +5518,16 @@ This search detects the assignment of rights to accesss content from another mai ====How To Implement==== - +You must install splunk Microsoft Office 365 add-on. This search works with o365:management:activity ====Required field==== +* _time + +* Operation + +* Parameters + ====ATT&CK==== @@ -5620,8 +5567,8 @@ Service Accounts ===O365 suspicious user email forwarding=== This search detects when multiple user configured a forwarding rule to the same destination. -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1114.003/ T1114.003] * '''Last Updated''': 2020-12-16 @@ -5629,14 +5576,14 @@ This search detects when multiple user configured a forwarding rule to the same
====Search==== -`o365_management_activity` Operation=Set-Mailbox -| spath input=Parameters -| rename Identity AS src_user -| search ForwardingSmtpAddress=* -| stats dc(src_user) AS count_src_user earliest(_time) as firstTime latest(_time) as lastTime values(src_user) AS src_user values(user) AS user by ForwardingSmtpAddress -| where count_src_user > 1 -|`security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` +`o365_management_activity` Operation=Set-Mailbox +| spath input=Parameters +| rename Identity AS src_user +| search ForwardingSmtpAddress=* +| stats dc(src_user) AS count_src_user earliest(_time) as firstTime latest(_time) as lastTime values(src_user) AS src_user values(user) AS user by ForwardingSmtpAddress +| where count_src_user > 1 +|`security_content_ctime(firstTime)` +|`security_content_ctime(lastTime)` |`o365_suspicious_user_email_forwarding_filter` ====Associated Analytic Story==== @@ -5645,10 +5592,16 @@ This search detects when multiple user configured a forwarding rule to the same ====How To Implement==== - +You must install splunk Microsoft Office 365 add-on. This search works with o365:management:activity ====Required field==== +* _time + +* Operation + +* Parameters + ====ATT&CK==== @@ -5689,7 +5642,7 @@ unknown This search provides detection of an user attaching itself to a different role trust policy. This can be used for lateral movement and escalation of privileges. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078] * '''Last Updated''': 2020-07-27 @@ -5698,8 +5651,8 @@ This search provides detection of an user attaching itself to a different role t ====Search==== `aws_cloudwatchlogs_eks` attach policy -| spath requestParameters.policyArn -| table sourceIPAddress user_access_key userIdentity.arn userIdentity.sessionContext.sessionIssuer.arn eventName errorCode errorMessage status action requestParameters.policyArn userIdentity.sessionContext.attributes.mfaAuthenticated userIdentity.sessionContext.attributes.creationDate +| spath requestParameters.policyArn +| table sourceIPAddress user_access_key userIdentity.arn userIdentity.sessionContext.sessionIssuer.arn eventName errorCode errorMessage status action requestParameters.policyArn userIdentity.sessionContext.attributes.mfaAuthenticated userIdentity.sessionContext.attributes.creationDate | `aws_detect_attach_to_role_policy_filter` ====Associated Analytic Story==== @@ -5712,6 +5665,10 @@ You must install splunk AWS add-on and Splunk App for AWS. This search works wit ====Required field==== +* _time + +* requestParameters.policyArn + ====ATT&CK==== @@ -5750,7 +5707,7 @@ Attach to policy can create a lot of noise. This search can be adjusted to provi This search provides detection of accounts creating permanent keys. Permanent keys are not created by default and they are only needed for programmatic calls. Creation of Permanent key is an important event to monitor. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078] * '''Last Updated''': 2020-07-27 @@ -5758,10 +5715,10 @@ This search provides detection of accounts creating permanent keys. Permanent ke
====Search==== -`aws_cloudwatchlogs_eks` CreateAccessKey -| spath eventName -| search eventName=CreateAccessKey "userIdentity.type"=IAMUser -| table sourceIPAddress userName userIdentity.type userAgent action status responseElements.accessKey.createDate responseElements.accessKey.status responseElements.accessKey.accessKeyId +`aws_cloudwatchlogs_eks` CreateAccessKey +| spath eventName +| search eventName=CreateAccessKey "userIdentity.type"=IAMUser +| table sourceIPAddress userName userIdentity.type userAgent action status responseElements.accessKey.createDate responseElements.accessKey.status responseElements.accessKey.accessKeyId |`aws_detect_permanent_key_creation_filter` ====Associated Analytic Story==== @@ -5774,6 +5731,28 @@ You must install splunk AWS add on and Splunk App for AWS. This search works wit ====Required field==== +* _time + +* eventName + +* userIdentity.type + +* sourceIPAddress + +* userName userIdentity.type + +* userAgent + +* action + +* status + +* responseElements.accessKey.createDate + +* esponseElements.accessKey.status + +* responseElements.accessKey.accessKeyId + ====ATT&CK==== @@ -5812,7 +5791,7 @@ Not all permanent key creations are malicious. If there is a policy of rotating This search provides detection of role creation by IAM users. Role creation is an event by itself if user is creating a new role with trust policies different than the available in AWS and it can be used for lateral movement and escalation of privileges. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078] * '''Last Updated''': 2020-07-27 @@ -5820,8 +5799,8 @@ This search provides detection of role creation by IAM users. Role creation is a
====Search==== -`aws_cloudwatchlogs_eks` event_name=CreateRole action=created userIdentity.type=AssumedRole requestParameters.description=Allows* -| table sourceIPAddress userIdentity.principalId userIdentity.arn action event_name awsRegion http_user_agent mfa_auth msg requestParameters.roleName requestParameters.description responseElements.role.arn responseElements.role.createDate +`aws_cloudwatchlogs_eks` event_name=CreateRole action=created userIdentity.type=AssumedRole requestParameters.description=Allows* +| table sourceIPAddress userIdentity.principalId userIdentity.arn action event_name awsRegion http_user_agent mfa_auth msg requestParameters.roleName requestParameters.description responseElements.role.arn responseElements.role.createDate | `aws_detect_role_creation_filter` ====Associated Analytic Story==== @@ -5834,6 +5813,42 @@ You must install splunk AWS add-on and Splunk App for AWS. This search works wit ====Required field==== +* _time + +* event_name + +* action + +* userIdentity.type + +* requestParameters.description + +* sourceIPAddress + +* userIdentity.principalId + +* userIdentity.arn + +* action + +* event_name + +* awsRegion + +* http_user_agent + +* mfa_auth + +* msg + +* requestParameters.roleName + +* requestParameters.description + +* responseElements.role.arn + +* responseElements.role.createDate + ====ATT&CK==== @@ -5872,7 +5887,7 @@ CreateRole is not very common in common users. This search can be adjusted to pr This search provides detection of suspicious use of sts:AssumeRole. These tokens can be created on the go and used by attackers to move laterally and escalate privileges. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078] * '''Last Updated''': 2020-07-27 @@ -5880,8 +5895,8 @@ This search provides detection of suspicious use of sts:AssumeRole. These tokens
====Search==== -`cloudtrail` user_type=AssumedRole userIdentity.sessionContext.sessionIssuer.type=Role -| table sourceIPAddress userIdentity.arn user_agent user_access_key status action requestParameters.roleName responseElements.role.roleName responseElements.role.createDate +`cloudtrail` user_type=AssumedRole userIdentity.sessionContext.sessionIssuer.type=Role +| table sourceIPAddress userIdentity.arn user_agent user_access_key status action requestParameters.roleName responseElements.role.roleName responseElements.role.createDate | `aws_detect_sts_assume_role_abuse_filter` ====Associated Analytic Story==== @@ -5894,6 +5909,30 @@ You must install splunk AWS add on and Splunk App for AWS. This search works wit ====Required field==== +* _time + +* user_type + +* userIdentity.sessionContext.sessionIssuer.type + +* sourceIPAddress + +* userIdentity.arn + +* user_agent + +* user_access_key + +* status + +* action + +* requestParameters.roleName + +* esponseElements.role.roleName + +* esponseElements.role.createDate + ====ATT&CK==== @@ -5932,7 +5971,7 @@ Sts:AssumeRole can be very noisy as it is a standard mechanism to provide cross This search provides detection of suspicious use of sts:GetSessionToken. These tokens can be created on the go and used by attackers to move laterally and escalate privileges. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1550/ T1550] * '''Last Updated''': 2020-07-27 @@ -5941,9 +5980,9 @@ This search provides detection of suspicious use of sts:GetSessionToken. These t ====Search==== `aws_cloudwatchlogs_eks` ASIA userIdentity.type=IAMUser -| spath eventName -| search eventName=GetSessionToken -| table sourceIPAddress eventTime userIdentity.arn userName userAgent user_type status region +| spath eventName +| search eventName=GetSessionToken +| table sourceIPAddress eventTime userIdentity.arn userName userAgent user_type status region | `aws_detect_sts_get_session_token_abuse_filter` ====Associated Analytic Story==== @@ -5956,6 +5995,28 @@ You must install splunk AWS add-on and Splunk App for AWS. This search works wit ====Required field==== +* _time + +* userIdentity.type + +* eventName + +* sourceIPAddress + +* eventTime + +* userIdentity.arn + +* userName + +* userAgent + +* user_type + +* status + +* region + ====ATT&CK==== @@ -5984,70 +6045,6 @@ Sts:GetSessionToken can be very noisy as in certain environments numerous calls ====Test Dataset==== -''version'': 1 -
-
- ----- - -===Gcp detect oauth token abuse=== -This search provides detection of possible GCP Oauth token abuse. GCP Oauth token without time limit can be exfiltrated and reused for keeping access sessions alive without further control of authentication, allowing attackers to access and move laterally. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078] -* '''Last Updated''': 2020-09-01 - -
-
- -====Search==== -`google_gcp_pubsub_message` type.googleapis.com/google.cloud.audit.AuditLog -|table protoPayload.@type protoPayload.status.details{}.@type protoPayload.status.details{}.violations{}.callerIp protoPayload.status.details{}.violations{}.type protoPayload.status.message -| `gcp_detect_oauth_token_abuse_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#GCP_Cross_Account_Activity|GCP Cross Account Activity]] - - -====How To Implement==== -You must install splunk GCP add-on. This search works with gcp:pubsub:message logs - -====Required field==== - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1078 -| Valid Accounts -| Defense Evasion, Initial Access, Persistence, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Lateral Movement - - -====Known False Positives==== -GCP Oauth token abuse detection will only work if there are access policies in place along with audit logs. - -====Reference==== - -* https://www.netskope.com/blog/gcp-oauth-token-hijacking-in-google-cloud-part-1 - -* https://www.netskope.com/blog/gcp-oauth-token-hijacking-in-google-cloud-part-2 - - -====Test Dataset==== - - ''version'': 1
@@ -6060,10 +6057,10 @@ GCP Oauth token abuse detection will only work if there are access policies in p ===Aws cloud provisioning from previously unseen city=== -This search looks for AWS provisioning activities from previously unseen cities. Provisioning activities are defined broadly as any event that begins with "Run" or "Create." This search is deprecated and have been translated to use the latest Change Datamodel. +This search looks for AWS provisioning activities from previously unseen cities. Provisioning activities are defined broadly as any event that begins with "Run" or "Create." This search is deprecated and have been translated to use the latest Change Datamodel. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1535/ T1535] * '''Last Updated''': 2018-03-16 @@ -6071,22 +6068,22 @@ This search looks for AWS provisioning activities from previously unseen cities.
====Search==== -`cloudtrail` (eventName=Run* OR eventName=Create*) -| iplocation sourceIPAddress -| search City=* [search `cloudtrail` (eventName=Run* OR eventName=Create*) -| iplocation sourceIPAddress -| search City=* -| stats earliest(_time) as firstTime, latest(_time) as lastTime by sourceIPAddress, City, Region, Country -| inputlookup append=t previously_seen_provisioning_activity_src.csv -| stats min(firstTime) as firstTime max(lastTime) as lastTime by sourceIPAddress, City, Region, Country -| outputlookup previously_seen_provisioning_activity_src.csv -| stats min(firstTime) as firstTime max(lastTime) as lastTime by City -| eval newCity=if(firstTime >= relative_time(now(), "-70m@m"), 1, 0) -| where newCity=1 -| table City] -| spath output=user userIdentity.arn -| rename sourceIPAddress as src_ip -| table _time, user, src_ip, City, eventName, errorCode +`cloudtrail` (eventName=Run* OR eventName=Create*) +| iplocation sourceIPAddress +| search City=* [search `cloudtrail` (eventName=Run* OR eventName=Create*) +| iplocation sourceIPAddress +| search City=* +| stats earliest(_time) as firstTime, latest(_time) as lastTime by sourceIPAddress, City, Region, Country +| inputlookup append=t previously_seen_provisioning_activity_src.csv +| stats min(firstTime) as firstTime max(lastTime) as lastTime by sourceIPAddress, City, Region, Country +| outputlookup previously_seen_provisioning_activity_src.csv +| stats min(firstTime) as firstTime max(lastTime) as lastTime by City +| eval newCity=if(firstTime >= relative_time(now(), "-70m@m"), 1, 0) +| where newCity=1 +| table City] +| spath output=user userIdentity.arn +| rename sourceIPAddress as src_ip +| table _time, user, src_ip, City, eventName, errorCode | `aws_cloud_provisioning_from_previously_unseen_city_filter` ====Associated Analytic Story==== @@ -6099,6 +6096,12 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- ====Required field==== +* _time + +* eventName + +* sourceIPAddress + ====ATT&CK==== @@ -6133,10 +6136,10 @@ This is a strictly behavioral search, so we define "false positive" slightly dif ---- ===Aws cloud provisioning from previously unseen country=== -This search looks for AWS provisioning activities from previously unseen countries. Provisioning activities are defined broadly as any event that begins with "Run" or "Create." This search is deprecated and have been translated to use the latest Change Datamodel. +This search looks for AWS provisioning activities from previously unseen countries. Provisioning activities are defined broadly as any event that begins with "Run" or "Create." This search is deprecated and have been translated to use the latest Change Datamodel. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1535/ T1535] * '''Last Updated''': 2018-03-16 @@ -6144,22 +6147,22 @@ This search looks for AWS provisioning activities from previously unseen countri
====Search==== -`cloudtrail` (eventName=Run* OR eventName=Create*) -| iplocation sourceIPAddress -| search Country=* [search `cloudtrail` (eventName=Run* OR eventName=Create*) -| iplocation sourceIPAddress -| search Country=* -| stats earliest(_time) as firstTime, latest(_time) as lastTime by sourceIPAddress, City, Region, Country -| inputlookup append=t previously_seen_provisioning_activity_src.csv -| stats min(firstTime) as firstTime max(lastTime) as lastTime by sourceIPAddress, City, Region, Country -| outputlookup previously_seen_provisioning_activity_src.csv -| stats min(firstTime) as firstTime max(lastTime) as lastTime by Country -| eval newCountry=if(firstTime >= relative_time(now(), "-70m@m"), 1, 0) -| where newCountry=1 -| table Country] -| spath output=user userIdentity.arn -| rename sourceIPAddress as src_ip -| table _time, user, src_ip, Country, eventName, errorCode +`cloudtrail` (eventName=Run* OR eventName=Create*) +| iplocation sourceIPAddress +| search Country=* [search `cloudtrail` (eventName=Run* OR eventName=Create*) +| iplocation sourceIPAddress +| search Country=* +| stats earliest(_time) as firstTime, latest(_time) as lastTime by sourceIPAddress, City, Region, Country +| inputlookup append=t previously_seen_provisioning_activity_src.csv +| stats min(firstTime) as firstTime max(lastTime) as lastTime by sourceIPAddress, City, Region, Country +| outputlookup previously_seen_provisioning_activity_src.csv +| stats min(firstTime) as firstTime max(lastTime) as lastTime by Country +| eval newCountry=if(firstTime >= relative_time(now(), "-70m@m"), 1, 0) +| where newCountry=1 +| table Country] +| spath output=user userIdentity.arn +| rename sourceIPAddress as src_ip +| table _time, user, src_ip, Country, eventName, errorCode | `aws_cloud_provisioning_from_previously_unseen_country_filter` ====Associated Analytic Story==== @@ -6172,6 +6175,12 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- ====Required field==== +* _time + +* eventName + +* sourceIPAddress + ====ATT&CK==== @@ -6206,31 +6215,31 @@ This is a strictly behavioral search, so we define "false positive" slightly dif ---- ===Aws cloud provisioning from previously unseen ip address=== -This search looks for AWS provisioning activities from previously unseen IP addresses. Provisioning activities are defined broadly as any event that begins with "Run" or "Create." This search is deprecated and have been translated to use the latest Change Datamodel. +This search looks for AWS provisioning activities from previously unseen IP addresses. Provisioning activities are defined broadly as any event that begins with "Run" or "Create." This search is deprecated and have been translated to use the latest Change Datamodel. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': +* '''Datamodel''': +* '''ATT&CK''': * '''Last Updated''': 2018-03-16
====Search==== -`cloudtrail` (eventName=Run* OR eventName=Create*) [search `cloudtrail` (eventName=Run* OR eventName=Create*) -| iplocation sourceIPAddress -| search Country=* -| stats earliest(_time) as firstTime, latest(_time) as lastTime by sourceIPAddress, City, Region, Country -| inputlookup append=t previously_seen_provisioning_activity_src.csv -| stats min(firstTime) as firstTime max(lastTime) as lastTime by sourceIPAddress, City, Region, Country -| outputlookup previously_seen_provisioning_activity_src.csv -| stats min(firstTime) as firstTime max(lastTime) as lastTime by sourceIPAddress -| eval newIP=if(firstTime >= relative_time(now(), "-70m@m"), 1, 0) -| where newIP=1 -| table sourceIPAddress] -| spath output=user userIdentity.arn -| rename sourceIPAddress as src_ip -| table _time, user, src_ip, eventName, errorCode +`cloudtrail` (eventName=Run* OR eventName=Create*) [search `cloudtrail` (eventName=Run* OR eventName=Create*) +| iplocation sourceIPAddress +| search Country=* +| stats earliest(_time) as firstTime, latest(_time) as lastTime by sourceIPAddress, City, Region, Country +| inputlookup append=t previously_seen_provisioning_activity_src.csv +| stats min(firstTime) as firstTime max(lastTime) as lastTime by sourceIPAddress, City, Region, Country +| outputlookup previously_seen_provisioning_activity_src.csv +| stats min(firstTime) as firstTime max(lastTime) as lastTime by sourceIPAddress +| eval newIP=if(firstTime >= relative_time(now(), "-70m@m"), 1, 0) +| where newIP=1 +| table sourceIPAddress] +| spath output=user userIdentity.arn +| rename sourceIPAddress as src_ip +| table _time, user, src_ip, eventName, errorCode | `aws_cloud_provisioning_from_previously_unseen_ip_address_filter` ====Associated Analytic Story==== @@ -6243,6 +6252,12 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- ====Required field==== +* _time + +* eventName + +* sourceIPAddress + @@ -6269,7 +6284,7 @@ This is a strictly behavioral search, so we define "false positive" slightly dif This search looks for AWS provisioning activities from previously unseen regions. Region in this context is similar to a state in the United States. Provisioning activities are defined broadly as any event that begins with "Run" or "Create." This search is deprecated and have been translated to use the latest Change Datamodel. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1535/ T1535] * '''Last Updated''': 2018-03-16 @@ -6277,22 +6292,22 @@ This search looks for AWS provisioning activities from previously unseen regions
====Search==== -`cloudtrail` (eventName=Run* OR eventName=Create*) -| iplocation sourceIPAddress -| search Region=* [search `cloudtrail` (eventName=Run* OR eventName=Create*) -| iplocation sourceIPAddress -| search Region=* -| stats earliest(_time) as firstTime, latest(_time) as lastTime by sourceIPAddress, City, Region, Country -| inputlookup append=t previously_seen_provisioning_activity_src.csv -| stats min(firstTime) as firstTime max(lastTime) as lastTime by sourceIPAddress, City, Region, Country -| outputlookup previously_seen_provisioning_activity_src.csv -| stats min(firstTime) as firstTime max(lastTime) as lastTime by Region -| eval newRegion=if(firstTime >= relative_time(now(), "-70m@m"), 1, 0) -| where newRegion=1 -| table Region] -| spath output=user userIdentity.arn -| rename sourceIPAddress as src_ip -| table _time, user, src_ip, Region, eventName, errorCode +`cloudtrail` (eventName=Run* OR eventName=Create*) +| iplocation sourceIPAddress +| search Region=* [search `cloudtrail` (eventName=Run* OR eventName=Create*) +| iplocation sourceIPAddress +| search Region=* +| stats earliest(_time) as firstTime, latest(_time) as lastTime by sourceIPAddress, City, Region, Country +| inputlookup append=t previously_seen_provisioning_activity_src.csv +| stats min(firstTime) as firstTime max(lastTime) as lastTime by sourceIPAddress, City, Region, Country +| outputlookup previously_seen_provisioning_activity_src.csv +| stats min(firstTime) as firstTime max(lastTime) as lastTime by Region +| eval newRegion=if(firstTime >= relative_time(now(), "-70m@m"), 1, 0) +| where newRegion=1 +| table Region] +| spath output=user userIdentity.arn +| rename sourceIPAddress as src_ip +| table _time, user, src_ip, Region, eventName, errorCode | `aws_cloud_provisioning_from_previously_unseen_region_filter` ====Associated Analytic Story==== @@ -6305,6 +6320,12 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- ====Required field==== +* _time + +* eventName + +* sourceIPAddress + ====ATT&CK==== @@ -6332,6 +6353,58 @@ This is a strictly behavioral search, so we define "false positive" slightly dif ====Test Dataset==== +''version'': 1 +
+
+ +---- + +===Aws eks kubernetes cluster sensitive object access=== +This search provides information on Kubernetes accounts accessing sensitve objects such as configmaps or secrets + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': +* '''ATT&CK''': +* '''Last Updated''': 2020-06-23 + +
+
+ +====Search==== +`aws_cloudwatchlogs_eks` objectRef.resource=secrets OR configmaps sourceIPs{}!=::1 sourceIPs{}!=127.0.0.1 +|table sourceIPs{} user.username user.groups{} objectRef.resource objectRef.namespace objectRef.name annotations.authorization.k8s.io/reason +|dedup user.username user.groups{} +|`aws_eks_kubernetes_cluster_sensitive_object_access_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Sensitive_Object_Access_Activity|Kubernetes Sensitive Object Access Activity]] + + +====How To Implement==== +You must install Splunk Add-on for Amazon Web Services and Splunk App for AWS. This search works with cloudwatch logs. + +====Required field==== + +* _time + + + + +====Kill Chain Phase==== + +* Lateral Movement + + +====Known False Positives==== +Sensitive object access is not necessarily malicious but user and object context can provide guidance for detection. + +====Reference==== + + +====Test Dataset==== + + ''version'': 1
@@ -6342,7 +6415,7 @@ This is a strictly behavioral search, so we define "false positive" slightly dif This search looks for CloudTrail events where a user successfully launches an abnormally high number of instances. This search is deprecated and have been translated to use the latest Change Datamodel * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1078.004/ T1078.004] * '''Last Updated''': 2020-07-21 @@ -6350,15 +6423,15 @@ This search looks for CloudTrail events where a user successfully launches an ab
====Search==== -`cloudtrail` eventName=RunInstances errorCode=success -| bucket span=10m _time -| stats count AS instances_launched by _time userName -| eventstats avg(instances_launched) as total_launched_avg, stdev(instances_launched) as total_launched_stdev -| eval threshold_value = 4 -| eval isOutlier=if(instances_launched > total_launched_avg+(total_launched_stdev * threshold_value), 1, 0) -| search isOutlier=1 AND _time >= relative_time(now(), "-10m@m") -| eval num_standard_deviations_away = round(abs(instances_launched - total_launched_avg) / total_launched_stdev, 2) -| table _time, userName, instances_launched, num_standard_deviations_away, total_launched_avg, total_launched_stdev +`cloudtrail` eventName=RunInstances errorCode=success +| bucket span=10m _time +| stats count AS instances_launched by _time userName +| eventstats avg(instances_launched) as total_launched_avg, stdev(instances_launched) as total_launched_stdev +| eval threshold_value = 4 +| eval isOutlier=if(instances_launched > total_launched_avg+(total_launched_stdev * threshold_value), 1, 0) +| search isOutlier=1 AND _time >= relative_time(now(), "-10m@m") +| eval num_standard_deviations_away = round(abs(instances_launched - total_launched_avg) / total_launched_stdev, 2) +| table _time, userName, instances_launched, num_standard_deviations_away, total_launched_avg, total_launched_stdev | `abnormally_high_aws_instances_launched_by_user_filter` ====Associated Analytic Story==== @@ -6373,6 +6446,14 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- ====Required field==== +* _time + +* eventName + +* errorCode + +* userName + ====ATT&CK==== @@ -6411,7 +6492,7 @@ Many service accounts configured within an AWS infrastructure are known to exhib This search looks for CloudTrail events where a user successfully launches an abnormally high number of instances. This search is deprecated and have been translated to use the latest Change Datamodel. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1078.004/ T1078.004] * '''Last Updated''': 2020-07-21 @@ -6419,11 +6500,11 @@ This search looks for CloudTrail events where a user successfully launches an ab
====Search==== -`cloudtrail` eventName=RunInstances errorCode=success `abnormally_high_aws_instances_launched_by_user___mltk_filter` -| bucket span=10m _time -| stats count as instances_launched by _time src_user -| apply ec2_excessive_runinstances_v1 -| rename "IsOutlier(instances_launched)" as isOutlier +`cloudtrail` eventName=RunInstances errorCode=success `abnormally_high_aws_instances_launched_by_user___mltk_filter` +| bucket span=10m _time +| stats count as instances_launched by _time src_user +| apply ec2_excessive_runinstances_v1 +| rename "IsOutlier(instances_launched)" as isOutlier | where isOutlier=1 ====Associated Analytic Story==== @@ -6438,6 +6519,14 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- ====Required field==== +* _time + +* eventName + +* errorCode + +* src_user + ====ATT&CK==== @@ -6476,7 +6565,7 @@ Many service accounts configured within an AWS infrastructure are known to exhib This search looks for CloudTrail events where an abnormally high number of instances were successfully terminated by a user in a 10-minute window. This search is deprecated and have been translated to use the latest Change Datamodel. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1078.004/ T1078.004] * '''Last Updated''': 2020-07-21 @@ -6484,15 +6573,15 @@ This search looks for CloudTrail events where an abnormally high number of insta
====Search==== -`cloudtrail` eventName=TerminateInstances errorCode=success -| bucket span=10m _time -| stats count AS instances_terminated by _time userName -| eventstats avg(instances_terminated) as total_terminations_avg, stdev(instances_terminated) as total_terminations_stdev -| eval threshold_value = 4 -| eval isOutlier=if(instances_terminated > total_terminations_avg+(total_terminations_stdev * threshold_value), 1, 0) +`cloudtrail` eventName=TerminateInstances errorCode=success +| bucket span=10m _time +| stats count AS instances_terminated by _time userName +| eventstats avg(instances_terminated) as total_terminations_avg, stdev(instances_terminated) as total_terminations_stdev +| eval threshold_value = 4 +| eval isOutlier=if(instances_terminated > total_terminations_avg+(total_terminations_stdev * threshold_value), 1, 0) | search isOutlier=1 AND _time >= relative_time(now(), "-10m@m") -| eval num_standard_deviations_away = round(abs(instances_terminated - total_terminations_avg) / total_terminations_stdev, 2) -|table _time, userName, instances_terminated, num_standard_deviations_away, total_terminations_avg, total_terminations_stdev +| eval num_standard_deviations_away = round(abs(instances_terminated - total_terminations_avg) / total_terminations_stdev, 2) +|table _time, userName, instances_terminated, num_standard_deviations_away, total_terminations_avg, total_terminations_stdev | `abnormally_high_aws_instances_terminated_by_user_filter` ====Associated Analytic Story==== @@ -6505,6 +6594,14 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- ====Required field==== +* _time + +* eventName + +* errorCode + +* userName + ====ATT&CK==== @@ -6543,7 +6640,7 @@ Many service accounts configured with your AWS infrastructure are known to exhib This search looks for CloudTrail events where a user successfully terminates an abnormally high number of instances. This search is deprecated and have been translated to use the latest Change Datamodel. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1078.004/ T1078.004] * '''Last Updated''': 2020-07-21 @@ -6551,11 +6648,11 @@ This search looks for CloudTrail events where a user successfully terminates an
====Search==== -`cloudtrail` eventName=TerminateInstances errorCode=success `abnormally_high_aws_instances_terminated_by_user___mltk_filter` -| bucket span=10m _time -| stats count as instances_terminated by _time src_user -| apply ec2_excessive_terminateinstances_v1 -| rename "IsOutlier(instances_terminated)" as isOutlier +`cloudtrail` eventName=TerminateInstances errorCode=success `abnormally_high_aws_instances_terminated_by_user___mltk_filter` +| bucket span=10m _time +| stats count as instances_terminated by _time src_user +| apply ec2_excessive_terminateinstances_v1 +| rename "IsOutlier(instances_terminated)" as isOutlier | where isOutlier=1 ====Associated Analytic Story==== @@ -6568,6 +6665,14 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- ====Required field==== +* _time + +* eventName + +* errorCode + +* src_user + ====ATT&CK==== @@ -6615,9 +6720,9 @@ This search allows you to identify the endpoints that have connected to more tha ====Search==== -| tstats `security_content_summariesonly` count, values(DNS.dest) AS dest dc(DNS.dest) as dest_count from datamodel=Network_Resolution where DNS.message_type=QUERY by DNS.src -| `drop_dm_object_name("Network_Resolution")` -|where dest_count > 5 +| tstats `security_content_summariesonly` count, values(DNS.dest) AS dest dc(DNS.dest) as dest_count from datamodel=Network_Resolution where DNS.message_type=QUERY by DNS.src +| `drop_dm_object_name("Network_Resolution")` +|where dest_count > 5 | `clients_connecting_to_multiple_dns_servers_filter` ====Associated Analytic Story==== @@ -6638,6 +6743,14 @@ Detailed documentation on how to create a new field within Incident Review may b ====Required field==== +* _time + +* DNS.dest + +* DNS.message_type + +* DNS.src + ====ATT&CK==== @@ -6676,8 +6789,8 @@ It's possible that an enterprise has more than five DNS servers that are configu Enforcing network-access controls is one of the defensive mechanisms used by cloud administrators to restrict access to a cloud instance. After the attacker has gained control of the console by compromising an admin account, they can delete a network ACL and gain access to the instance from anywhere. This search will query the Change datamodel to detect users deleting network ACLs. Deprecated because it's a duplicate * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': +* '''Datamodel''': +* '''ATT&CK''': * '''Last Updated''': 2020-09-08
@@ -6685,10 +6798,10 @@ Enforcing network-access controls is one of the defensive mechanisms used by clo ====Search==== `cloudtrail` eventName=DeleteNetworkAcl -|rename userIdentity.arn as arn -| stats count min(_time) as firstTime max(_time) as lastTime values(errorMessage) values(errorCode) values(userAgent) values(userIdentity.*) by src userName arn eventName -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` +|rename userIdentity.arn as arn +| stats count min(_time) as firstTime max(_time) as lastTime values(errorMessage) values(errorCode) values(userAgent) values(userIdentity.*) by src userName arn eventName +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` | `cloud_network_access_control_list_deleted_filter` ====Associated Analytic Story==== @@ -6701,6 +6814,24 @@ You must be ingesting your cloud infrastructure logs from your cloud provider. Y ====Required field==== +* _time + +* eventName + +* userIdentity.arn + +* errorMessage + +* errorCode + +* userAgent + +* src + +* userName + +* arn + @@ -6737,8 +6868,8 @@ This search will detect DNS requests resolved by unauthorized DNS servers. Legit ====Search==== -| tstats `security_content_summariesonly` count from datamodel=Network_Resolution where DNS.dest_category != dns_server AND DNS.src_category != dns_server by DNS.src DNS.dest -| `drop_dm_object_name("DNS")` +| tstats `security_content_summariesonly` count from datamodel=Network_Resolution where DNS.dest_category != dns_server AND DNS.src_category != dns_server by DNS.src DNS.dest +| `drop_dm_object_name("DNS")` | `dns_query_requests_resolved_by_unauthorized_dns_servers_filter` ====Associated Analytic Story==== @@ -6757,6 +6888,16 @@ To successfully implement this search you will need to ensure that DNS data is p ====Required field==== +* _time + +* DNS.dest_category + +* DNS.src_category + +* DNS.src + +* DNS.dest + ====ATT&CK==== @@ -6785,6 +6926,98 @@ Legitimate DNS activity can be detected in this search. Investigate, verify and ====Test Dataset==== +''version'': 3 +
+
+ +---- + +===Dns record changed=== +The search takes the DNS records and their answers results of the discovered_dns_records lookup and finds if any records have changed by searching DNS response from the Network_Resolution datamodel across the last day. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Network_Resolution +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1071.004/ T1071.004] +* '''Last Updated''': 2020-07-21 + +
+
+ +====Search==== + +| inputlookup discovered_dns_records +| rename answer as discovered_answer +| join domain[ +|tstats `security_content_summariesonly` count values(DNS.record_type) as type, values(DNS.answer) as current_answer values(DNS.src) as src from datamodel=Network_Resolution where DNS.message_type=RESPONSE DNS.answer!="unknown" DNS.answer!="" by DNS.query +| rename DNS.query as query +| where query!="unknown" +| rex field=query "(?\w+\.\w+?)(?:$ +|/)"] +| makemv delim=" " answer +| makemv delim=" " type +| sort -count +| table count,src,domain,type,query,current_answer,discovered_answer +| makemv current_answer +| mvexpand current_answer +| makemv discovered_answer +| eval n=mvfind(discovered_answer, current_answer) +| where isnull(n) +| `dns_record_changed_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#DNS_Hijacking|DNS Hijacking]] + + +====How To Implement==== +To successfully implement this search you will need to ensure that DNS data is populating the `Network_Resolution` data model. It also requires that the `discover_dns_record` lookup table be populated by the included support search "Discover DNS record". \ + **Splunk>Phantom Playbook Integration**\ +If Splunk>Phantom is also configured in your environment, a Playbook called "DNS Hijack Enrichment" can be configured to run when any results are found by this detection search. The playbook takes in the DNS record changed and uses Geoip, whois, Censys and PassiveTotal to detect if DNS issuers changed. To use this integration, install the Phantom App for Splunk `https://splunkbase.splunk.com/app/3411/`, add the correct hostname to the "Phantom Instance" field in the Adaptive Response Actions when configuring this detection search, and set the corresponding Playbook to active. \ +(Playbook Link:`https://my.phantom.us/4.2/playbook/dns-hijack-enrichment/`).\ + + +====Required field==== + +* _time + +* DNS.record_type + +* DNS.answer + +* DNS.src + +* DNS.message_type + +* DNS.query + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1071.004 +| DNS +| Command and Control +|} + + +====Kill Chain Phase==== + +* Command and Control + + +====Known False Positives==== +Legitimate DNS changes can be detected in this search. Investigate, verify and update the list of provided current answers for the domains in question as appropriate. + +====Reference==== + + +====Test Dataset==== + + ''version'': 3
@@ -6795,22 +7028,22 @@ Legitimate DNS activity can be detected in this search. Investigate, verify and This search looks for CloudTrail events where a user logged into the AWS account, is making API calls and has not enabled Multi Factor authentication. Multi factor authentication adds a layer of security by forcing the users to type a unique authentication code from an approved authentication device when they access AWS websites or services. AWS Best Practices recommend that you enable MFA for privileged IAM users. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': +* '''Datamodel''': +* '''ATT&CK''': * '''Last Updated''': 2018-05-17
====Search==== -`cloudtrail` userIdentity.sessionContext.attributes.mfaAuthenticated=false +`cloudtrail` userIdentity.sessionContext.attributes.mfaAuthenticated=false | search NOT [ -| inputlookup aws_service_accounts -| fields identity +| inputlookup aws_service_accounts +| fields identity | rename identity as user] -| stats count min(_time) as firstTime max(_time) as lastTime values(eventName) as eventName by userIdentity.arn userIdentity.type user -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| stats count min(_time) as firstTime max(_time) as lastTime values(eventName) as eventName by userIdentity.arn userIdentity.type user +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `detect_api_activity_from_users_without_mfa_filter` ====Associated Analytic Story==== @@ -6829,6 +7062,18 @@ Detailed documentation on how to create a new field within Incident Review may b ====Required field==== +* _time + +* userIdentity.sessionContext.attributes.mfaAuthenticated + +* eventName + +* userIdentity.arn + +* userIdentity.type + +* user + @@ -6854,7 +7099,7 @@ Many service accounts configured within an AWS infrastructure do not have multi This search looks for successful CloudTrail activity by user accounts that are not listed in the identity table or `aws_service_accounts.csv`. It returns event names and count, as well as the first and last time a specific user or service is detected, grouped by users. Deprecated because managing this list can be quite hard. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1078.004/ T1078.004] * '''Last Updated''': 2020-07-21 @@ -6862,18 +7107,18 @@ This search looks for successful CloudTrail activity by user accounts that are n
====Search==== -`cloudtrail` errorCode=success -| rename userName as identity +`cloudtrail` errorCode=success +| rename userName as identity | search NOT [ -| inputlookup identity_lookup_expanded -| fields identity] +| inputlookup identity_lookup_expanded +| fields identity] | search NOT [ -| inputlookup aws_service_accounts -| fields identity] -| rename identity as user -| stats count min(_time) as firstTime max(_time) as lastTime values(eventName) as eventName by user -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| inputlookup aws_service_accounts +| fields identity] +| rename identity as user +| stats count min(_time) as firstTime max(_time) as lastTime values(eventName) as eventName by user +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `detect_aws_api_activities_from_unapproved_accounts_filter` ====Associated Analytic Story==== @@ -6892,6 +7137,16 @@ Detailed documentation on how to create a new field within Incident Review may b ====Required field==== +* _time + +* errorCode + +* userName + +* eventName + +* user + ====ATT&CK==== @@ -6939,21 +7194,21 @@ This search looks for DNS requests for phishing domains that are leveraging Evil ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(DNS.answer) as answer from datamodel=Network_Resolution.DNS by DNS.dest DNS.src DNS.query host +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(DNS.answer) as answer from datamodel=Network_Resolution.DNS by DNS.dest DNS.src DNS.query host | `drop_dm_object_name(DNS)` | rex field=query ".*?(?[^./:]+\.(\S{2,3} -|\S{2,3}.\S{2,3}))$" +|\S{2,3}.\S{2,3}))$" | stats count values(query) as query by domain dest src answer -| search `evilginx_phishlets_amazon` OR `evilginx_phishlets_facebook` OR `evilginx_phishlets_github` OR `evilginx_phishlets_0365` OR `evilginx_phishlets_outlook` OR `evilginx_phishlets_aws` OR `evilginx_phishlets_google` -| search NOT [ inputlookup legit_domains.csv +| search `evilginx_phishlets_amazon` OR `evilginx_phishlets_facebook` OR `evilginx_phishlets_github` OR `evilginx_phishlets_0365` OR `evilginx_phishlets_outlook` OR `evilginx_phishlets_aws` OR `evilginx_phishlets_google` +| search NOT [ inputlookup legit_domains.csv | fields domain] | join domain type=outer [ -| tstats count `security_content_summariesonly` values(Web.url) as url from datamodel=Web.Web by Web.dest Web.site -| rename "Web.*" as * +| tstats count `security_content_summariesonly` values(Web.url) as url from datamodel=Web.Web by Web.dest Web.site +| rename "Web.*" as * | rex field=site ".*?(?[^./:]+\.(\S{2,3} -|\S{2,3}.\S{2,3}))$" -| table dest domain url] -| table count src dest query answer domain url +|\S{2,3}.\S{2,3}))$" +| table dest domain url] +| table count src dest query answer domain url | `detect_dns_requests_to_phishing_sites_leveraging_evilginx2_filter` ====Associated Analytic Story==== @@ -6970,6 +7225,18 @@ If Splunk>Phantom is also configured in your environment, a Playbook called `Let ====Required field==== +* _time + +* DNS.answer + +* DNS.dest + +* DNS.src + +* DNS.query + +* host + ====ATT&CK==== @@ -7019,14 +7286,14 @@ This search is used to detect attempts to use DNS tunneling, by calculating the ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Network_Resolution where DNS.message_type=response AND DNS.record_type=TXT by DNS.src DNS.dest DNS.answer DNS.record_type -| `drop_dm_object_name("DNS")` -| eval anslen=len(answer) -| search anslen>100 -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| rename src as "Source IP", dest as "Destination IP", answer as "DNS Answer" anslen as "Answer Length" record_type as "DNS Record Type" firstTime as "First Time" lastTime as "Last Time" count as Count -| table "Source IP" "Destination IP" "DNS Answer" "DNS Record Type" "Answer Length" Count "First Time" "Last Time" +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Network_Resolution where DNS.message_type=response AND DNS.record_type=TXT by DNS.src DNS.dest DNS.answer DNS.record_type +| `drop_dm_object_name("DNS")` +| eval anslen=len(answer) +| search anslen>100 +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| rename src as "Source IP", dest as "Destination IP", answer as "DNS Answer" anslen as "Answer Length" record_type as "DNS Record Type" firstTime as "First Time" lastTime as "Last Time" count as Count +| table "Source IP" "Destination IP" "DNS Answer" "DNS Record Type" "Answer Length" Count "First Time" "Last Time" | `detect_long_dns_txt_record_response_filter` ====Associated Analytic Story==== @@ -7041,6 +7308,18 @@ To successfully implement this search you need to ingest data from your DNS logs ====Required field==== +* _time + +* DNS.message_type + +* DNS.record_type + +* DNS.src + +* DNS.dest + +* DNS.answer + ====ATT&CK==== @@ -7075,81 +7354,11 @@ It's possible that legitimate TXT record responses can be long enough to trigger ---- -===Detect mimikatz using loaded images=== -This search looks for reading loaded Images unique to credential dumping with Mimikatz. Deprecated because mimikatz libraries changed and very noisy sysmon Event Code. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003.001/ T1003.001] -* '''Last Updated''': 2019-12-03 - -
-
- -====Search==== -`sysmon` EventCode=7 -| stats values(ImageLoaded) as ImageLoaded values(ProcessId) as ProcessId by Computer, Image -| search ImageLoaded=*WinSCard.dll ImageLoaded=*cryptdll.dll ImageLoaded=*hid.dll ImageLoaded=*samlib.dll ImageLoaded=*vaultcli.dll -| rename Computer as dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `detect_mimikatz_using_loaded_images_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] - -* [[Documentation:ESSOC:stories:UseCase#Detect_Zerologon_Attack|Detect Zerologon Attack]] - -* [[Documentation:ESSOC:stories:UseCase#Cloud_Federated_Credential_Abuse|Cloud Federated Credential Abuse]] - - -====How To Implement==== -This search needs Sysmon Logs and a sysmon configuration, which includes EventCode 7 with powershell.exe. This search uses an input macro named `sysmon`. We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Windows Sysmon logs. Replace the macro definition with configurations for your Splunk environment. The search also uses a post-filter macro designed to filter out known false positives. - -====Required field==== - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1003.001 -| LSASS Memory -| Credential Access -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -Other tools can import the same DLLs. These tools should be part of a whitelist. - -====Reference==== - -* https://cyberwardog.blogspot.com/2017/03/chronicles-of-threat-hunter-hunting-for.html - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - ===Detect mimikatz via powershell and eventcode 4703=== This search looks for PowerShell requesting privileges consistent with credential dumping. Deprecated, looks like things changed from a logging perspective. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1003.001/ T1003.001] * '''Last Updated''': 2019-02-27 @@ -7157,14 +7366,14 @@ This search looks for PowerShell requesting privileges consistent with credentia
====Search==== -`wineventlog_security` signature_id=4703 Process_Name=*powershell.exe -| rex field=Message "Enabled Privileges:\s+(?\w+)\s+Disabled Privileges:" -| where privs="SeDebugPrivilege" -| stats count min(_time) as firstTime max(_time) as lastTime by dest, Process_Name, privs, Process_ID, Message -| rename privs as "Enabled Privilege" -| rename Process_Name as process +`wineventlog_security` signature_id=4703 Process_Name=*powershell.exe +| rex field=Message "Enabled Privileges:\s+(?\w+)\s+Disabled Privileges:" +| where privs="SeDebugPrivilege" +| stats count min(_time) as firstTime max(_time) as lastTime by dest, Process_Name, privs, Process_ID, Message +| rename privs as "Enabled Privilege" +| rename Process_Name as process | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | `detect_mimikatz_via_powershell_and_eventcode_4703_filter` ====Associated Analytic Story==== @@ -7177,6 +7386,18 @@ You must be ingesting Windows Security logs. You must also enable the account ch ====Required field==== +* _time + +* signature_id + +* Process_Name + +* Message + +* dest + +* Process_ID + ====ATT&CK==== @@ -7215,7 +7436,7 @@ The activity may be legitimate. PowerShell is often used by administrators to pe This search will detect users creating spikes of API activity in your AWS environment. It will also update the cache file that factors in the latest data. This search is deprecated and have been translated to use the latest Change Datamodel. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1078.004/ T1078.004] * '''Last Updated''': 2020-07-21 @@ -7223,25 +7444,25 @@ This search will detect users creating spikes of API activity in your AWS enviro
====Search==== -`cloudtrail` eventType=AwsApiCall [search `cloudtrail` eventType=AwsApiCall -| spath output=arn path=userIdentity.arn -| stats count as apiCalls by arn -| inputlookup api_call_by_user_baseline append=t -| fields - latestCount -| stats values(*) as * by arn -| rename apiCalls as latestCount -| eval newAvgApiCalls=avgApiCalls + (latestCount-avgApiCalls)/720 -| eval newStdevApiCalls=sqrt(((pow(stdevApiCalls, 2)*719 + (latestCount-newAvgApiCalls)*(latestCount-avgApiCalls))/720)) -| eval avgApiCalls=coalesce(newAvgApiCalls, avgApiCalls), stdevApiCalls=coalesce(newStdevApiCalls, stdevApiCalls), numDataPoints=if(isnull(latestCount), numDataPoints, numDataPoints+1) -| table arn, latestCount, numDataPoints, avgApiCalls, stdevApiCalls -| outputlookup api_call_by_user_baseline -| eval dataPointThreshold = 15, deviationThreshold = 3 -| eval isSpike=if((latestCount > avgApiCalls+deviationThreshold*stdevApiCalls) AND numDataPoints > dataPointThreshold, 1, 0) -| where isSpike=1 -| rename arn as userIdentity.arn -| table userIdentity.arn] -| spath output=user userIdentity.arn -| stats values(eventName) as eventName, count as numberOfApiCalls, dc(eventName) as uniqueApisCalled by user +`cloudtrail` eventType=AwsApiCall [search `cloudtrail` eventType=AwsApiCall +| spath output=arn path=userIdentity.arn +| stats count as apiCalls by arn +| inputlookup api_call_by_user_baseline append=t +| fields - latestCount +| stats values(*) as * by arn +| rename apiCalls as latestCount +| eval newAvgApiCalls=avgApiCalls + (latestCount-avgApiCalls)/720 +| eval newStdevApiCalls=sqrt(((pow(stdevApiCalls, 2)*719 + (latestCount-newAvgApiCalls)*(latestCount-avgApiCalls))/720)) +| eval avgApiCalls=coalesce(newAvgApiCalls, avgApiCalls), stdevApiCalls=coalesce(newStdevApiCalls, stdevApiCalls), numDataPoints=if(isnull(latestCount), numDataPoints, numDataPoints+1) +| table arn, latestCount, numDataPoints, avgApiCalls, stdevApiCalls +| outputlookup api_call_by_user_baseline +| eval dataPointThreshold = 15, deviationThreshold = 3 +| eval isSpike=if((latestCount > avgApiCalls+deviationThreshold*stdevApiCalls) AND numDataPoints > dataPointThreshold, 1, 0) +| where isSpike=1 +| rename arn as userIdentity.arn +| table userIdentity.arn] +| spath output=user userIdentity.arn +| stats values(eventName) as eventName, count as numberOfApiCalls, dc(eventName) as uniqueApisCalled by user | `detect_spike_in_aws_api_activity_filter` ====Associated Analytic Story==== @@ -7260,6 +7481,12 @@ Detailed documentation on how to create a new field within Incident Review may b ====Required field==== +* _time + +* eventType + +* userIdentity.arn + ====ATT&CK==== @@ -7298,7 +7525,7 @@ Detailed documentation on how to create a new field within Incident Review may b This search will detect users creating spikes in API activity related to network access-control lists (ACLs)in your AWS environment. This search is deprecated and have been translated to use the latest Change Datamodel. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1562.007/ T1562.007] * '''Last Updated''': 2018-05-21 @@ -7306,25 +7533,25 @@ This search will detect users creating spikes in API activity related to network
====Search==== -`cloudtrail` `network_acl_events` [search `cloudtrail` `network_acl_events` -| spath output=arn path=userIdentity.arn -| stats count as apiCalls by arn -| inputlookup network_acl_activity_baseline append=t -| fields - latestCount -| stats values(*) as * by arn -| rename apiCalls as latestCount -| eval newAvgApiCalls=avgApiCalls + (latestCount-avgApiCalls)/720 -| eval newStdevApiCalls=sqrt(((pow(stdevApiCalls, 2)*719 + (latestCount-newAvgApiCalls)*(latestCount-avgApiCalls))/720)) -| eval avgApiCalls=coalesce(newAvgApiCalls, avgApiCalls), stdevApiCalls=coalesce(newStdevApiCalls, stdevApiCalls), numDataPoints=if(isnull(latestCount), numDataPoints, numDataPoints+1) -| table arn, latestCount, numDataPoints, avgApiCalls, stdevApiCalls -| outputlookup network_acl_activity_baseline -| eval dataPointThreshold = 15, deviationThreshold = 3 -| eval isSpike=if((latestCount > avgApiCalls+deviationThreshold*stdevApiCalls) AND numDataPoints > dataPointThreshold, 1, 0) -| where isSpike=1 -| rename arn as userIdentity.arn -| table userIdentity.arn] -| spath output=user userIdentity.arn -| stats values(eventName) as eventNames, count as numberOfApiCalls, dc(eventName) as uniqueApisCalled by user +`cloudtrail` `network_acl_events` [search `cloudtrail` `network_acl_events` +| spath output=arn path=userIdentity.arn +| stats count as apiCalls by arn +| inputlookup network_acl_activity_baseline append=t +| fields - latestCount +| stats values(*) as * by arn +| rename apiCalls as latestCount +| eval newAvgApiCalls=avgApiCalls + (latestCount-avgApiCalls)/720 +| eval newStdevApiCalls=sqrt(((pow(stdevApiCalls, 2)*719 + (latestCount-newAvgApiCalls)*(latestCount-avgApiCalls))/720)) +| eval avgApiCalls=coalesce(newAvgApiCalls, avgApiCalls), stdevApiCalls=coalesce(newStdevApiCalls, stdevApiCalls), numDataPoints=if(isnull(latestCount), numDataPoints, numDataPoints+1) +| table arn, latestCount, numDataPoints, avgApiCalls, stdevApiCalls +| outputlookup network_acl_activity_baseline +| eval dataPointThreshold = 15, deviationThreshold = 3 +| eval isSpike=if((latestCount > avgApiCalls+deviationThreshold*stdevApiCalls) AND numDataPoints > dataPointThreshold, 1, 0) +| where isSpike=1 +| rename arn as userIdentity.arn +| table userIdentity.arn] +| spath output=user userIdentity.arn +| stats values(eventName) as eventNames, count as numberOfApiCalls, dc(eventName) as uniqueApisCalled by user | `detect_spike_in_network_acl_activity_filter` ====Associated Analytic Story==== @@ -7337,6 +7564,10 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- ====Required field==== +* _time + +* userIdentity.arn + ====ATT&CK==== @@ -7375,7 +7606,7 @@ The false-positive rate may vary based on the values of`dataPointThreshold` and This search will detect users creating spikes in API activity related to security groups in your AWS environment. It will also update the cache file that factors in the latest data. This search is deprecated and have been translated to use the latest Change Datamodel. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1078.004/ T1078.004] * '''Last Updated''': 2018-04-18 @@ -7383,25 +7614,25 @@ This search will detect users creating spikes in API activity related to securit
====Search==== -`cloudtrail` `security_group_api_calls` [search `cloudtrail` `security_group_api_calls` -| spath output=arn path=userIdentity.arn -| stats count as apiCalls by arn -| inputlookup security_group_activity_baseline append=t -| fields - latestCount -| stats values(*) as * by arn -| rename apiCalls as latestCount -| eval newAvgApiCalls=avgApiCalls + (latestCount-avgApiCalls)/720 -| eval newStdevApiCalls=sqrt(((pow(stdevApiCalls, 2)*719 + (latestCount-newAvgApiCalls)*(latestCount-avgApiCalls))/720)) -| eval avgApiCalls=coalesce(newAvgApiCalls, avgApiCalls), stdevApiCalls=coalesce(newStdevApiCalls, stdevApiCalls), numDataPoints=if(isnull(latestCount), numDataPoints, numDataPoints+1) -| table arn, latestCount, numDataPoints, avgApiCalls, stdevApiCalls -| outputlookup security_group_activity_baseline -| eval dataPointThreshold = 15, deviationThreshold = 3 -| eval isSpike=if((latestCount > avgApiCalls+deviationThreshold*stdevApiCalls) AND numDataPoints > dataPointThreshold, 1, 0) -| where isSpike=1 -| rename arn as userIdentity.arn -| table userIdentity.arn] -| spath output=user userIdentity.arn -| stats values(eventName) as eventNames, count as numberOfApiCalls, dc(eventName) as uniqueApisCalled by user +`cloudtrail` `security_group_api_calls` [search `cloudtrail` `security_group_api_calls` +| spath output=arn path=userIdentity.arn +| stats count as apiCalls by arn +| inputlookup security_group_activity_baseline append=t +| fields - latestCount +| stats values(*) as * by arn +| rename apiCalls as latestCount +| eval newAvgApiCalls=avgApiCalls + (latestCount-avgApiCalls)/720 +| eval newStdevApiCalls=sqrt(((pow(stdevApiCalls, 2)*719 + (latestCount-newAvgApiCalls)*(latestCount-avgApiCalls))/720)) +| eval avgApiCalls=coalesce(newAvgApiCalls, avgApiCalls), stdevApiCalls=coalesce(newStdevApiCalls, stdevApiCalls), numDataPoints=if(isnull(latestCount), numDataPoints, numDataPoints+1) +| table arn, latestCount, numDataPoints, avgApiCalls, stdevApiCalls +| outputlookup security_group_activity_baseline +| eval dataPointThreshold = 15, deviationThreshold = 3 +| eval isSpike=if((latestCount > avgApiCalls+deviationThreshold*stdevApiCalls) AND numDataPoints > dataPointThreshold, 1, 0) +| where isSpike=1 +| rename arn as userIdentity.arn +| table userIdentity.arn] +| spath output=user userIdentity.arn +| stats values(eventName) as eventNames, count as numberOfApiCalls, dc(eventName) as uniqueApisCalled by user | `detect_spike_in_security_group_activity_filter` ====Associated Analytic Story==== @@ -7414,6 +7645,10 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- ====Required field==== +* _time + +* serIdentity.arn + ====ATT&CK==== @@ -7453,7 +7688,7 @@ The search is used to detect hosts that generate Windows Event ID 4663 for succe * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Change_Analysis -* '''ATT&CK''': +* '''ATT&CK''': * '''Last Updated''': 2017-11-27
@@ -7461,10 +7696,10 @@ The search is used to detect hosts that generate Windows Event ID 4663 for succe ====Search==== -| tstats `security_content_summariesonly` count earliest(_time) AS earliest latest(_time) AS latest from datamodel=Change_Analysis where (nodename = All_Changes) All_Changes.result="Removable Storage device" (All_Changes.result_id=4663 OR All_Changes.result_id=4656) (All_Changes.src_priority=high) by All_Changes.dest +| tstats `security_content_summariesonly` count earliest(_time) AS earliest latest(_time) AS latest from datamodel=Change_Analysis where (nodename = All_Changes) All_Changes.result="Removable Storage device" (All_Changes.result_id=4663 OR All_Changes.result_id=4656) (All_Changes.src_priority=high) by All_Changes.dest | `drop_dm_object_name("All_Changes")` | `security_content_ctime(earliest)` -| `security_content_ctime(latest)` +| `security_content_ctime(latest)` | `detect_usb_device_insertion_filter` ====Associated Analytic Story==== @@ -7477,6 +7712,16 @@ To successfully implement this search, you must ingest Windows Security Event lo ====Required field==== +* _time + +* All_Changes.result + +* All_Changes.result_id + +* All_Changes.src_priority + +* All_Changes.dest + @@ -7506,7 +7751,7 @@ Legitimate USB activity will also be detected. Please verify and investigate as This search detects new API calls that have either never been seen before or that have not been seen in the previous hour, where the identity type is `AssumedRole`. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1078.004/ T1078.004] * '''Last Updated''': 2018-04-16 @@ -7514,20 +7759,20 @@ This search detects new API calls that have either never been seen before or tha
====Search==== -`cloudtrail` eventType=AwsApiCall errorCode=success userIdentity.type=AssumedRole [search `cloudtrail` eventType=AwsApiCall errorCode=success userIdentity.type=AssumedRole -| stats earliest(_time) as earliest latest(_time) as latest by userName eventName -| inputlookup append=t previously_seen_api_calls_from_user_roles -| stats min(earliest) as earliest, max(latest) as latest by userName eventName +`cloudtrail` eventType=AwsApiCall errorCode=success userIdentity.type=AssumedRole [search `cloudtrail` eventType=AwsApiCall errorCode=success userIdentity.type=AssumedRole +| stats earliest(_time) as earliest latest(_time) as latest by userName eventName +| inputlookup append=t previously_seen_api_calls_from_user_roles +| stats min(earliest) as earliest, max(latest) as latest by userName eventName | outputlookup previously_seen_api_calls_from_user_roles -| eval newApiCallfromUserRole=if(earliest>=relative_time(now(), "-70m@m"), 1, 0) -| where newApiCallfromUserRole=1 -| `security_content_ctime(earliest)` -| `security_content_ctime(latest)` -| table eventName userName] +| eval newApiCallfromUserRole=if(earliest>=relative_time(now(), "-70m@m"), 1, 0) +| where newApiCallfromUserRole=1 +| `security_content_ctime(earliest)` +| `security_content_ctime(latest)` +| table eventName userName] |rename userName as user -| stats values(eventName) earliest(_time) as earliest latest(_time) as latest by user -| `security_content_ctime(earliest)` -| `security_content_ctime(latest)` +| stats values(eventName) earliest(_time) as earliest latest(_time) as latest by user +| `security_content_ctime(earliest)` +| `security_content_ctime(latest)` | `detect_new_api_calls_from_user_roles_filter` ====Associated Analytic Story==== @@ -7540,6 +7785,18 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- ====Required field==== +* _time + +* eventType + +* errorCode + +* userIdentity.type + +* userName + +* eventName + ====ATT&CK==== @@ -7576,7 +7833,7 @@ It is possible that there are legitimate user roles making new or infrequently u This search looks for CloudTrail events wherein a console login event by a user was recorded within the last hour, then compares the event to a lookup file of previously seen users (by ARN values) who have logged into the console. The alert is fired if the user has logged into the console for the first time within the last hour. Deprecated now this search is updated to use the Authentication datamodel. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1078.004/ T1078.004] * '''Last Updated''': 2020-07-21 @@ -7584,15 +7841,15 @@ This search looks for CloudTrail events wherein a console login event by a user
====Search==== -`cloudtrail` eventName=ConsoleLogin -| rename userIdentity.arn as user -| stats earliest(_time) as firstTime latest(_time) as lastTime by user -| inputlookup append=t previously_seen_users_console_logins_cloudtrail -| stats min(firstTime) as firstTime max(lastTime) as lastTime by user -| eval userStatus=if(firstTime >= relative_time(now(), "-70m@m"), "First Time Logging into AWS Console","Previously Seen User") +`cloudtrail` eventName=ConsoleLogin +| rename userIdentity.arn as user +| stats earliest(_time) as firstTime latest(_time) as lastTime by user +| inputlookup append=t previously_seen_users_console_logins_cloudtrail +| stats min(firstTime) as firstTime max(lastTime) as lastTime by user +| eval userStatus=if(firstTime >= relative_time(now(), "-70m@m"), "First Time Logging into AWS Console","Previously Seen User") | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` -| where userStatus ="First Time Logging into AWS Console" +| where userStatus ="First Time Logging into AWS Console" | `detect_new_user_aws_console_login_filter` ====Associated Analytic Story==== @@ -7605,6 +7862,12 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- ====Required field==== +* _time + +* eventName + +* userIdentity.arn + ====ATT&CK==== @@ -7652,10 +7915,10 @@ This search looks for web connections to dynamic DNS providers. ====Search==== -| tstats `security_content_summariesonly` count values(Web.url) as url min(_time) as firstTime from datamodel=Web where Web.status=200 by Web.src Web.dest Web.status -| `drop_dm_object_name("Web")` -| `security_content_ctime(firstTime)` -| `dynamic_dns_web_traffic` +| tstats `security_content_summariesonly` count values(Web.url) as url min(_time) as firstTime from datamodel=Web where Web.status=200 by Web.src Web.dest Web.status +| `drop_dm_object_name("Web")` +| `security_content_ctime(firstTime)` +| `dynamic_dns_web_traffic` | `detect_web_traffic_to_dynamic_domain_providers_filter` ====Associated Analytic Story==== @@ -7670,6 +7933,16 @@ Detailed documentation on how to create a new field within Incident Review may b ====Required field==== +* _time + +* Web.url + +* Web.status + +* Web.src + +* Web.dest + ====ATT&CK==== @@ -7719,17 +7992,17 @@ This search is used to detect DNS tunneling, by calculating the sum of the lengt ====Search==== -| tstats `security_content_summariesonly` dc("DNS.query") as count from datamodel=Network_Resolution where nodename=DNS "DNS.message_type"="QUERY" NOT (`cim_corporate_web_domain_search("DNS.query")`) NOT "DNS.query"="*.in-addr.arpa" NOT ("DNS.src_category"="svc_infra_dns" OR "DNS.src_category"="svc_infra_webproxy" OR "DNS.src_category"="svc_infra_email*" ) by "DNS.src","DNS.query" -| rename "DNS.src" as src "DNS.query" as message -| eval length=len(message) -| stats sum(length) as length by src -| append [ tstats `security_content_summariesonly` dc("DNS.answer") as count from datamodel=Network_Resolution where nodename=DNS "DNS.message_type"="QUERY" NOT (`cim_corporate_web_domain_search("DNS.query")`) NOT "DNS.query"="*.in-addr.arpa" NOT ("DNS.src_category"="svc_infra_dns" OR "DNS.src_category"="svc_infra_webproxy" OR "DNS.src_category"="svc_infra_email*" ) by "DNS.src","DNS.answer" -| rename "DNS.src" as src "DNS.answer" as message -| eval message=if(message=="unknown","", message) -| eval length=len(message) -| stats sum(length) as length by src ] -| stats sum(length) as length by src -| where length > 10000 +| tstats `security_content_summariesonly` dc("DNS.query") as count from datamodel=Network_Resolution where nodename=DNS "DNS.message_type"="QUERY" NOT (`cim_corporate_web_domain_search("DNS.query")`) NOT "DNS.query"="*.in-addr.arpa" NOT ("DNS.src_category"="svc_infra_dns" OR "DNS.src_category"="svc_infra_webproxy" OR "DNS.src_category"="svc_infra_email*" ) by "DNS.src","DNS.query" +| rename "DNS.src" as src "DNS.query" as message +| eval length=len(message) +| stats sum(length) as length by src +| append [ tstats `security_content_summariesonly` dc("DNS.answer") as count from datamodel=Network_Resolution where nodename=DNS "DNS.message_type"="QUERY" NOT (`cim_corporate_web_domain_search("DNS.query")`) NOT "DNS.query"="*.in-addr.arpa" NOT ("DNS.src_category"="svc_infra_dns" OR "DNS.src_category"="svc_infra_webproxy" OR "DNS.src_category"="svc_infra_email*" ) by "DNS.src","DNS.answer" +| rename "DNS.src" as src "DNS.answer" as message +| eval message=if(message=="unknown","", message) +| eval length=len(message) +| stats sum(length) as length by src ] +| stats sum(length) as length by src +| where length > 10000 | `detection_of_dns_tunnels_filter` ====Associated Analytic Story==== @@ -7746,6 +8019,16 @@ To successfully implement this search, we must ensure that DNS data is being ing ====Required field==== +* _time + +* DNS.query + +* DNS.message_type + +* DNS.src_category + +* DNS.src + ====ATT&CK==== @@ -7786,7 +8069,7 @@ It's possible that normal DNS traffic will exhibit this behavior. If an alert is This search looks for EC2 instances being modified by users who have not previously modified them. This search is deprecated and have been translated to use the latest Change Datamodel. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1078.004/ T1078.004] * '''Last Updated''': 2020-07-21 @@ -7794,21 +8077,21 @@ This search looks for EC2 instances being modified by users who have not previou
====Search==== -`cloudtrail` `ec2_modification_api_calls` [search `cloudtrail` `ec2_modification_api_calls` errorCode=success -| stats earliest(_time) as firstTime latest(_time) as lastTime by userIdentity.arn -| rename userIdentity.arn as arn -| inputlookup append=t previously_seen_ec2_modifications_by_user -| stats min(firstTime) as firstTime, max(lastTime) as lastTime by arn -| outputlookup previously_seen_ec2_modifications_by_user -| eval newUser=if(firstTime >= relative_time(now(), "-70m@m"), 1, 0) -| where newUser=1 -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| rename arn as userIdentity.arn -| table userIdentity.arn] -| spath output=dest responseElements.instancesSet.items{}.instanceId -| spath output=user userIdentity.arn -| table _time, user, dest +`cloudtrail` `ec2_modification_api_calls` [search `cloudtrail` `ec2_modification_api_calls` errorCode=success +| stats earliest(_time) as firstTime latest(_time) as lastTime by userIdentity.arn +| rename userIdentity.arn as arn +| inputlookup append=t previously_seen_ec2_modifications_by_user +| stats min(firstTime) as firstTime, max(lastTime) as lastTime by arn +| outputlookup previously_seen_ec2_modifications_by_user +| eval newUser=if(firstTime >= relative_time(now(), "-70m@m"), 1, 0) +| where newUser=1 +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| rename arn as userIdentity.arn +| table userIdentity.arn] +| spath output=dest responseElements.instancesSet.items{}.instanceId +| spath output=user userIdentity.arn +| table _time, user, dest | `ec2_instance_modified_with_previously_unseen_user_filter` ====Associated Analytic Story==== @@ -7821,6 +8104,12 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- ====Required field==== +* _time + +* errorCode + +* userIdentity.arn + ====ATT&CK==== @@ -7857,7 +8146,7 @@ It's possible that a new user will start to modify EC2 instances when they haven This search looks for CloudTrail events where an instance is started in a particular region in the last one hour and then compares it to a lookup file of previously seen regions where an instance was started * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1535/ T1535] * '''Last Updated''': 2018-02-23 @@ -7865,15 +8154,15 @@ This search looks for CloudTrail events where an instance is started in a partic
====Search==== -`cloudtrail` earliest=-1h StartInstances -| stats earliest(_time) as earliest latest(_time) as latest by awsRegion -| inputlookup append=t previously_seen_aws_regions.csv -| stats min(earliest) as earliest max(latest) as latest by awsRegion -| outputlookup previously_seen_aws_regions.csv -| eval regionStatus=if(earliest >= relative_time(now(),"-1d@d"), "Instance Started in a New Region","Previously Seen Region") -| `security_content_ctime(earliest)` -| `security_content_ctime(latest)` -| where regionStatus="Instance Started in a New Region" +`cloudtrail` earliest=-1h StartInstances +| stats earliest(_time) as earliest latest(_time) as latest by awsRegion +| inputlookup append=t previously_seen_aws_regions.csv +| stats min(earliest) as earliest max(latest) as latest by awsRegion +| outputlookup previously_seen_aws_regions.csv +| eval regionStatus=if(earliest >= relative_time(now(),"-1d@d"), "Instance Started in a New Region","Previously Seen Region") +| `security_content_ctime(earliest)` +| `security_content_ctime(latest)` +| where regionStatus="Instance Started in a New Region" | `ec2_instance_started_in_previously_unseen_region_filter` ====Associated Analytic Story==== @@ -7888,6 +8177,10 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- ====Required field==== +* _time + +* awsRegion + ====ATT&CK==== @@ -7926,28 +8219,28 @@ It's possible that a user has unknowingly started an instance in a new region. P This search looks for EC2 instances being created with previously unseen AMIs. This search is deprecated and have been translated to use the latest Change Datamodel. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': +* '''Datamodel''': +* '''ATT&CK''': * '''Last Updated''': 2018-03-12
====Search==== -`cloudtrail` eventName=RunInstances [search `cloudtrail` eventName=RunInstances errorCode=success -| stats earliest(_time) as firstTime latest(_time) as lastTime by requestParameters.instancesSet.items{}.imageId -| rename requestParameters.instancesSet.items{}.imageId as amiID -| inputlookup append=t previously_seen_ec2_amis.csv -| stats min(firstTime) as firstTime max(lastTime) as lastTime by amiID -| outputlookup previously_seen_ec2_amis.csv -| eval newAMI=if(firstTime >= relative_time(now(), "-70m@m"), 1, 0) +`cloudtrail` eventName=RunInstances [search `cloudtrail` eventName=RunInstances errorCode=success +| stats earliest(_time) as firstTime latest(_time) as lastTime by requestParameters.instancesSet.items{}.imageId +| rename requestParameters.instancesSet.items{}.imageId as amiID +| inputlookup append=t previously_seen_ec2_amis.csv +| stats min(firstTime) as firstTime max(lastTime) as lastTime by amiID +| outputlookup previously_seen_ec2_amis.csv +| eval newAMI=if(firstTime >= relative_time(now(), "-70m@m"), 1, 0) | `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| where newAMI=1 -| rename amiID as requestParameters.instancesSet.items{}.imageId -| table requestParameters.instancesSet.items{}.imageId] -| rename requestParameters.instanceType as instanceType, responseElements.instancesSet.items{}.instanceId as dest, userIdentity.arn as arn, requestParameters.instancesSet.items{}.imageId as amiID -| table firstTime, lastTime, arn, amiID, dest, instanceType +|`security_content_ctime(lastTime)` +| where newAMI=1 +| rename amiID as requestParameters.instancesSet.items{}.imageId +| table requestParameters.instancesSet.items{}.imageId] +| rename requestParameters.instanceType as instanceType, responseElements.instancesSet.items{}.instanceId as dest, userIdentity.arn as arn, requestParameters.instancesSet.items{}.imageId as amiID +| table firstTime, lastTime, arn, amiID, dest, instanceType | `ec2_instance_started_with_previously_unseen_ami_filter` ====Associated Analytic Story==== @@ -7960,6 +8253,14 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- ====Required field==== +* _time + +* eventName + +* errorCode + +* requestParameters.instancesSet.items{}.imageId + @@ -7985,30 +8286,30 @@ After a new AMI is created, the first systems created with that AMI will cause t This search looks for EC2 instances being created with previously unseen instance types. This search is deprecated and have been translated to use the latest Change Datamodel. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': +* '''Datamodel''': +* '''ATT&CK''': * '''Last Updated''': 2020-02-07
====Search==== -`cloudtrail` eventName=RunInstances [search `cloudtrail` eventName=RunInstances errorCode=success -| fillnull value="m1.small" requestParameters.instanceType -| stats earliest(_time) as earliest latest(_time) as latest by requestParameters.instanceType -| rename requestParameters.instanceType as instanceType -| inputlookup append=t previously_seen_ec2_instance_types.csv -| stats min(earliest) as earliest max(latest) as latest by instanceType -| outputlookup previously_seen_ec2_instance_types.csv -| eval newType=if(earliest >= relative_time(now(), "-70m@m"), 1, 0) -| `security_content_ctime(earliest)` -| `security_content_ctime(latest)` -| where newType=1 -| rename instanceType as requestParameters.instanceType -| table requestParameters.instanceType] -| spath output=user userIdentity.arn -| rename requestParameters.instanceType as instanceType, responseElements.instancesSet.items{}.instanceId as dest -| table _time, user, dest, instanceType +`cloudtrail` eventName=RunInstances [search `cloudtrail` eventName=RunInstances errorCode=success +| fillnull value="m1.small" requestParameters.instanceType +| stats earliest(_time) as earliest latest(_time) as latest by requestParameters.instanceType +| rename requestParameters.instanceType as instanceType +| inputlookup append=t previously_seen_ec2_instance_types.csv +| stats min(earliest) as earliest max(latest) as latest by instanceType +| outputlookup previously_seen_ec2_instance_types.csv +| eval newType=if(earliest >= relative_time(now(), "-70m@m"), 1, 0) +| `security_content_ctime(earliest)` +| `security_content_ctime(latest)` +| where newType=1 +| rename instanceType as requestParameters.instanceType +| table requestParameters.instanceType] +| spath output=user userIdentity.arn +| rename requestParameters.instanceType as instanceType, responseElements.instancesSet.items{}.instanceId as dest +| table _time, user, dest, instanceType | `ec2_instance_started_with_previously_unseen_instance_type_filter` ====Associated Analytic Story==== @@ -8021,6 +8322,14 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- ====Required field==== +* _time + +* eventName + +* errorCode + +* requestParameters.instanceType + @@ -8046,7 +8355,7 @@ It is possible that an admin will create a new system using a new instance type This search looks for EC2 instances being created by users who have not created them before. This search is deprecated and have been translated to use the latest Change Datamodel. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1078.004/ T1078.004] * '''Last Updated''': 2020-07-21 @@ -8054,20 +8363,20 @@ This search looks for EC2 instances being created by users who have not created
====Search==== -`cloudtrail` eventName=RunInstances [search `cloudtrail` eventName=RunInstances errorCode=success -| stats earliest(_time) as firstTime latest(_time) as lastTime by userIdentity.arn -| rename userIdentity.arn as arn -| inputlookup append=t previously_seen_ec2_launches_by_user.csv -| stats min(firstTime) as firstTime, max(lastTime) as lastTime by arn -| outputlookup previously_seen_ec2_launches_by_user.csv -| eval newUser=if(firstTime >= relative_time(now(), "-70m@m"), 1, 0) -| where newUser=1 -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| rename arn as userIdentity.arn -| table userIdentity.arn] -| rename requestParameters.instanceType as instanceType, responseElements.instancesSet.items{}.instanceId as dest, userIdentity.arn as user -| table _time, user, dest, instanceType +`cloudtrail` eventName=RunInstances [search `cloudtrail` eventName=RunInstances errorCode=success +| stats earliest(_time) as firstTime latest(_time) as lastTime by userIdentity.arn +| rename userIdentity.arn as arn +| inputlookup append=t previously_seen_ec2_launches_by_user.csv +| stats min(firstTime) as firstTime, max(lastTime) as lastTime by arn +| outputlookup previously_seen_ec2_launches_by_user.csv +| eval newUser=if(firstTime >= relative_time(now(), "-70m@m"), 1, 0) +| where newUser=1 +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| rename arn as userIdentity.arn +| table userIdentity.arn] +| rename requestParameters.instanceType as instanceType, responseElements.instancesSet.items{}.instanceId as dest, userIdentity.arn as user +| table _time, user, dest, instanceType | `ec2_instance_started_with_previously_unseen_user_filter` ====Associated Analytic Story==== @@ -8082,6 +8391,14 @@ You must install the AWS App for Splunk (version 5.1.0 or later) and Splunk Add- ====Required field==== +* _time + +* eventName + +* errorCode + +* userIdentity.arn + ====ATT&CK==== @@ -8127,10 +8444,10 @@ This search looks for processes launched from files with at least five spaces in ====Search==== -| tstats `security_content_summariesonly` count values(Processes.process_path) as process_path min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process = "* .*" by Processes.dest Processes.user Processes.process Processes.process_name +| tstats `security_content_summariesonly` count values(Processes.process_path) as process_path min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process = "* .*" by Processes.dest Processes.user Processes.process Processes.process_name | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `drop_dm_object_name(Processes)` +| `security_content_ctime(lastTime)` +| `drop_dm_object_name(Processes)` | `execution_of_file_with_spaces_before_extension_filter` ====Associated Analytic Story==== @@ -8143,6 +8460,18 @@ To successfully implement this search, you must be ingesting data that records p ====Required field==== +* _time + +* Processes.process_path + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.process_name + ====ATT&CK==== @@ -8181,21 +8510,21 @@ None identified. This search returns a list of hosts that have not successfully completed a backup in over a week. Deprecated because it's a infrastructure monitoring. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': +* '''Datamodel''': +* '''ATT&CK''': * '''Last Updated''': 2017-09-12
====Search==== -`netbackup` MESSAGE="Disk/Partition backup completed successfully." -| stats latest(_time) as latestTime by COMPUTERNAME -| `security_content_ctime(latestTime)` -| rename COMPUTERNAME as dest -| eval isOutlier=if(latestTime <= relative_time(now(), "-7d@d"), 1, 0) -| search isOutlier=1 -| table latestTime, dest +`netbackup` MESSAGE="Disk/Partition backup completed successfully." +| stats latest(_time) as latestTime by COMPUTERNAME +| `security_content_ctime(latestTime)` +| rename COMPUTERNAME as dest +| eval isOutlier=if(latestTime <= relative_time(now(), "-7d@d"), 1, 0) +| search isOutlier=1 +| table latestTime, dest | `extended_period_without_successful_netbackup_backups_filter` ====Associated Analytic Story==== @@ -8208,6 +8537,12 @@ To successfully implement this search you need to first obtain data from your ba ====Required field==== +* _time + +* MESSAGE + +* COMPUTERNAME + @@ -8244,19 +8579,19 @@ This search looks for command-line arguments that use a `/c` parameter to execut | tstats `security_content_summariesonly` min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = cmd.exe Processes.process = "* /c *" by Processes.process Processes.process_name Processes.parent_process_name Processes.dest | `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | search [ -| tstats `security_content_summariesonly` earliest(_time) as firstTime latest(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = cmd.exe Processes.process = "* /c *" by Processes.process -| `drop_dm_object_name(Processes)` -| inputlookup append=t previously_seen_cmd_line_arguments -| stats min(firstTime) as firstTime, max(lastTime) as lastTime by process -| outputlookup previously_seen_cmd_line_arguments -| eval newCmdLineArgument=if(firstTime >= relative_time(now(), "-70m@m"), 1, 0) -| where newCmdLineArgument=1 -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| table process] +| tstats `security_content_summariesonly` earliest(_time) as firstTime latest(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = cmd.exe Processes.process = "* /c *" by Processes.process +| `drop_dm_object_name(Processes)` +| inputlookup append=t previously_seen_cmd_line_arguments +| stats min(firstTime) as firstTime, max(lastTime) as lastTime by process +| outputlookup previously_seen_cmd_line_arguments +| eval newCmdLineArgument=if(firstTime >= relative_time(now(), "-70m@m"), 1, 0) +| where newCmdLineArgument=1 +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| table process] | `first_time_seen_command_line_argument_filter` ====Associated Analytic Story==== @@ -8277,6 +8612,16 @@ You must be ingesting data that records process activity from your hosts to popu ====Required field==== +* _time + +* Processes.process_name + +* Processes.process + +* Processes.parent_process_name + +* Processes.dest + ====ATT&CK==== @@ -8317,11 +8662,171 @@ Legitimate programs can also use command-line arguments to execute. Please verif ---- +===Gcp detect accounts with high risk roles by project=== +This search provides detection of accounts with high risk roles by projects. Compromised accounts with high risk roles can move laterally or even scalate privileges at different projects depending on organization schema. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078] +* '''Last Updated''': 2020-10-09 + +
+
+ +====Search==== +`google_gcp_pubsub_message` data.protoPayload.request.policy.bindings{}.role=roles/owner OR roles/editor OR roles/iam.serviceAccountUser OR roles/iam.serviceAccountAdmin OR roles/iam.serviceAccountTokenCreator OR roles/dataflow.developer OR roles/dataflow.admin OR roles/composer.admin OR roles/dataproc.admin OR roles/dataproc.editor +| table data.resource.type data.protoPayload.authenticationInfo.principalEmail data.protoPayload.authorizationInfo{}.permission data.protoPayload.authorizationInfo{}.resource data.protoPayload.response.bindings{}.role data.protoPayload.response.bindings{}.members{} +| `gcp_detect_accounts_with_high_risk_roles_by_project_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#GCP_Cross_Account_Activity|GCP Cross Account Activity]] + + +====How To Implement==== +You must install splunk GCP add-on. This search works with gcp:pubsub:message logs + +====Required field==== + +* _time + +* data.protoPayload.request.policy.bindings{}.role + +* data.resource.type data.protoPayload.authenticationInfo.principalEmail + +* data.protoPayload.authorizationInfo{}.permission + +* data.protoPayload.authorizationInfo{}.resource + +* data.protoPayload.response.bindings{}.role + +* data.protoPayload.response.bindings{}.members{} + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1078 +| Valid Accounts +| Defense Evasion, Initial Access, Persistence, Privilege Escalation +|} + + +====Kill Chain Phase==== + +* Lateral Movement + + +====Known False Positives==== +Accounts with high risk roles should be reduced to the minimum number needed, however specific tasks and setups may be simply expected behavior within organization + +====Reference==== + +* https://github.com/dxa4481/gcploit + +* https://www.youtube.com/watch?v=Ml09R38jpok + +* https://cloud.google.com/iam/docs/understanding-roles + + +====Test Dataset==== + + +''version'': 1 +
+
+ +---- + +===Gcp detect high risk permissions by resource and account=== +This search provides detection of high risk permissions by resource and accounts. These are permissions that can allow attackers with compromised accounts to move laterally and escalate privileges. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078] +* '''Last Updated''': 2020-10-09 + +
+
+ +====Search==== +`google_gcp_pubsub_message` data.protoPayload.authorizationInfo{}.permission=iam.serviceAccounts.getaccesstoken OR iam.serviceAccounts.setIamPolicy OR iam.serviceAccounts.actas OR dataflow.jobs.create OR composer.environments.create OR dataproc.clusters.create +|table data.protoPayload.requestMetadata.callerIp data.protoPayload.authenticationInfo.principalEmail data.protoPayload.authorizationInfo{}.permission data.protoPayload.response.bindings{}.members{} data.resource.labels.project_id +| `gcp_detect_high_risk_permissions_by_resource_and_account_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#GCP_Cross_Account_Activity|GCP Cross Account Activity]] + + +====How To Implement==== +You must install splunk GCP add-on. This search works with gcp:pubsub:message logs + +====Required field==== + +* _time + +* data.protoPayload.authorizationInfo{}.permission + +* data.protoPayload.requestMetadata.callerIp + +* data.protoPayload.authenticationInfo.principalEmail + +* data.protoPayload.authorizationInfo{}.permission + +* data.protoPayload.response.bindings{}.members{} + +* data.resource.labels.project_id + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1078 +| Valid Accounts +| Defense Evasion, Initial Access, Persistence, Privilege Escalation +|} + + +====Kill Chain Phase==== + +* Lateral Movement + + +====Known False Positives==== +High risk permissions are part of any GCP environment, however it is important to track resource and accounts usage, this search may produce false positives. + +====Reference==== + +* https://github.com/dxa4481/gcploit + +* https://www.youtube.com/watch?v=Ml09R38jpok + +* https://cloud.google.com/iam/docs/permissions-reference + + +====Test Dataset==== + + +''version'': 1 +
+
+ +---- + ===Gcp gcr container uploaded=== This search show information on uploaded containers including source user, account, action, bucket name event name, http user agent, message and destination path. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1525/ T1525] * '''Last Updated''': 2020-02-20 @@ -8330,8 +8835,8 @@ This search show information on uploaded containers including source user, accou ====Search==== -|tstats count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Cloud_Infrastructure.Storage where Storage.event_name=storage.objects.create by Storage.src_user Storage.account Storage.action Storage.bucket_name Storage.event_name Storage.http_user_agent Storage.msg Storage.object_path -| `drop_dm_object_name("Storage")` +|tstats count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Cloud_Infrastructure.Storage where Storage.event_name=storage.objects.create by Storage.src_user Storage.account Storage.action Storage.bucket_name Storage.event_name Storage.http_user_agent Storage.msg Storage.object_path +| `drop_dm_object_name("Storage")` | `gcp_gcr_container_uploaded_filter` ====Associated Analytic Story==== @@ -8344,6 +8849,8 @@ You must install the GCP App for Splunk (version 2.0.0 or later), then configure ====Required field==== +* _time + ====ATT&CK==== @@ -8370,6 +8877,72 @@ Uploading container is a normal behavior from developers or users with access to ====Test Dataset==== +''version'': 1 +
+
+ +---- + +===Gcp kubernetes cluster scan detection=== +This search provides information of unauthenticated requests via user agent, and authentication data against Kubernetes cluster + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1526/ T1526] +* '''Last Updated''': 2020-04-15 + +
+
+ +====Search==== +`google_gcp_pubsub_message` data.protoPayload.requestMetadata.callerIp!=127.0.0.1 data.protoPayload.requestMetadata.callerIp!=::1 "data.labels.authorization.k8s.io/decision"=forbid "data.protoPayload.status.message"=PERMISSION_DENIED data.protoPayload.authenticationInfo.principalEmail="system:anonymous" +| rename data.protoPayload.requestMetadata.callerIp as src_ip +| stats count min(_time) as firstTime max(_time) as lastTime values(data.protoPayload.methodName) as method_name values(data.protoPayload.resourceName) as resource_name values(data.protoPayload.requestMetadata.callerSuppliedUserAgent) as http_user_agent by src_ip data.resource.labels.cluster_name +| rename data.resource.labels.cluster_name as cluster_name +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` +| `gcp_kubernetes_cluster_scan_detection_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Scanning_Activity|Kubernetes Scanning Activity]] + + +====How To Implement==== +You must install the GCP App for Splunk (version 2.0.0 or later), then configure stackdriver and set a Pub/Sub subscription to be imported to Splunk. You must also install Cloud Infrastructure data model.Customize the macro kubernetes_gcp_scan_fingerprint_attack_detection to filter out FPs. + +====Required field==== + +* _time + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1526 +| Cloud Service Discovery +| Discovery +|} + + +====Kill Chain Phase==== + +* Reconnaissance + + +====Known False Positives==== +Not all unauthenticated requests are malicious, but frequency, User Agent and source IPs will provide context. + +====Reference==== + + +====Test Dataset==== + + ''version'': 1
@@ -8380,7 +8953,7 @@ Uploading container is a normal behavior from developers or users with access to This detection search will help profile user accounts in your environment by identifying newly created accounts that have been added to your network in the past week. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1078.002/ T1078.002] * '''Last Updated''': 2017-09-12 @@ -8389,12 +8962,12 @@ This detection search will help profile user accounts in your environment by ide ====Search==== -| from datamodel Identity_Management.All_Identities -| eval empStatus=case((now()-startDate)<604800, "Accounts created in last week") +| from datamodel Identity_Management.All_Identities +| eval empStatus=case((now()-startDate)<604800, "Accounts created in last week") | search empStatus="Accounts created in last week" -| `security_content_ctime(endDate)` +| `security_content_ctime(endDate)` | `security_content_ctime(startDate)` -| table identity empStatus endDate startDate +| table identity empStatus endDate startDate | `identify_new_user_accounts_filter` ====Associated Analytic Story==== @@ -8407,6 +8980,8 @@ To successfully implement this search, you need to be populating the Enterprise ====Required field==== +* _time + ====ATT&CK==== @@ -8433,6 +9008,968 @@ If the Identity_Management data model is not updated regularly, this search coul ====Test Dataset==== +''version'': 1 +
+
+ +---- + +===Kubernetes aws detect rbac authorization by account=== +This search provides information on Kubernetes RBAC authorizations by accounts, this search can be modified by adding top to see both extremes of RBAC by accounts occurrences + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': +* '''ATT&CK''': +* '''Last Updated''': 2020-06-23 + +
+
+ +====Search==== +`aws_cloudwatchlogs_eks` annotations.authorization.k8s.io/reason=* +| table sourceIPs{} user.username userAgent annotations.authorization.k8s.io/reason +| stats count by user.username annotations.authorization.k8s.io/reason +| rare user.username annotations.authorization.k8s.io/reason +|`kubernetes_aws_detect_rbac_authorization_by_account_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Sensitive_Role_Activity|Kubernetes Sensitive Role Activity]] + + +====How To Implement==== +You must install splunk AWS add on and Splunk App for AWS. This search works with cloudwatch logs + +====Required field==== + +* _time + + + + +====Kill Chain Phase==== + +* Lateral Movement + + +====Known False Positives==== +Not all RBAC Authorications are malicious. RBAC authorizations can uncover malicious activity specially if sensitive Roles have been granted. + +====Reference==== + + +====Test Dataset==== + + +''version'': 1 +
+
+ +---- + +===Kubernetes aws detect most active service accounts by pod=== +This search provides information on Kubernetes service accounts,accessing pods by IP address, verb and decision + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': +* '''ATT&CK''': +* '''Last Updated''': 2020-06-23 + +
+
+ +====Search==== +`aws_cloudwatchlogs_eks` user.groups{}=system:serviceaccounts objectRef.resource=pods +| table sourceIPs{} user.username userAgent verb annotations.authorization.k8s.io/decision +| top sourceIPs{} user.username verb annotations.authorization.k8s.io/decision +|`kubernetes_aws_detect_most_active_service_accounts_by_pod_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Sensitive_Role_Activity|Kubernetes Sensitive Role Activity]] + + +====How To Implement==== +You must install splunk AWS add on and Splunk App for AWS. This search works with cloudwatch logs + +====Required field==== + +* _time + + + + +====Kill Chain Phase==== + +* Lateral Movement + + +====Known False Positives==== +Not all service accounts interactions are malicious. Analyst must consider IP, verb and decision context when trying to detect maliciousness. + +====Reference==== + + +====Test Dataset==== + + +''version'': 1 +
+
+ +---- + +===Kubernetes aws detect sensitive role access=== +This search provides information on Kubernetes accounts accessing sensitve objects such as configmpas or secrets + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': +* '''ATT&CK''': +* '''Last Updated''': 2020-06-23 + +
+
+ +====Search==== +`aws_cloudwatchlogs_eks` objectRef.resource=clusterroles OR clusterrolebindings sourceIPs{}!=::1 sourceIPs{}!=127.0.0.1 +| table sourceIPs{} user.username user.groups{} objectRef.namespace requestURI annotations.authorization.k8s.io/reason +| dedup user.username user.groups{} +|`kubernetes_aws_detect_sensitive_role_access_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Sensitive_Role_Activity|Kubernetes Sensitive Role Activity]] + + +====How To Implement==== +You must install splunk AWS add on and Splunk App for AWS. This search works with cloudwatch logs. + +====Required field==== + +* _time + + + + +====Kill Chain Phase==== + +* Lateral Movement + + +====Known False Positives==== +Sensitive role resource access is necessary for cluster operation, however source IP, namespace and user group may indicate possible malicious use. + +====Reference==== + + +====Test Dataset==== + + +''version'': 1 +
+
+ +---- + +===Kubernetes aws detect service accounts forbidden failure access=== +This search provides information on Kubernetes service accounts with failure or forbidden access status, this search can be extended by using top or rare operators to find trends or rarities in failure status, user agents, source IPs and request URI + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': +* '''ATT&CK''': +* '''Last Updated''': 2020-06-23 + +
+
+ +====Search==== +`aws_cloudwatchlogs_eks` user.groups{}=system:serviceaccounts responseStatus.status = Failure +| table sourceIPs{} user.username userAgent verb responseStatus.status requestURI +| `kubernetes_aws_detect_service_accounts_forbidden_failure_access_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Sensitive_Object_Access_Activity|Kubernetes Sensitive Object Access Activity]] + + +====How To Implement==== +You must install splunk AWS add on and Splunk App for AWS. This search works with cloudwatch logs. + +====Required field==== + +* _time + + + + +====Kill Chain Phase==== + +* Lateral Movement + + +====Known False Positives==== +This search can give false positives as there might be inherent issues with authentications and permissions at cluster. + +====Reference==== + + +====Test Dataset==== + + +''version'': 1 +
+
+ +---- + +===Kubernetes azure detect rbac authorization by account=== +This search provides information on Kubernetes RBAC authorizations by accounts, this search can be modified by adding rare or top to see both extremes of RBAC by accounts occurrences + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': +* '''ATT&CK''': +* '''Last Updated''': 2020-05-26 + +
+
+ +====Search==== +`kubernetes_azure` category=kube-audit +| spath input=properties.log +| search annotations.authorization.k8s.io/reason=* +| table sourceIPs{} user.username userAgent annotations.authorization.k8s.io/reason +|stats count by user.username annotations.authorization.k8s.io/reason +| rare user.username annotations.authorization.k8s.io/reason +|`kubernetes_azure_detect_rbac_authorization_by_account_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Sensitive_Role_Activity|Kubernetes Sensitive Role Activity]] + + +====How To Implement==== +You must install the Add-on for Microsoft Cloud Services and Configure Kube-Audit data diagnostics + +====Required field==== + +* _time + + + + +====Kill Chain Phase==== + +* Lateral Movement + + +====Known False Positives==== +Not all RBAC Authorications are malicious. RBAC authorizations can uncover malicious activity specially if sensitive Roles have been granted. + +====Reference==== + + +====Test Dataset==== + + +''version'': 1 +
+
+ +---- + +===Kubernetes azure detect most active service accounts by pod namespace=== +This search provides information on Kubernetes service accounts,accessing pods and namespaces by IP address and verb + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': +* '''ATT&CK''': +* '''Last Updated''': 2020-05-26 + +
+
+ +====Search==== +`kubernetes_azure` category=kube-audit +| spath input=properties.log +| search user.groups{}=system:serviceaccounts* OR user.username=system.anonymous OR annotations.authorization.k8s.io/decision=allow +| table sourceIPs{} user.username userAgent verb responseStatus.reason responseStatus.status properties.pod objectRef.namespace +| top sourceIPs{} user.username verb responseStatus.status properties.pod objectRef.namespace +|`kubernetes_azure_detect_most_active_service_accounts_by_pod_namespace_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Sensitive_Role_Activity|Kubernetes Sensitive Role Activity]] + + +====How To Implement==== +You must install the Add-on for Microsoft Cloud Services and Configure Kube-Audit data diagnostics + +====Required field==== + +* _time + + + + +====Kill Chain Phase==== + +* Lateral Movement + + +====Known False Positives==== +Not all service accounts interactions are malicious. Analyst must consider IP and verb context when trying to detect maliciousness. + +====Reference==== + + +====Test Dataset==== + + +''version'': 1 +
+
+ +---- + +===Kubernetes azure detect sensitive object access=== +This search provides information on Kubernetes accounts accessing sensitve objects such as configmpas or secrets + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': +* '''ATT&CK''': +* '''Last Updated''': 2020-05-20 + +
+
+ +====Search==== +`kubernetes_azure` category=kube-audit +| spath input=properties.log +| search objectRef.resource=secrets OR configmaps user.username=system.anonymous OR annotations.authorization.k8s.io/decision=allow +|table user.username user.groups{} objectRef.resource objectRef.namespace objectRef.name annotations.authorization.k8s.io/reason +|dedup user.username user.groups{} +|`kubernetes_azure_detect_sensitive_object_access_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Sensitive_Object_Access_Activity|Kubernetes Sensitive Object Access Activity]] + + +====How To Implement==== +You must install the Add-on for Microsoft Cloud Services and Configure Kube-Audit data diagnostics + +====Required field==== + +* _time + + + + +====Kill Chain Phase==== + +* Lateral Movement + + +====Known False Positives==== +Sensitive object access is not necessarily malicious but user and object context can provide guidance for detection. + +====Reference==== + + +====Test Dataset==== + + +''version'': 1 +
+
+ +---- + +===Kubernetes azure detect sensitive role access=== +This search provides information on Kubernetes accounts accessing sensitve objects such as configmpas or secrets + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': +* '''ATT&CK''': +* '''Last Updated''': 2020-05-20 + +
+
+ +====Search==== +`kubernetes_azure` category=kube-audit +| spath input=properties.log +| search objectRef.resource=clusterroles OR clusterrolebindings +| table sourceIPs{} user.username user.groups{} objectRef.namespace requestURI annotations.authorization.k8s.io/reason +| dedup user.username user.groups{} +|`kubernetes_azure_detect_sensitive_role_access_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Sensitive_Role_Activity|Kubernetes Sensitive Role Activity]] + + +====How To Implement==== +You must install the Add-on for Microsoft Cloud Services and Configure Kube-Audit data diagnostics + +====Required field==== + +* _time + + + + +====Kill Chain Phase==== + +* Lateral Movement + + +====Known False Positives==== +Sensitive role resource access is necessary for cluster operation, however source IP, namespace and user group may indicate possible malicious use. + +====Reference==== + + +====Test Dataset==== + + +''version'': 1 +
+
+ +---- + +===Kubernetes azure detect service accounts forbidden failure access=== +This search provides information on Kubernetes service accounts with failure or forbidden access status + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': +* '''ATT&CK''': +* '''Last Updated''': 2020-05-20 + +
+
+ +====Search==== +`kubernetes_azure` category=kube-audit +| spath input=properties.log +| search user.groups{}=system:serviceaccounts* responseStatus.reason=Forbidden +| table sourceIPs{} user.username userAgent verb responseStatus.reason responseStatus.status properties.pod objectRef.namespace +|`kubernetes_azure_detect_service_accounts_forbidden_failure_access_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Sensitive_Object_Access_Activity|Kubernetes Sensitive Object Access Activity]] + + +====How To Implement==== +You must install the Add-on for Microsoft Cloud Services and Configure Kube-Audit data diagnostics + +====Required field==== + +* _time + + + + +====Kill Chain Phase==== + +* Lateral Movement + + +====Known False Positives==== +This search can give false positives as there might be inherent issues with authentications and permissions at cluster. + +====Reference==== + + +====Test Dataset==== + + +''version'': 1 +
+
+ +---- + +===Kubernetes azure detect suspicious kubectl calls=== +This search provides information on rare Kubectl calls with IP, verb namespace and object access context + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': +* '''ATT&CK''': +* '''Last Updated''': 2020-05-26 + +
+
+ +====Search==== +`kubernetes_azure` category=kube-audit +| spath input=properties.log +| spath input=responseObject.metadata.annotations.kubectl.kubernetes.io/last-applied-configuration +| search userAgent=kubectl* sourceIPs{}!=127.0.0.1 sourceIPs{}!=::1 +| table sourceIPs{} verb userAgent user.groups{} objectRef.resource objectRef.namespace requestURI +| rare sourceIPs{} verb userAgent user.groups{} objectRef.resource objectRef.namespace requestURI +|`kubernetes_azure_detect_suspicious_kubectl_calls_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Sensitive_Object_Access_Activity|Kubernetes Sensitive Object Access Activity]] + + +====How To Implement==== +You must install the Add-on for Microsoft Cloud Services and Configure Kube-Audit data diagnostics + +====Required field==== + +* _time + + + + +====Kill Chain Phase==== + +* Lateral Movement + + +====Known False Positives==== +Kubectl calls are not malicious by nature. However source IP, verb and Object can reveal potential malicious activity, specially suspicious IPs and sensitive objects such as configmaps or secrets + +====Reference==== + + +====Test Dataset==== + + +''version'': 1 +
+
+ +---- + +===Kubernetes azure pod scan fingerprint=== +This search provides information of unauthenticated requests via source IP user agent, request URI and response status data against Kubernetes cluster pod in Azure + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': +* '''ATT&CK''': +* '''Last Updated''': 2020-05-20 + +
+
+ +====Search==== +`kubernetes_azure` category=kube-audit +| spath input=properties.log +| search responseStatus.code=401 +| table sourceIPs{} userAgent verb requestURI responseStatus.reason properties.pod +|`kubernetes_azure_pod_scan_fingerprint_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Scanning_Activity|Kubernetes Scanning Activity]] + + +====How To Implement==== +You must install the Add-on for Microsoft Cloud Services and Configure Kube-Audit data diagnostics + +====Required field==== + +* _time + + + + +====Kill Chain Phase==== + +* Reconnaissance + + +====Known False Positives==== +Not all unauthenticated requests are malicious, but source IPs, userAgent, verb, request URI and response status will provide context. + +====Reference==== + + +====Test Dataset==== + + +''version'': 1 +
+
+ +---- + +===Kubernetes azure scan fingerprint=== +This search provides information of unauthenticated requests via source IP user agent, request URI and response status data against Kubernetes cluster in Azure + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1526/ T1526] +* '''Last Updated''': 2020-05-19 + +
+
+ +====Search==== +`kubernetes_azure` category=kube-audit +| spath input=properties.log +| search responseStatus.code=401 +| table sourceIPs{} userAgent verb requestURI responseStatus.reason +|`kubernetes_azure_scan_fingerprint_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Scanning_Activity|Kubernetes Scanning Activity]] + + +====How To Implement==== +You must install the Add-on for Microsoft Cloud Services and Configure Kube-Audit data diagnostics + +====Required field==== + +* _time + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1526 +| Cloud Service Discovery +| Discovery +|} + + +====Kill Chain Phase==== + +* Reconnaissance + + +====Known False Positives==== +Not all unauthenticated requests are malicious, but source IPs, userAgent, verb, request URI and response status will provide context. + +====Reference==== + + +====Test Dataset==== + + +''version'': 1 +
+
+ +---- + +===Kubernetes gcp detect rbac authorizations by account=== +This search provides information on Kubernetes RBAC authorizations by accounts, this search can be modified by adding top to see both extremes of RBAC by accounts occurrences + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': +* '''ATT&CK''': +* '''Last Updated''': 2020-07-11 + +
+
+ +====Search==== +`google_gcp_pubsub_message` data.labels.authorization.k8s.io/reason=ClusterRoleBinding OR Clusterrole +| table src_ip src_user data.labels.authorization.k8s.io/decision data.labels.authorization.k8s.io/reason +| rare src_user data.labels.authorization.k8s.io/reason +|`kubernetes_gcp_detect_rbac_authorizations_by_account_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Sensitive_Role_Activity|Kubernetes Sensitive Role Activity]] + + +====How To Implement==== +You must install splunk AWS add on for GCP. This search works with pubsub messaging service logs + +====Required field==== + +* _time + + + + +====Kill Chain Phase==== + +* Lateral Movement + + +====Known False Positives==== +Not all RBAC Authorications are malicious. RBAC authorizations can uncover malicious activity specially if sensitive Roles have been granted. + +====Reference==== + + +====Test Dataset==== + + +''version'': 1 +
+
+ +---- + +===Kubernetes gcp detect most active service accounts by pod=== +This search provides information on Kubernetes service accounts,accessing pods by IP address, verb and decision + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': +* '''ATT&CK''': +* '''Last Updated''': 2020-07-10 + +
+
+ +====Search==== +`google_gcp_pubsub_message` data.protoPayload.request.spec.group{}=system:serviceaccounts +| table src_ip src_user http_user_agent data.protoPayload.request.spec.nonResourceAttributes.verb data.labels.authorization.k8s.io/decision data.protoPayload.response.spec.resourceAttributes.resource +| top src_ip src_user http_user_agent data.labels.authorization.k8s.io/decision data.protoPayload.response.spec.resourceAttributes.resource +|`kubernetes_gcp_detect_most_active_service_accounts_by_pod_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Sensitive_Role_Activity|Kubernetes Sensitive Role Activity]] + + +====How To Implement==== +You must install splunk GCP add on. This search works with pubsub messaging service logs + +====Required field==== + +* _time + + + + +====Kill Chain Phase==== + +* Lateral Movement + + +====Known False Positives==== +Not all service accounts interactions are malicious. Analyst must consider IP, verb and decision context when trying to detect maliciousness. + +====Reference==== + + +====Test Dataset==== + + +''version'': 1 +
+
+ +---- + +===Kubernetes gcp detect sensitive object access=== +This search provides information on Kubernetes accounts accessing sensitve objects such as configmaps or secrets + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': +* '''ATT&CK''': +* '''Last Updated''': 2020-07-11 + +
+
+ +====Search==== +`google_gcp_pubsub_message` data.protoPayload.authorizationInfo{}.resource=configmaps OR secrets +| table data.protoPayload.requestMetadata.callerIp src_user data.resource.labels.cluster_name data.protoPayload.request.metadata.namespace data.labels.authorization.k8s.io/decision +| dedup data.protoPayload.requestMetadata.callerIp src_user data.resource.labels.cluster_name +|`kubernetes_gcp_detect_sensitive_object_access_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Sensitive_Object_Access_Activity|Kubernetes Sensitive Object Access Activity]] + + +====How To Implement==== +You must install splunk add on for GCP . This search works with pubsub messaging service logs. + +====Required field==== + +* _time + + + + +====Kill Chain Phase==== + +* Lateral Movement + + +====Known False Positives==== +Sensitive object access is not necessarily malicious but user and object context can provide guidance for detection. + +====Reference==== + + +====Test Dataset==== + + +''version'': 1 +
+
+ +---- + +===Kubernetes gcp detect sensitive role access=== +This search provides information on Kubernetes accounts accessing sensitve objects such as configmpas or secrets + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': +* '''ATT&CK''': +* '''Last Updated''': 2020-07-11 + +
+
+ +====Search==== +`google_gcp_pubsub_message` data.labels.authorization.k8s.io/reason=ClusterRoleBinding OR Clusterrole dest=apis/rbac.authorization.k8s.io/v1 src_ip!=::1 +| table src_ip src_user http_user_agent data.labels.authorization.k8s.io/decision data.labels.authorization.k8s.io/reason +| dedup src_ip src_user +|`kubernetes_gcp_detect_sensitive_role_access_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Sensitive_Role_Activity|Kubernetes Sensitive Role Activity]] + + +====How To Implement==== +You must install splunk add on for GCP. This search works with pubsub messaging servicelogs. + +====Required field==== + +* _time + + + + +====Kill Chain Phase==== + +* Lateral Movement + + +====Known False Positives==== +Sensitive role resource access is necessary for cluster operation, however source IP, user agent, decision and reason may indicate possible malicious use. + +====Reference==== + + +====Test Dataset==== + + +''version'': 1 +
+
+ +---- + +===Kubernetes gcp detect service accounts forbidden failure access=== +This search provides information on Kubernetes service accounts with failure or forbidden access status, this search can be extended by using top or rare operators to find trends or rarities in failure status, user agents, source IPs and request URI + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': +* '''ATT&CK''': +* '''Last Updated''': 2020-06-23 + +
+
+ +====Search==== +`google_gcp_pubsub_message` system:serviceaccounts data.protoPayload.response.status.allowed!=* +| table src_ip src_user http_user_agent data.protoPayload.response.spec.resourceAttributes.namespace data.resource.labels.cluster_name data.protoPayload.response.spec.resourceAttributes.verb data.protoPayload.request.status.allowed data.protoPayload.response.status.reason data.labels.authorization.k8s.io/decision +| dedup src_ip src_user +| `kubernetes_gcp_detect_service_accounts_forbidden_failure_access_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Sensitive_Object_Access_Activity|Kubernetes Sensitive Object Access Activity]] + + +====How To Implement==== +You must install splunk add on for GCP. This search works with pubsub messaging service logs. + +====Required field==== + +* _time + + + + +====Kill Chain Phase==== + +* Lateral Movement + + +====Known False Positives==== +This search can give false positives as there might be inherent issues with authentications and permissions at cluster. + +====Reference==== + + +====Test Dataset==== + + +''version'': 1 +
+
+ +---- + +===Kubernetes gcp detect suspicious kubectl calls=== +This search provides information on anonymous Kubectl calls with IP, verb namespace and object access context + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': +* '''ATT&CK''': +* '''Last Updated''': 2020-07-11 + +
+
+ +====Search==== +`google_gcp_pubsub_message` data.protoPayload.requestMetadata.callerSuppliedUserAgent=kubectl* src_user=system:unsecured OR src_user=system:anonymous +| table src_ip src_user data.protoPayload.requestMetadata.callerSuppliedUserAgent data.protoPayload.authorizationInfo{}.granted object_path +|dedup src_ip src_user +|`kubernetes_gcp_detect_suspicious_kubectl_calls_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Kubernetes_Sensitive_Object_Access_Activity|Kubernetes Sensitive Object Access Activity]] + + +====How To Implement==== +You must install splunk add on for GCP. This search works with pubsub messaging logs. + +====Required field==== + +* _time + + + + +====Kill Chain Phase==== + +* Lateral Movement + + +====Known False Positives==== +Kubectl calls are not malicious by nature. However source IP, source user, user agent, object path, and authorization context can reveal potential malicious activity, specially anonymous suspicious IPs and sensitive objects such as configmaps or secrets + +====Reference==== + + +====Test Dataset==== + + ''version'': 1
@@ -8452,11 +9989,11 @@ This search looks for PowerShell processes started with a base64 encoded command ====Search==== -| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=powershell.exe by Processes.user Processes.process_name Processes.parent_process_name Processes.dest -| `drop_dm_object_name(Processes)` +| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=powershell.exe by Processes.user Processes.process_name Processes.parent_process_name Processes.dest +| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` -| search (process=*-EncodedCommand* OR process=*-enc*) process=*-Exec* +| search (process=*-EncodedCommand* OR process=*-enc*) process=*-Exec* | `malicious_powershell_process___multiple_suspicious_command_line_arguments_filter` ====Associated Analytic Story==== @@ -8469,6 +10006,8 @@ You must be ingesting data that records process activity from your hosts to popu ====Required field==== +* _time + ====ATT&CK==== @@ -8510,7 +10049,7 @@ This search looks for DNS requests for faux domains similar to the domains that * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Network_Resolution -* '''ATT&CK''': +* '''ATT&CK''': * '''Last Updated''': 2017-09-23
@@ -8518,10 +10057,10 @@ This search looks for DNS requests for faux domains similar to the domains that ====Search==== -| tstats `security_content_summariesonly` values(DNS.answer) as IPs min(_time) as firstTime from datamodel=Network_Resolution by DNS.src, DNS.query -| `drop_dm_object_name("DNS")` +| tstats `security_content_summariesonly` values(DNS.answer) as IPs min(_time) as firstTime from datamodel=Network_Resolution by DNS.src, DNS.query +| `drop_dm_object_name("DNS")` | `security_content_ctime(firstTime)` -| `brand_abuse_dns` +| `brand_abuse_dns` | `monitor_dns_for_brand_abuse_filter` ====Associated Analytic Story==== @@ -8534,6 +10073,8 @@ You need to ingest data from your DNS logs. Specifically you must ingest the dom ====Required field==== +* _time + @@ -8563,15 +10104,15 @@ None at this time This search allows you to look for evidence of exploitation for CVE-2016-4859, the Splunk Open Redirect Vulnerability. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': +* '''Datamodel''': +* '''ATT&CK''': * '''Last Updated''': 2017-09-19
====Search==== -index=_internal sourcetype=splunk_web_access return_to="/%09/*" +index=_internal sourcetype=splunk_web_access return_to="/%09/*" | `open_redirect_in_splunk_web_filter` ====Associated Analytic Story==== @@ -8584,6 +10125,8 @@ No extra steps needed to implement this search. ====Required field==== +* _time + @@ -8611,8 +10154,8 @@ None identified This search looks for ColdRoot events from the osx-attacks osquery pack. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': +* '''Datamodel''': +* '''ATT&CK''': * '''Last Updated''': 2019-01-29
@@ -8620,11 +10163,11 @@ This search looks for ColdRoot events from the osx-attacks osquery pack. ====Search==== -| from datamodel Alerts.Alerts -| search app=osquery:results (name=pack_osx-attacks_OSX_ColdRoot_RAT_Launchd OR name=pack_osx-attacks_OSX_ColdRoot_RAT_Files) -| rename columns.path as path -| bucket _time span=30s -| stats count(path) by _time, host, user, path +| from datamodel Alerts.Alerts +| search app=osquery:results (name=pack_osx-attacks_OSX_ColdRoot_RAT_Launchd OR name=pack_osx-attacks_OSX_ColdRoot_RAT_Files) +| rename columns.path as path +| bucket _time span=30s +| stats count(path) by _time, host, user, path | `osquery_pack___coldroot_detection_filter` ====Associated Analytic Story==== @@ -8637,6 +10180,8 @@ In order to properly run this search, Splunk needs to ingest data from your osqu ====Required field==== +* _time + @@ -8675,10 +10220,10 @@ This search looks for processes launching netsh.exe to execute various commands ====Search==== -| tstats `security_content_summariesonly` count values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=netsh.exe by Processes.user Processes.dest Processes.parent_process Processes.parent_process_name Processes.process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` count values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=netsh.exe by Processes.user Processes.dest Processes.parent_process Processes.parent_process_name Processes.process_name +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `processes_created_by_netsh_filter` ====Associated Analytic Story==== @@ -8691,6 +10236,8 @@ To successfully implement this search, you must be ingesting logs with the proce ====Required field==== +* _time + ====ATT&CK==== @@ -8730,7 +10277,7 @@ This search looks for applications on the endpoint that you have marked as prohi * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': +* '''ATT&CK''': * '''Last Updated''': 2019-10-11
@@ -8738,11 +10285,11 @@ This search looks for applications on the endpoint that you have marked as prohi ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes by Processes.dest Processes.user Processes.process_name +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes by Processes.dest Processes.user Processes.process_name | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `drop_dm_object_name(Processes)` -| `prohibited_softwares` +| `security_content_ctime(lastTime)` +| `drop_dm_object_name(Processes)` +| `prohibited_softwares` | `prohibited_software_on_endpoint_filter` ====Associated Analytic Story==== @@ -8759,6 +10306,8 @@ To successfully implement this search, you must be ingesting data that records p ====Required field==== +* _times + @@ -8800,10 +10349,10 @@ The search looks for command-line arguments used to hide a file or directory usi ====Search==== | tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = reg.exe Processes.process="*add*" Processes.process="*Hidden*" Processes.process="*REG_DWORD*" by Processes.process_name Processes.parent_process_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` -| regex process = "(/d\s+2)" +| regex process = "(/d\s+2)" | `reg_exe_used_to_hide_files_directories_via_registry_keys_filter` ====Associated Analytic Story==== @@ -8820,6 +10369,8 @@ You must be ingesting data that records process activity from your hosts to popu ====Required field==== +* _time + ====ATT&CK==== @@ -8858,8 +10409,8 @@ None at the moment This search monitors for remote modifications to registry keys. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': +* '''Datamodel''': +* '''ATT&CK''': * '''Last Updated''': 2020-03-02
@@ -8867,10 +10418,10 @@ This search monitors for remote modifications to registry keys. ====Search==== -| tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="\\\\*" by Registry.dest , Registry.user -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `drop_dm_object_name(Registry)` +| tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="\\\\*" by Registry.dest , Registry.user +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` +| `drop_dm_object_name(Registry)` | `remote_registry_key_modifications_filter` ====Associated Analytic Story==== @@ -8887,6 +10438,8 @@ To successfully implement this search, you must populate the `Endpoint` data mod ====Required field==== +* _time + @@ -8923,10 +10476,10 @@ This search looks for wmic.exe being launched with parameters to operate on remo ====Search==== -| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=wmic.exe AND Processes.process= */node* by Processes.user Processes.process_name Processes.parent_process_name Processes.dest -| `drop_dm_object_name(Processes)` +| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=wmic.exe AND Processes.process= */node* by Processes.user Processes.process_name Processes.parent_process_name Processes.dest +| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | `remote_wmi_command_attempt_filter` ====Associated Analytic Story==== @@ -8939,6 +10492,8 @@ You must be ingesting data that records process activity from your hosts to popu ====Required field==== +* _time + ====ATT&CK==== @@ -8986,11 +10541,11 @@ This search looks for flags passed to schtasks.exe on the command-line that indi ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Processes.process) as process from datamodel=Endpoint.Processes where Processes.process_name=schtasks.exe (Processes.process= "*create*" OR Processes.process= "*delete*") by Processes.parent_process Processes.process_name Processes.user -| `drop_dm_object_name("Processes")` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Processes.process) as process from datamodel=Endpoint.Processes where Processes.process_name=schtasks.exe (Processes.process= "*create*" OR Processes.process= "*delete*") by Processes.parent_process Processes.process_name Processes.user +| `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` -| search (process=*rhaegal* OR process=*drogon* OR *viserion_*) +|`security_content_ctime(lastTime)` +| search (process=*rhaegal* OR process=*drogon* OR *viserion_*) | `scheduled_tasks_used_in_badrabbit_ransomware_filter` ====Associated Analytic Story==== @@ -9003,6 +10558,8 @@ You must be ingesting data that records process activity from your hosts to popu ====Required field==== +* _time + ====ATT&CK==== @@ -9037,24 +10594,76 @@ No known false positives ---- +===Spectre and meltdown vulnerable systems=== +The search is used to detect systems that are still vulnerable to the Spectre and Meltdown vulnerabilities. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Vulnerabilities +* '''ATT&CK''': +* '''Last Updated''': 2017-01-07 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` min(_time) as firstTime max(_time) as lastTime from datamodel=Vulnerabilities where Vulnerabilities.cve ="CVE-2017-5753" OR Vulnerabilities.cve ="CVE-2017-5715" OR Vulnerabilities.cve ="CVE-2017-5754" by Vulnerabilities.dest +| `drop_dm_object_name(Vulnerabilities)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `spectre_and_meltdown_vulnerable_systems_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Spectre_And_Meltdown_Vulnerabilities|Spectre And Meltdown Vulnerabilities]] + + +====How To Implement==== +The search requires that you are ingesting your vulnerability-scanner data and that it reports the CVE of the vulnerability identified. + +====Required field==== + +* _time + + + + +====Kill Chain Phase==== + + +====Known False Positives==== +It is possible that your vulnerability scanner is not detecting that the patches have been applied. + +====Reference==== + + +====Test Dataset==== + + +''version'': 1 +
+
+ +---- + ===Splunk enterprise information disclosure=== This search allows you to look for evidence of exploitation for CVE-2018-11409, a Splunk Enterprise Information Disclosure Bug. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': +* '''Datamodel''': +* '''ATT&CK''': * '''Last Updated''': 2018-06-14
====Search==== -index=_internal sourcetype=splunkd_ui_access server-info -| search clientip!=127.0.0.1 uri_path="*raw/services/server/info/server-info" -| rename clientip as src_ip, splunk_server as dest -| stats earliest(_time) as firstTime, latest(_time) as lastTime, values(uri) as uri, values(useragent) as http_user_agent, values(user) as user by src_ip, dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +index=_internal sourcetype=splunkd_ui_access server-info +| search clientip!=127.0.0.1 uri_path="*raw/services/server/info/server-info" +| rename clientip as src_ip, splunk_server as dest +| stats earliest(_time) as firstTime, latest(_time) as lastTime, values(uri) as uri, values(useragent) as http_user_agent, values(user) as user by src_ip, dest +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `splunk_enterprise_information_disclosure_filter` ====Associated Analytic Story==== @@ -9067,6 +10676,8 @@ The REST endpoint that exposes system information is also necessary for the prop ====Required field==== +* _time + @@ -9094,7 +10705,7 @@ Retrieving server information may be a legitimate API request. Verify that the a This search looks for changes to registry values that control Windows file associations, executed by a process that is not typical for legitimate, routine changes to this area. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1546.001/ T1546.001] * '''Last Updated''': 2020-07-22 @@ -9103,13 +10714,13 @@ This search looks for changes to registry values that control Windows file assoc ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Processes.process_name) as process_name values(Processes.parent_process_name) as parent_process_name FROM datamodel=Endpoint.Processes where Processes.process_name!=Explorer.exe AND Processes.process_name!=OpenWith.exe by Processes.process_id Processes.dest -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Processes.process_name) as process_name values(Processes.parent_process_name) as parent_process_name FROM datamodel=Endpoint.Processes where Processes.process_name!=Explorer.exe AND Processes.process_name!=OpenWith.exe by Processes.process_id Processes.dest +| `drop_dm_object_name("Processes")` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | join [ -| tstats `security_content_summariesonly` values(Registry.registry_path) as registry_path count FROM datamodel=Endpoint.Registry where Registry.registry_path=*\\Explorer\\FileExts* by Registry.process_id Registry.dest -| `drop_dm_object_name("Registry")` +| tstats `security_content_summariesonly` values(Registry.registry_path) as registry_path count FROM datamodel=Endpoint.Registry where Registry.registry_path=*\\Explorer\\FileExts* by Registry.process_id Registry.dest +| `drop_dm_object_name("Registry")` | table process_id dest registry_path] | `suspicious_changes_to_file_associations_filter` @@ -9125,6 +10736,8 @@ To successfully implement this search you need to be ingesting information on re ====Required field==== +* _time + ====ATT&CK==== @@ -9159,12 +10772,78 @@ There may be other processes in your environment that users may legitimately use ---- +===Suspicious email - uba anomaly=== +This detection looks for emails that are suspicious because of their sender, domain rareness, or behavior differences. This is an anomaly generated by Splunk User Behavior Analytics (UBA). + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': UEBA +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1566/ T1566] +* '''Last Updated''': 2020-07-22 + +
+
+ +====Search==== + +|tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(All_UEBA_Events.category) as category from datamodel=UEBA where nodename=All_UEBA_Events.UEBA_Anomalies All_UEBA_Events.UEBA_Anomalies.uba_model = "SuspiciousEmailDetectionModel" by All_UEBA_Events.description All_UEBA_Events.severity All_UEBA_Events.user All_UEBA_Events.uba_event_type All_UEBA_Events.link All_UEBA_Events.signature All_UEBA_Events.url All_UEBA_Events.UEBA_Anomalies.uba_model +| `drop_dm_object_name(All_UEBA_Events)` +| `drop_dm_object_name(UEBA_Anomalies)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `suspicious_email___uba_anomaly_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Suspicious_Emails|Suspicious Emails]] + + +====How To Implement==== +You must be ingesting data from email logs and have Splunk integrated with UBA. This anomaly is raised by a UBA detection model called "SuspiciousEmailDetectionModel." Ensure that this model is enabled on your UBA instance. + +====Required field==== + +* _time + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1566 +| Phishing +| Initial Access +|} + + +====Kill Chain Phase==== + +* Delivery + + +====Known False Positives==== +This detection model will alert on any sender domain that is seen for the first time. This could be a potential false positive. The next step is to investigate and add the URL to an allow list if you determine that it is a legitimate sender. + +====Reference==== + + +====Test Dataset==== + + +''version'': 3 +
+
+ +---- + ===Suspicious file write=== The search looks for files created with names that have been linked to malicious activity. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': +* '''Datamodel''': +* '''ATT&CK''': * '''Last Updated''': 2019-04-25
@@ -9172,11 +10851,11 @@ The search looks for files created with names that have been linked to malicious ====Search==== -| tstats `security_content_summariesonly` count values(Filesystem.action) as action values(Filesystem.file_path) as file_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem by Filesystem.file_name Filesystem.dest -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `drop_dm_object_name(Filesystem)` -| `suspicious_writes` +| tstats `security_content_summariesonly` count values(Filesystem.action) as action values(Filesystem.file_path) as file_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem by Filesystem.file_name Filesystem.dest +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` +| `drop_dm_object_name(Filesystem)` +| `suspicious_writes` | `suspicious_file_write_filter` ====Associated Analytic Story==== @@ -9189,6 +10868,8 @@ You must be ingesting data that records the filesystem activity from your hosts ====Required field==== +* _time + @@ -9216,7 +10897,7 @@ It's possible for a legitimate file to be created with the same name as one note This search detects writes to the 'System Volume Information' folder by something other than the System process. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1036/ T1036] * '''Last Updated''': 2020-07-22 @@ -9224,10 +10905,10 @@ This search detects writes to the 'System Volume Information' folder by somethin
====Search==== -(`sysmon` OR tag=process) EventCode=11 process_id!=4 file_path=*System\ Volume\ Information* -| stats count min(_time) as firstTime max(_time) as lastTime by dest, Image, file_path +(`sysmon` OR tag=process) EventCode=11 process_id!=4 file_path=*System\ Volume\ Information* +| stats count min(_time) as firstTime max(_time) as lastTime by dest, Image, file_path | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | `suspicious_writes_to_system_volume_information_filter` ====Associated Analytic Story==== @@ -9240,6 +10921,8 @@ You need to be ingesting logs with both the process name and command-line from y ====Required field==== +* _time + ====ATT&CK==== @@ -9285,11 +10968,11 @@ This search looks for applications on the endpoint that you have marked as uncom ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes by Processes.dest Processes.user Processes.process Processes.process_name +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes by Processes.dest Processes.user Processes.process Processes.process_name | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `drop_dm_object_name(Processes)` -| `uncommon_processes` +| `security_content_ctime(lastTime)` +| `drop_dm_object_name(Processes)` +| `uncommon_processes` |`uncommon_processes_on_endpoint_filter` ====Associated Analytic Story==== @@ -9298,14 +10981,14 @@ This search looks for applications on the endpoint that you have marked as uncom * [[Documentation:ESSOC:stories:UseCase#Unusual_Processes|Unusual Processes]] -* [[Documentation:ESSOC:stories:UseCase#Cloud_Federated_Credential_Abuse|Cloud Federated Credential Abuse]] - ====How To Implement==== You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. This search uses a lookup file `uncommon_processes_default.csv` to track various features of process names that are usually uncommon in most environments. Please consider updating `uncommon_processes_local.csv` to hunt for processes that are uncommon in your environment. ====Required field==== +* _time + ====ATT&CK==== @@ -9344,7 +11027,7 @@ None identified This search detects loading of unsigned images by LSASS. Deprecated because too noisy. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1003.001/ T1003.001] * '''Last Updated''': 2019-12-06 @@ -9352,11 +11035,11 @@ This search detects loading of unsigned images by LSASS. Deprecated because too
====Search==== -`sysmon` EventID=7 Image=*lsass.exe Signed=false -| stats count min(_time) as firstTime max(_time) as lastTime by Computer, Image, ImageLoaded, Signed, SHA1 -| rename Computer as dest +`sysmon` EventID=7 Image=*lsass.exe Signed=false +| stats count min(_time) as firstTime max(_time) as lastTime by Computer, Image, ImageLoaded, Signed, SHA1 +| rename Computer as dest | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | `unsigned_image_loaded_by_lsass_filter` ====Associated Analytic Story==== @@ -9369,6 +11052,8 @@ This search needs Sysmon Logs with a sysmon configuration, which includes EventC ====Required field==== +* _time + ====ATT&CK==== @@ -9409,20 +11094,20 @@ Other tools could load images into LSASS for legitimate reason. But enterprise t This search gives you the hosts where a backup was attempted and then failed. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': +* '''Datamodel''': +* '''ATT&CK''': * '''Last Updated''': 2017-09-12
====Search==== -`netbackup` -| stats latest(_time) as latestTime by COMPUTERNAME, MESSAGE -| search MESSAGE="An error occurred, failed to backup." -| `security_content_ctime(latestTime)` -| rename COMPUTERNAME as dest, MESSAGE as signature -| table latestTime, dest, signature +`netbackup` +| stats latest(_time) as latestTime by COMPUTERNAME, MESSAGE +| search MESSAGE="An error occurred, failed to backup." +| `security_content_ctime(latestTime)` +| rename COMPUTERNAME as dest, MESSAGE as signature +| table latestTime, dest, signature | `unsuccessful_netbackup_backups_filter` ====Associated Analytic Story==== @@ -9435,6 +11120,8 @@ To successfully implement this search you need to obtain data from your backup s ====Required field==== +* _time + @@ -9456,35 +11143,46 @@ None identified ---- -===Windows disableantispyware registry=== -The search looks for the Registry Key DisableAntiSpyware set to disable. This is consistent with Ryuk infections across a fleet of endpoints. +===Web fraud - account harvesting=== +This search is used to identify the creation of multiple user accounts using the same email domain name. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562.001/ T1562.001] -* '''Last Updated''': 2020-11-06 +* '''Datamodel''': +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1136/ T1136] +* '''Last Updated''': 2018-10-08
====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_key_name="DisableAntiSpyware" AND Registry.registry_value_name="DWORD (0x00000000)" by Registry.dest Registry.user Registry.registry_path Registry.registry_value_name -| `drop_dm_object_name(Registry)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `windows_disableantispyware_registry_filter` +`stream_http` http_content_type=text* uri="/magento2/customer/account/loginPost/" +| rex field=cookie "form_key=(?\w+)" +| rex field=form_data "login\[username\]=(?[^& +|^$]+)" +| search Username=* +| rex field=Username "@(?.*)" +| stats dc(Username) as UniqueUsernames list(Username) as src_user by email_domain +| where UniqueUsernames> 25 +| `web_fraud___account_harvesting_filter` ====Associated Analytic Story==== -* [[Documentation:ESSOC:stories:UseCase#Ryuk_Ransomware|Ryuk Ransomware]] +* [[Documentation:ESSOC:stories:UseCase#Web_Fraud_Detection|Web Fraud Detection]] ====How To Implement==== -You must be ingesting data that records the process-system activity from your hosts to populate the Endpoint Processes data-model object. If you are using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which you want to collect data. +We start with a dataset that provides visibility into the email address used for the account creation. In this example, we are narrowing our search down to the single web page that hosts the Magento2 e-commerce platform (via URI) used for account creation, the single http content-type to grab only the user's clicks, and the http field that provides the username (form_data), for performance reasons. After we have the username and email domain, we look for numerous account creations per email domain. Common data sources used for this detection are customized Apache logs or Splunk Stream. ====Required field==== +* _time + +* http_content_type + +* uri + +* cookie + ====ATT&CK==== @@ -9493,22 +11191,170 @@ You must be ingesting data that records the process-system activity from your ho ! Technique ! Tactic |- -| T1562.001 -| Disable or Modify Tools -| Defense Evasion +| T1136 +| Create Account +| Persistence |} ====Kill Chain Phase==== -* Delivery +* Actions on Objectives ====Known False Positives==== -It is unusual to turn this feature on a Windows system since it is a default security control, although it is not rare for some policies to disable it. Although no false positives have been identified, use the provided filter macro to tune the search. +As is common with many fraud-related searches, we are usually looking to attribute risk or synthesize relevant context with loosely written detections that simply detect anamolous behavior. This search will need to be customized to fit your environment—improving its fidelity by counting based on something much more specific, such as a device ID that may be present in your dataset. Consideration for whether the large number of registrations are occuring from a first-time seen domain may also be important. Extending the search window to look further back in time, or even calculating the average per hour/day for each email domain to look for an anomalous spikes, will improve this search. You can also use Shannon entropy or Levenshtein Distance (both courtesy of URL Toolbox) to consider the randomness or similarity of the email name or email domain, as the names are often machine-generated. ====Reference==== +* https://splunkbase.splunk.com/app/2734/ + +* https://splunkbase.splunk.com/app/1809/ + + +====Test Dataset==== + + +''version'': 1 +
+
+ +---- + +===Web fraud - anomalous user clickspeed=== +This search is used to examine web sessions to identify those where the clicks are occurring too quickly for a human or are occurring with a near-perfect cadence (high periodicity or low standard deviation), resembling a script driven session. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078] +* '''Last Updated''': 2018-10-08 + +
+
+ +====Search==== +`stream_http` http_content_type=text* +| rex field=cookie "form_key=(?\w+)" +| streamstats window=2 current=1 range(_time) as TimeDelta by session_id +| where TimeDelta>0 +|stats count stdev(TimeDelta) as ClickSpeedStdDev avg(TimeDelta) as ClickSpeedAvg by session_id +| where count>5 AND (ClickSpeedStdDev<.5 OR ClickSpeedAvg<.5) +| `web_fraud___anomalous_user_clickspeed_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Web_Fraud_Detection|Web Fraud Detection]] + + +====How To Implement==== +Start with a dataset that allows you to see clickstream data for each user click on the website. That data must have a time stamp and must contain a reference to the session identifier being used by the website. This ties the clicks together into clickstreams. This value is usually found in the http cookie. With a bit of tuning, a version of this search could be used in high-volume scenarios, such as scraping, crawling, application DDOS, credit-card testing, account takeover, etc. Common data sources used for this detection are customized Apache logs, customized IIS, and Splunk Stream. + +====Required field==== + +* _time + +* http_content_type + +* cookie + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1078 +| Valid Accounts +| Defense Evasion, Initial Access, Persistence, Privilege Escalation +|} + + +====Kill Chain Phase==== + +* Actions on Objectives + + +====Known False Positives==== +As is common with many fraud-related searches, we are usually looking to attribute risk or synthesize relevant context with loosly written detections that simply detect anamoluous behavior. + +====Reference==== + +* https://en.wikipedia.org/wiki/Session_ID + +* https://en.wikipedia.org/wiki/Session_(computer_science) + +* https://en.wikipedia.org/wiki/HTTP_cookie + +* https://splunkbase.splunk.com/app/1809/ + + +====Test Dataset==== + + +''version'': 1 +
+
+ +---- + +===Web fraud - password sharing across accounts=== +This search is used to identify user accounts that share a common password. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': +* '''ATT&CK''': +* '''Last Updated''': 2018-10-08 + +
+
+ +====Search==== +`stream_http` http_content_type=text* uri=/magento2/customer/account/loginPost* +| rex field=form_data "login\[username\]=(?[^& +|^$]+)" +| rex field=form_data "login\[password\]=(?[^& +|^$]+)" +| stats dc(Username) as UniqueUsernames values(Username) as user list(src_ip) as src_ip by Password +|where UniqueUsernames>5 +| `web_fraud___password_sharing_across_accounts_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Web_Fraud_Detection|Web Fraud Detection]] + + +====How To Implement==== +We need to start with a dataset that allows us to see the values of usernames and passwords that users are submitting to the website hosting the Magento2 e-commerce platform (commonly found in the HTTP form_data field). A tokenized or hashed value of a password is acceptable and certainly preferable to a clear-text password. Common data sources used for this detection are customized Apache logs, customized IIS, and Splunk Stream. + +====Required field==== + +* _time + +* http_content_type + +* uri + + + + +====Kill Chain Phase==== + + +====Known False Positives==== +As is common with many fraud-related searches, we are usually looking to attribute risk or synthesize relevant context with loosely written detections that simply detect anamoluous behavior. + +====Reference==== + +* https://en.wikipedia.org/wiki/Session_ID + +* https://en.wikipedia.org/wiki/Session_(computer_science) + +* https://en.wikipedia.org/wiki/HTTP_cookie + +* https://splunkbase.splunk.com/app/1809/ + ====Test Dataset==== @@ -9520,10 +11366,10 @@ It is unusual to turn this feature on a Windows system since it is a default sec ---- ===Windows connhost exe started forcefully=== -The search looks for the Console Window Host process (connhost.exe) executed using the force flag -ForceV1. This is not regular behavior in the Windows OS and is often seen executed by the Ryuk Ransomware. DEPRECATED This event is actually seen in the windows 10 client of attack_range_local. After further testing we realized this is not specific to Ryuk. +The search looks for the Console Window Host process (connhost.exe) executed using the force flag -ForceV1. This is not regular behavior in the Windows OS and is often seen executed by the Ryuk Ransomware. DEPRECATED This event is actually seen in the windows 10 client of attack_range_local. After further testing we realized this is not specific to Ryuk. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1059.003/ T1059.003] * '''Last Updated''': 2020-11-06 @@ -9532,10 +11378,10 @@ The search looks for the Console Window Host process (connhost.exe) executed usi ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes WHERE Processes.process="*C:\\Windows\\system32\\conhost.exe* 0xffffffff *-ForceV1*" by Processes.user Processes.process_name Processes.process Processes.dest -| `drop_dm_object_name(Processes)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes WHERE Processes.process="*C:\\Windows\\system32\\conhost.exe* 0xffffffff *-ForceV1*" by Processes.user Processes.process_name Processes.process Processes.dest +| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | `windows_connhost_exe_started_forcefully_filter` ====Associated Analytic Story==== @@ -9548,6 +11394,8 @@ You must be ingesting data that records the process-system activity from your ho ====Required field==== +* _time + ====ATT&CK==== @@ -9586,8 +11434,8 @@ This process should not be ran forcefully, we have not see any false positives f The search looks for modifications to the hosts file on all Windows endpoints across your environment. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': +* '''Datamodel''': +* '''ATT&CK''': * '''Last Updated''': 2018-11-02
@@ -9595,11 +11443,11 @@ The search looks for modifications to the hosts file on all Windows endpoints ac ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem by Filesystem.file_name Filesystem.file_path Filesystem.dest -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| search Filesystem.file_name=hosts AND Filesystem.file_path=*Windows\\System32\\* -| `drop_dm_object_name(Filesystem)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem by Filesystem.file_name Filesystem.file_path Filesystem.dest +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` +| search Filesystem.file_name=hosts AND Filesystem.file_path=*Windows\\System32\\* +| `drop_dm_object_name(Filesystem)` | `windows_hosts_file_modification_filter` ====Associated Analytic Story==== @@ -9612,6 +11460,8 @@ To successfully implement this search, you must be ingesting data that records t ====Required field==== +* _time + @@ -9629,6 +11479,72 @@ There may be legitimate reasons for system administrators to add entries to this ====Test Dataset==== +''version'': 1 +
+
+ +---- + +===Gcp detect oauth token abuse=== +This search provides detection of possible GCP Oauth token abuse. GCP Oauth token without time limit can be exfiltrated and reused for keeping access sessions alive without further control of authentication, allowing attackers to access and move laterally. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078] +* '''Last Updated''': 2020-09-01 + +
+
+ +====Search==== +`google_gcp_pubsub_message` type.googleapis.com/google.cloud.audit.AuditLog +|table protoPayload.@type protoPayload.status.details{}.@type protoPayload.status.details{}.violations{}.callerIp protoPayload.status.details{}.violations{}.type protoPayload.status.message +| `gcp_detect_oauth_token_abuse_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#GCP_Cross_Account_Activity|GCP Cross Account Activity]] + + +====How To Implement==== +You must install splunk GCP add-on. This search works with gcp:pubsub:message logs + +====Required field==== + +* _time + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1078 +| Valid Accounts +| Defense Evasion, Initial Access, Persistence, Privilege Escalation +|} + + +====Kill Chain Phase==== + +* Lateral Movement + + +====Known False Positives==== +GCP Oauth token abuse detection will only work if there are access policies in place along with audit logs. + +====Reference==== + +* https://www.netskope.com/blog/gcp-oauth-token-hijacking-in-google-cloud-part-1 + +* https://www.netskope.com/blog/gcp-oauth-token-hijacking-in-google-cloud-part-2 + + +====Test Dataset==== + + ''version'': 1
@@ -9644,7 +11560,7 @@ There may be legitimate reasons for system administrators to add entries to this Detect memory dumping of the LSASS process. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1003.001/ T1003.001] * '''Last Updated''': 2019-12-06 @@ -9652,11 +11568,11 @@ Detect memory dumping of the LSASS process.
====Search==== -`sysmon` EventCode=10 TargetImage=*lsass.exe CallTrace=*dbgcore.dll* OR CallTrace=*dbghelp.dll* -| stats count min(_time) as firstTime max(_time) as lastTime by Computer, TargetImage, TargetProcessId, SourceImage, SourceProcessId -| rename Computer as dest +`sysmon` EventCode=10 TargetImage=*lsass.exe CallTrace=*dbgcore.dll* OR CallTrace=*dbghelp.dll* +| stats count min(_time) as firstTime max(_time) as lastTime by Computer, TargetImage, TargetProcessId, SourceImage, SourceProcessId +| rename Computer as dest | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | `access_lsass_memory_for_dump_creation_filter` ====Associated Analytic Story==== @@ -9669,6 +11585,22 @@ This search requires Sysmon Logs and a Sysmon configuration, which includes Even ====Required field==== +* _time + +* EventCode + +* TargetImage + +* CallTrace + +* Computer + +* TargetProcessId + +* SourceImage + +* SourceProcessId + ====ATT&CK==== @@ -9707,11 +11639,191 @@ Administrators can create memory dumps for debugging purposes, but memory dumps ---- +===Any powershell downloadfile=== +The following analytic identifies the use of PowerShell downloading a file using `DownloadFile` method. This particular method is utilized in many different PowerShell frameworks to download files and output to disk. Identify the source (IP/domain) and destination file and triage appropriately. If AMSI logging or PowerShell transaction logs are available, review for further details of the implant. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059.001/ T1059.001] +* '''Last Updated''': 2021-03-01 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=powershell.exe OR Processes.process_name=pwsh.exe OR Processes.process_name=PowerShell_ISE.exe) Processes.process=*DownloadFile* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `any_powershell_downloadfile_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] + + +====How To Implement==== +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. + +====Required field==== + +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_name + +* Processes.process_id + +* Processes.parent_process_id + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1059.001 +| PowerShell +| Execution +|} + + +====Kill Chain Phase==== + +* Exploitation + + +====Known False Positives==== +False positives may be present and filtering will need to occur by parent process or command line argument. It may be required to modify this query to an EDR product for more granular coverage. + +====Reference==== + +* https://docs.microsoft.com/en-us/dotnet/api/system.net.webclient.downloadfile?view=net-5.0 + +* https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/ + +* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/windows-sysmon.log + + +''version'': 1 +
+
+ +---- + +===Any powershell downloadstring=== +The following analytic identifies the use of PowerShell downloading a file using `DownloadString` method. This particular method is utilized in many different PowerShell frameworks to download files and output to disk. Identify the source (IP/domain) and destination file and triage appropriately. If AMSI logging or PowerShell transaction logs are available, review for further details of the implant. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059.001/ T1059.001] +* '''Last Updated''': 2021-03-01 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=powershell.exe OR Processes.process_name=pwsh.exe OR Processes.process_name=PowerShell_ISE.exe Processes.process=*.DownloadString* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `any_powershell_downloadstring_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] + +* [[Documentation:ESSOC:stories:UseCase#HAFNIUM_Group|HAFNIUM Group]] + + +====How To Implement==== +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. + +====Required field==== + +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_name + +* Processes.process_id + +* Processes.parent_process_id + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1059.001 +| PowerShell +| Execution +|} + + +====Kill Chain Phase==== + +* Exploitation + + +====Known False Positives==== +False positives may be present and filtering will need to occur by parent process or command line argument. It may be required to modify this query to an EDR product for more granular coverage. + +====Reference==== + +* https://docs.microsoft.com/en-us/dotnet/api/system.net.webclient.downloadstring?view=net-5.0 + +* https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/ + +* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1059.001/T1059.001.md + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/windows-sysmon.log + + +''version'': 1 +
+
+ +---- + ===Applying stolen credentials via mimikatz modules=== This detection indicates use of Mimikatz modules that facilitate Pass-the-Token attack, Golden or Silver kerberos ticket attack, and Skeleton key attack. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1055/ T1055], [https://attack.mitre.org/techniques/T1068/ T1068], [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1098/ T1098], [https://attack.mitre.org/techniques/T1134/ T1134], [https://attack.mitre.org/techniques/T1543/ T1543], [https://attack.mitre.org/techniques/T1547/ T1547], [https://attack.mitre.org/techniques/T1548/ T1548], [https://attack.mitre.org/techniques/T1554/ T1554], [https://attack.mitre.org/techniques/T1556/ T1556], [https://attack.mitre.org/techniques/T1558/ T1558] * '''Last Updated''': 2020-11-03 @@ -9722,14 +11834,16 @@ This detection indicates use of Mimikatz modules that facilitate Pass-the-Token | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, /(?i)kerberos::ptt/)=true OR match_regex(cmd_line, /(?i)kerberos::golden/)=true OR match_regex(cmd_line, /(?i)kerberos::silver/)=true OR match_regex(cmd_line, /(?i)misc::skeleton/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -9815,6 +11929,8 @@ None identified. ====Test Dataset==== +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555/applying_stolen_credentials/logAllMimikatzModules.log + ''version'': 1
@@ -9826,8 +11942,8 @@ None identified. Stolen credentials are applied by methods such as user impersonation, credential injection, spoofing of authentication processes or getting hold of critical accounts. This detection indicates such activities carried out by PowerSploit exploit kit APIs. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1055/ T1055], [https://attack.mitre.org/techniques/T1068/ T1068], [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1098/ T1098], [https://attack.mitre.org/techniques/T1134/ T1134], [https://attack.mitre.org/techniques/T1543/ T1543], [https://attack.mitre.org/techniques/T1547/ T1547], [https://attack.mitre.org/techniques/T1548/ T1548], [https://attack.mitre.org/techniques/T1554/ T1554], [https://attack.mitre.org/techniques/T1556/ T1556], [https://attack.mitre.org/techniques/T1558/ T1558] +* '''Datamodel''': +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1055/ T1055], [https://attack.mitre.org/techniques/T1068/ T1068], [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1098/ T1098], [https://attack.mitre.org/techniques/T1134/ T1134], [https://attack.mitre.org/techniques/T1543/ T1543], [https://attack.mitre.org/techniques/T1547/ T1547], [https://attack.mitre.org/techniques/T1548/ T1548], [https://attack.mitre.org/techniques/T1554/ T1554], [https://attack.mitre.org/techniques/T1555/ T1555], [https://attack.mitre.org/techniques/T1558/ T1558] * '''Last Updated''': 2020-11-03
@@ -9837,14 +11953,16 @@ Stolen credentials are applied by methods such as user impersonation, credential | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, /(?i)Invoke-CredentialInjection/)=true OR match_regex(cmd_line, /(?i)Invoke-TokenManipulation/)=true OR match_regex(cmd_line, /(?i)Invoke-UserImpersonation/)=true OR match_regex(cmd_line, /(?i)Get-System/)=true OR match_regex(cmd_line, /(?i)Invoke-RevertToSelf/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -9903,9 +12021,9 @@ You must be ingesting Windows Security logs from devices of interest, including | Compromise Client Software Binary | Persistence |- -| T1556 -| Modify Authentication Process -| Credential Access, Defense Evasion +| T1555 +| Credentials from Password Stores +| Credential Access |- | T1558 | Steal or Forge Kerberos Tickets @@ -9928,6 +12046,8 @@ None identified. ====Test Dataset==== +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1555/applying_stolen_credentials/logAllPowerSploitModulesWithOldNames.log + ''version'': 1
@@ -9939,7 +12059,7 @@ None identified. This detection identifies use of DSInternals modules that verify password strength, i.e., identify week accounts that would be easily compromised. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1098/ T1098], [https://attack.mitre.org/techniques/T1087/ T1087], [https://attack.mitre.org/techniques/T1201/ T1201], [https://attack.mitre.org/techniques/T1552/ T1552], [https://attack.mitre.org/techniques/T1555/ T1555] * '''Last Updated''': 2020-11-03 @@ -9950,14 +12070,16 @@ This detection identifies use of DSInternals modules that verify password streng | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, /(?i)Test-PasswordQuality/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -10029,7 +12151,7 @@ None identified. ---- ===Attempt to add certificate to untrusted store=== -Attempt to add a certificate to the certificate store +Attempt To Add Certificate To Untrusted Store * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint @@ -10041,10 +12163,10 @@ Attempt to add a certificate to the certificate store ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime values(Processes.process) as process max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=*certutil* (Processes.process=*-addstore*) by Processes.parent_process Processes.process_name Processes.user -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` count min(_time) as firstTime values(Processes.process) as process max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=*certutil* (Processes.process=*-addstore*) by Processes.parent_process Processes.process_name Processes.user +| `drop_dm_object_name("Processes")` +| `security_content_ctime(firstTime)` +|`security_content_ctime(lastTime)` | `attempt_to_add_certificate_to_untrusted_store_filter` ====Associated Analytic Story==== @@ -10057,6 +12179,16 @@ You must be ingesting data that records process activity from your hosts to popu ====Required field==== +* _time + +* Processes.process + +* Processes.process_name + +* Processes.parent_process + +* Processes.user + ====ATT&CK==== @@ -10108,10 +12240,10 @@ Monitor for changes of the ExecutionPolicy in the registry to the values "unrest ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path=*Software\\Microsoft\\Powershell\\1\\ShellIds\\Microsoft.PowerShell* Registry.registry_key_name=ExecutionPolicy (Registry.registry_value_name=Unrestricted OR Registry.registry_value_name=Bypass) by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest -| `drop_dm_object_name(Registry)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_path=*Software\\Microsoft\\Powershell\\1\\ShellIds\\Microsoft.PowerShell* Registry.registry_key_name=ExecutionPolicy (Registry.registry_value_name=Unrestricted OR Registry.registry_value_name=Bypass) by Registry.registry_path Registry.registry_key_name Registry.registry_value_name Registry.dest +| `drop_dm_object_name(Registry)` | `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` +|`security_content_ctime(lastTime)` | `attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass_filter` ====Associated Analytic Story==== @@ -10120,12 +12252,24 @@ Monitor for changes of the ExecutionPolicy in the registry to the values "unrest * [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] +* [[Documentation:ESSOC:stories:UseCase#HAFNIUM_Group|HAFNIUM Group]] + ====How To Implement==== You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Registry node. You must also be ingesting logs with the fields registry_path, registry_key_name, and registry_value_name from your endpoints. ====Required field==== +* _time + +* Registry.registry_path + +* Registry.registry_key_name + +* Registry.registry_value_name + +* Registry.dest + ====ATT&CK==== @@ -10177,12 +12321,12 @@ This search looks for attempts to stop security-related services on the endpoint ====Search==== -| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name = net.exe OR Processes.process_name = sc.exe) Processes.process="* stop *" by Processes.process_name Processes.parent_process_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -|lookup security_services_lookup service as process OUTPUTNEW category, description -| search category=security +| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name = net.exe OR Processes.process_name = sc.exe) Processes.process="* stop *" by Processes.process_name Processes.parent_process_name Processes.dest Processes.user +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +|lookup security_services_lookup service as process OUTPUTNEW category, description +| search category=security | `attempt_to_stop_security_service_filter` ====Associated Analytic Story==== @@ -10195,6 +12339,16 @@ You must be ingesting data that records the file-system activity from your hosts ====Required field==== +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + ====ATT&CK==== @@ -10246,10 +12400,10 @@ Monitor for execution of reg.exe with parameters specifying an export of keys th ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=reg.exe OR Processes.process_name=cmd.exe) Processes.process=*save* (Processes.process=*HKEY_LOCAL_MACHINE\\Security* OR Processes.process=*HKEY_LOCAL_MACHINE\\SAM* OR Processes.process=*HKEY_LOCAL_MACHINE\\System* OR Processes.process=*HKLM\\Security* OR Processes.process=*HKLM\\System* OR Processes.process=*HKLM\\SAM*) by Processes.user Processes.process_name Processes.process Processes.dest -| `drop_dm_object_name(Processes)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=reg.exe OR Processes.process_name=cmd.exe) Processes.process=*save* (Processes.process=*HKEY_LOCAL_MACHINE\\Security* OR Processes.process=*HKEY_LOCAL_MACHINE\\SAM* OR Processes.process=*HKEY_LOCAL_MACHINE\\System* OR Processes.process=*HKLM\\Security* OR Processes.process=*HKLM\\System* OR Processes.process=*HKLM\\SAM*) by Processes.user Processes.process_name Processes.process Processes.dest +| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | `attempted_credential_dump_from_registry_via_reg_exe_filter` ====Associated Analytic Story==== @@ -10262,6 +12416,14 @@ You must be ingesting endpoint data that tracks process activity, including pare ====Required field==== +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + ====ATT&CK==== @@ -10302,7 +12464,7 @@ None identified. Monitor for execution of reg.exe with parameters specifying an export of keys that contain hashed credentials that attackers may try to crack offline. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/ T1003] * '''Last Updated''': 2020-6-04 @@ -10310,13 +12472,13 @@ Monitor for execution of reg.exe with parameters specifying an export of keys th
====Search==== - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) -| eval process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null) -| where process_name="cmd.exe" OR process_name="reg.exe" -| where cmd_line != null AND match_regex(cmd_line, /(?i)save\s+/)=true AND ( match_regex(cmd_line, /(?i)HKLM\\Security/)=true OR match_regex(cmd_line, /(?i)HKLM\\SAM/)=true OR match_regex(cmd_line, /(?i)HKLM\\System/)=true OR match_regex(cmd_line, /(?i)HKEY_LOCAL_MACHINE\\Security/)=true OR match_regex(cmd_line, /(?i)HKEY_LOCAL_MACHINE\\SAM/)=true OR match_regex(cmd_line, /(?i)HKEY_LOCAL_MACHINE\\System/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend(dest_device_id, dest_user_id), body = "TBD" + +| from read_ssa_enriched_events() +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) +| eval process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null) +| where process_name="cmd.exe" OR process_name="reg.exe" +| where cmd_line != null AND match_regex(cmd_line, /(?i)save\s+/)=true AND ( match_regex(cmd_line, /(?i)HKLM\\Security/)=true OR match_regex(cmd_line, /(?i)HKLM\\SAM/)=true OR match_regex(cmd_line, /(?i)HKLM\\System/)=true OR match_regex(cmd_line, /(?i)HKEY_LOCAL_MACHINE\\Security/)=true OR match_regex(cmd_line, /(?i)HKEY_LOCAL_MACHINE\\SAM/)=true OR match_regex(cmd_line, /(?i)HKEY_LOCAL_MACHINE\\System/)=true ) +| eval start_time = timestamp, end_time = timestamp, entities = mvappend(dest_device_id, dest_user_id), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== @@ -10388,10 +12550,10 @@ This search looks for flags passed to bcdedit.exe modifications to the built-in ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = bcdedit.exe Processes.process="*recoveryenabled*" (Processes.process="* no*") by Processes.process_name Processes.process Processes.parent_process_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = bcdedit.exe Processes.process="*recoveryenabled*" (Processes.process="* no*") by Processes.process_name Processes.process Processes.parent_process_name Processes.dest Processes.user +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `bcdedit_failure_recovery_modification_filter` ====Associated Analytic Story==== @@ -10406,6 +12568,18 @@ You must be ingesting endpoint data that tracks process activity, including pare ====Required field==== +* _time + +* Processes.process_name + +* Processes.process + +* Processes.parent_process_name + +* Processes.dest + +* Processes.user + ====ATT&CK==== @@ -10457,12 +12631,12 @@ The search looks for a batch file (.bat) written to the Windows system directory ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Filesystem.dest) as dest values(Filesystem.file_name) as file_name values(Filesystem.user) as user from datamodel=Endpoint.Filesystem by Filesystem.file_path -| `drop_dm_object_name(Filesystem)` -| `security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Filesystem.dest) as dest values(Filesystem.file_name) as file_name values(Filesystem.user) as user from datamodel=Endpoint.Filesystem by Filesystem.file_path +| `drop_dm_object_name(Filesystem)` +| `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` -| rex field=file_name "(?\.[^\.]+)$" -| search file_path=*system32* AND file_extension=.bat +| rex field=file_name "(?\.[^\.]+)$" +| search file_path=*system32* AND file_extension=.bat | `batch_file_write_to_system32_filter` ====Associated Analytic Story==== @@ -10475,6 +12649,16 @@ You must be ingesting data that records the file-system activity from your hosts ====Required field==== +* _time + +* Filesystem.dest + +* Filesystem.file_name + +* Filesystem.user + +* Filesystem.file_path + ====ATT&CK==== @@ -10505,6 +12689,259 @@ It is possible for this search to generate a notable event for a batch file writ * https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1204.002/batch_file_in_system32/windows-sysmon.log +''version'': 1 +
+
+ +---- + +===Certutil download with urlcache and split arguments=== +Certutil.exe may download a file from a remote destination using `-urlcache`. This behavior does require a URL to be passed on the command-line. In addition, `-f` (force) and `-split` (Split embedded ASN.1 elements, and save to files) will be used. It is not entirely common for `certutil.exe` to contact public IP space. However, it is uncommon for `certutil.exe` to write files to world writeable paths.\ During triage, capture any files on disk and review. Review the reputation of the remote IP or domain in question. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1105/ T1105] +* '''Last Updated''': 2021-03-23 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=certutil.exe Processes.process=*urlcache* Processes.process=*split* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `certutil_download_with_urlcache_and_split_arguments_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Ingress_Tool_Transfer|Ingress Tool Transfer]] + + +====How To Implement==== +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. + +====Required field==== + +* _time + +* Processes.process + +* Processes.parent_process + +* Processes.process_name + +* Processes.user + +* Processes.dest + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1105 +| Ingress Tool Transfer +| Command and Control +|} + + +====Kill Chain Phase==== + +* Exploitation + + +====Known False Positives==== +Limited false positives in most environments, however tune as needed based on parent-child relationship or network connection. + +====Reference==== + +* https://attack.mitre.org/techniques/T1105/ + +* https://www.avira.com/en/blog/certutil-abused-by-attackers-to-spread-threats + +* https://www.fireeye.com/blog/threat-research/2019/10/certutil-qualms-they-came-to-drop-fombs.html + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-sysmon.log + + +''version'': 1 +
+
+ +---- + +===Certutil download with verifyctl and split arguments=== +Certutil.exe may download a file from a remote destination using `-VerifyCtl`. This behavior does require a URL to be passed on the command-line. In addition, `-f` (force) and `-split` (Split embedded ASN.1 elements, and save to files) will be used. It is not entirely common for `certutil.exe` to contact public IP space. \ During triage, capture any files on disk and review. Review the reputation of the remote IP or domain in question. Using `-VerifyCtl`, the file will either be written to the current working directory or `%APPDATA%\..\LocalLow\Microsoft\CryptnetUrlCache\Content\`. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1105/ T1105] +* '''Last Updated''': 2021-03-23 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=certutil.exe Processes.process=*verifyctl* Processes.process=*split* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `certutil_download_with_verifyctl_and_split_arguments_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Ingress_Tool_Transfer|Ingress Tool Transfer]] + + +====How To Implement==== +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. + +====Required field==== + +* _time + +* Processes.process + +* Processes.parent_process + +* Processes.process_name + +* Processes.user + +* Processes.dest + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1105 +| Ingress Tool Transfer +| Command and Control +|} + + +====Kill Chain Phase==== + +* Exploitation + + +====Known False Positives==== +Limited false positives in most environments, however tune as needed based on parent-child relationship or network connection. + +====Reference==== + +* https://attack.mitre.org/techniques/T1105/ + +* https://www.hexacorn.com/blog/2020/08/23/certutil-one-more-gui-lolbin/ + +* https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2012-R2-and-2012/cc732443(v=ws.11)#-verifyctl + +* https://www.avira.com/en/blog/certutil-abused-by-attackers-to-spread-threats + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1105/atomic_red_team/windows-sysmon.log + + +''version'': 1 +
+
+ +---- + +===Certutil with decode argument=== +CertUtil.exe may be used to `encode` and `decode` a file, including PE and script code. Encoding will convert a file to base64 with `-----BEGIN CERTIFICATE-----` and `-----END CERTIFICATE-----` tags. Malicious usage will include decoding a encoded file that was downloaded. Once decoded, it will be loaded by a parallel process. Note that there are two additional command switches that may be used - `encodehex` and `decodehex`. Similarly, the file will be encoded in HEX and later decoded for further execution. During triage, identify the source of the file being decoded. Review its contents or execution behavior for further analysis. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1140/ T1140] +* '''Last Updated''': 2021-03-23 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=certutil.exe Processes.process=*decode* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `certutil_with_decode_argument_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Deobfuscate-Decode_Files_or_Information|Deobfuscate-Decode Files or Information]] + + +====How To Implement==== +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. + +====Required field==== + +* _time + +* Processes.process + +* Processes.parent_process + +* Processes.process_name + +* Processes.user + +* Processes.dest + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1140 +| Deobfuscate/Decode Files or Information +| Defense Evasion +|} + + +====Kill Chain Phase==== + +* Exploitation + + +====Known False Positives==== +Typically seen used to `encode` files, but it is possible to see legitimate use of `decode`. Filter based on parent-child relationship, file paths, endpoint or user. + +====Reference==== + +* https://attack.mitre.org/techniques/T1140/ + +* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1140/T1140.md + +* https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/certutil + +* https://www.bleepingcomputer.com/news/security/certutilexe-could-allow-attackers-to-download-malware-while-bypassing-av/ + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1140/atomic_red_team/windows-sysmon.log + + ''version'': 1
@@ -10516,7 +12953,7 @@ This search looks for arguments to certutil.exe indicating the manipulation or e * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': +* '''ATT&CK''': * '''Last Updated''': 2021-01-26
@@ -10524,10 +12961,10 @@ This search looks for arguments to certutil.exe indicating the manipulation or e ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime values(Processes.process) as process max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=certutil.exe Processes.process = "* -exportPFX *" by Processes.parent_process Processes.process_name Processes.process Processes.user -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` count min(_time) as firstTime values(Processes.process) as process max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=certutil.exe Processes.process = "* -exportPFX *" by Processes.parent_process Processes.process_name Processes.process Processes.user +| `drop_dm_object_name("Processes")` +| `security_content_ctime(firstTime)` +|`security_content_ctime(lastTime)` | `certutil_exe_certificate_extraction_filter` ====Associated Analytic Story==== @@ -10542,6 +12979,16 @@ This search looks for arguments to certutil.exe indicating the manipulation or e ====Required field==== +* _time + +* Processes.process + +* Processes.process_name + +* Processes.parent_process + +* Processes.user + @@ -10580,10 +13027,10 @@ This search looks for child processes of spoolsv.exe. This activity is associate ====Search==== -| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=spoolsv.exe AND Processes.process_name!=regsvr32.exe by Processes.dest Processes.parent_process Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=spoolsv.exe AND Processes.process_name!=regsvr32.exe by Processes.dest Processes.parent_process Processes.user +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `child_processes_of_spoolsv_exe_filter` ====Associated Analytic Story==== @@ -10596,6 +13043,22 @@ You must be ingesting endpoint data that tracks process activity, including pare ====Required field==== +* _time + +* Processes.process_name + +* Processes.process + +* Processes.parent_process_name + +* Processes.process_name + +* Processes.dest + +* Processes.parent_process + +* Processes.user + ====ATT&CK==== @@ -10630,6 +13093,261 @@ Some legitimate printer-related processes may show up as children of spoolsv.exe ---- +===Clop common exec parameter=== +The following analytics are designed to identifies some CLOP ransomware variant that using arguments to execute its main code or feature of its code. In this variant if the parameter is "runrun", CLOP ransomware will try to encrypt files in network shares and if it is "temp.dat", it will try to read from some stream pipe or file start encrypting files within the infected local machines. This technique can be also identified as an anti-sandbox technique to make its code non-responsive since it is waiting for some parameter to execute properly. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1204/ T1204] +* '''Last Updated''': 2021-03-17 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` values(Processes.process) as cmdline values(Processes.parent_process_name) as parent_process values(Processes.process_name) count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process = "*runrun*" OR Processes.process = "*temp.dat*" by Processes.parent_process_name Processes.process_name Processes.process Processes.dest Processes.user Processes.process_id Processes.process_guid +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `clop_common_exec_parameter_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Clop_Ransomware|Clop Ransomware]] + + +====How To Implement==== +To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. + +====Required field==== + +* Processes.process + +* Processes.parent_process_name + +* _time + +* Processes.process_name + +* Processes.dest + +* Processes.user + +* Processes.process_id + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1204 +| User Execution +| Execution +|} + + +====Kill Chain Phase==== + +* Obfuscation + + +====Known False Positives==== +Operators can execute third party tools using these parameters. + +====Reference==== + +* https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html + +* https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_b/windows-sysmon.log + + +''version'': 1 +
+
+ +---- + +===Clop ransomware known service name=== +This detection is to identify the common service name created by the CLOP ransomware as part of its persistence and high privilege code execution in the infected machine. Ussually CLOP ransomware use StartServiceCtrlDispatcherW API in creating this service entry. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1543/ T1543] +* '''Last Updated''': 2021-03-17 + +
+
+ +====Search==== +`wineventlog_system` EventCode=7045 Service_Name IN ("SecurityCenterIBM", "WinCheckDRVs") +| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Service_File_Name Service_Name Service_Start_Type Service_Type +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `clop_ransomware_known_service_name_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Clop_Ransomware|Clop Ransomware]] + + +====How To Implement==== +To successfully implement this search, you need to be ingesting logs with the Service name, Service File Name Service Start type, and Service Type from your endpoints. + +====Required field==== + +* EventCode + +* cmdline + +* _time + +* parent_process_name + +* process_name + +* OriginalFileName + +* process_path + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1543 +| Create or Modify System Process +| Persistence, Privilege Escalation +|} + + +====Kill Chain Phase==== + +* Privilege Escalation + + +====Known False Positives==== +unknown + +====Reference==== + +* https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html + +* https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-system.log + + +''version'': 1 +
+
+ +---- + +===Cobalt strike named pipes=== +The following analytic identifies the use of default or publicly known named pipes used with Cobalt Strike. A named pipe is a named, one-way or duplex pipe for communication between the pipe server and one or more pipe clients. Cobalt Strike uses named pipes in many ways and has default values used with the Artifact Kit and Malleable C2 Profiles. The following query assists with identifying these default named pipes. Each EDR product presents named pipes a little different. Consider taking the values and generating a query based on the product of choice. \ +Upon triage, review the process performing the named pipe. If it is explorer.exe, It is possible it was injected into by another process. Review recent parallel processes to identify suspicious patterns or behaviors. A parallel process may have a network connection, review and follow the connection back to identify any file modifications. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1055/ T1055] +* '''Last Updated''': 2021-02-22 + +
+
+ +====Search==== +`sysmon` EventID=17 OR EventID=18 PipeName IN (\\msagent_*, \\wkssvc*, \\DserNamePipe*, \\srvsvc_*, \\mojo.*, \\postex_*, \\status_*, \\MSSE-*, \\spoolss_*, \\win_svc*, \\ntsvcs*, \\winsock*) +| stats count min(_time) as firstTime max(_time) as lastTime by Computer, process_name, process_id process_path, PipeName +| rename Computer as dest +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `cobalt_strike_named_pipes_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Cobalt_Strike|Cobalt Strike]] + + +====How To Implement==== +To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. + +====Required field==== + +* _time + +* EventID + +* PipeName + +* Computer + +* process_name + +* process_path + +* process_id + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1055 +| Process Injection +| Defense Evasion, Privilege Escalation +|} + + +====Kill Chain Phase==== + +* Actions on Objectives + + +====Known False Positives==== +The idea of using named pipes with Cobalt Strike is to blend in. Therefore, some of the named pipes identified and added may cause false positives. Filter by process name or pipe name to reduce false positives. + +====Reference==== + +* https://attack.mitre.org/techniques/T1218/009/ + +* https://docs.microsoft.com/en-us/windows/win32/ipc/named-pipes + +* https://www.cobaltstrike.com/help-smb-beacon + +* https://blog.cobaltstrike.com/2021/02/09/learn-pipe-fitting-for-all-of-your-offense-projects/ + +* https://gist.github.com/MHaggis/6c600e524045a6d49c35291a21e10752 + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log + + +''version'': 1 +
+
+ +---- + ===Common ransomware extensions=== The search looks for file modifications with extensions commonly used by Ransomware @@ -10643,22 +13361,24 @@ The search looks for file modifications with extensions commonly used by Ransomw ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Filesystem.user) as user values(Filesystem.dest) as dest values(Filesystem.file_path) as file_path from datamodel=Endpoint.Filesystem by Filesystem.file_name -| `drop_dm_object_name(Filesystem)` -| `security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Filesystem.user) as user values(Filesystem.dest) as dest values(Filesystem.file_path) as file_path from datamodel=Endpoint.Filesystem by Filesystem.file_name +| `drop_dm_object_name(Filesystem)` +| `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` -| rex field=file_name "(?\.[^\.]+)$" -| `ransomware_extensions` +| rex field=file_name "(?\.[^\.]+)$" +| `ransomware_extensions` | `common_ransomware_extensions_filter` ====Associated Analytic Story==== * [[Documentation:ESSOC:stories:UseCase#SamSam_Ransomware|SamSam Ransomware]] -* [[Documentation:ESSOC:stories:UseCase#Ryuk_Ransonware|Ryuk Ransonware]] +* [[Documentation:ESSOC:stories:UseCase#Ryuk_Ransomware|Ryuk Ransomware]] * [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] +* [[Documentation:ESSOC:stories:UseCase#Clop_Ransomware|Clop Ransomware]] + ====How To Implement==== You must be ingesting data that records the filesystem activity from your hosts to populate the Endpoint file-system data model node. If you are using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which you want to collect data.\ @@ -10669,6 +13389,16 @@ Detailed documentation on how to create a new field within Incident Review may b ====Required field==== +* _time + +* Filesystem.user + +* Filesystem.dest + +* Filesystem.file_path + +* Filesystem.file_name + ====ATT&CK==== @@ -10718,11 +13448,11 @@ The search looks for files created with names matching those typically used in r ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Filesystem.user) as user values(Filesystem.dest) as dest values(Filesystem.file_path) as file_path from datamodel=Endpoint.Filesystem by Filesystem.file_name -| `drop_dm_object_name(Filesystem)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `ransomware_notes` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Filesystem.user) as user values(Filesystem.dest) as dest values(Filesystem.file_path) as file_path from datamodel=Endpoint.Filesystem by Filesystem.file_name +| `drop_dm_object_name(Filesystem)` +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` +| `ransomware_notes` | `common_ransomware_notes_filter` ====Associated Analytic Story==== @@ -10733,12 +13463,24 @@ The search looks for files created with names matching those typically used in r * [[Documentation:ESSOC:stories:UseCase#Ryuk_Ransomware|Ryuk Ransomware]] +* [[Documentation:ESSOC:stories:UseCase#Clop_Ransomware|Clop Ransomware]] + ====How To Implement==== You must be ingesting data that records file-system activity from your hosts to populate the Endpoint Filesystem data-model node. This is typically populated via endpoint detection-and-response product, such as Carbon Black, or via other endpoint data sources, such as Sysmon. The data used for this search is typically generated via logs that report file-system reads and writes. ====Required field==== +* _time + +* Filesystem.user + +* Filesystem.dest + +* Filesystem.file_path + +* Filesystem.file_name + ====ATT&CK==== @@ -10779,7 +13521,7 @@ It's possible that a legitimate file could be created with the same name used by Detect remote thread creation into LSASS consistent with credential dumping. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1003.001/ T1003.001] * '''Last Updated''': 2019-12-06 @@ -10787,11 +13529,11 @@ Detect remote thread creation into LSASS consistent with credential dumping.
====Search==== -`sysmon` EventID=8 TargetImage=*lsass.exe -| stats count min(_time) as firstTime max(_time) as lastTime by Computer, EventCode, TargetImage, TargetProcessId -| rename Computer as dest +`sysmon` EventID=8 TargetImage=*lsass.exe +| stats count min(_time) as firstTime max(_time) as lastTime by Computer, EventCode, TargetImage, TargetProcessId +| rename Computer as dest | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | `create_remote_thread_into_lsass_filter` ====Associated Analytic Story==== @@ -10804,6 +13546,20 @@ This search needs Sysmon Logs with a Sysmon configuration, which includes EventC ====Required field==== +* _time + +* EventID + +* TargetImage + +* Computer + +* EventCode + +* TargetImage + +* TargetProcessId + ====ATT&CK==== @@ -10836,6 +13592,86 @@ Other tools can access LSASS for legitimate reasons and generate an event. In th * https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon.log +''version'': 1 +
+
+ +---- + +===Create service in suspicious file path=== +This detection is to identify a creation of "user mode service" where the service file path is located in non-common service folder in windows. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques// ] +* '''Last Updated''': 2021-03-12 + +
+
+ +====Search==== + `wineventlog_system` EventCode=7045 Service_File_Name = "*\.exe" NOT (Service_File_Name IN ("C:\\Windows\\*", "C:\\Program File*", "C:\\Programdata\\*", "%systemroot%\\*")) Service_Type = "user mode service" +| stats count min(_time) as firstTime max(_time) as lastTime by EventCode Service_File_Name Service_Name Service_Start_Type Service_Type +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `create_service_in_suspicious_file_path_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Clop_Ransomware|Clop Ransomware]] + + +====How To Implement==== +To successfully implement this search, you need to be ingesting logs with the Service name, Service File Name Service Start type, and Service Type from your endpoints. + +====Required field==== + +* EventCode + +* Service_File_Name + +* Service_Type + +* _time + +* Service_Name + +* Service_Start_Type + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| +| +| +|} + + +====Kill Chain Phase==== + +* Privilege Escalation + + +====Known False Positives==== +unknown + +====Reference==== + +* https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html + +* https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-system.log + + ''version'': 1
@@ -10855,10 +13691,10 @@ This search looks for the creation of local administrator accounts using net.exe ====Search==== -| tstats `security_content_summariesonly` count values(Processes.user) as user values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=net.exe OR Processes.process_name=net1.exe) AND (Processes.process=*localgroup* OR Processes.process=*/add* OR Processes.process=*user*) by Processes.process Processes.process_name Processes.dest -| `drop_dm_object_name(Processes)` +| tstats `security_content_summariesonly` count values(Processes.user) as user values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=net.exe OR Processes.process_name=net1.exe) AND (Processes.process=*localgroup* OR Processes.process=*/add* OR Processes.process=*user*) by Processes.process Processes.process_name Processes.dest +| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` |`create_local_admin_accounts_using_net_exe_filter` ====Associated Analytic Story==== @@ -10871,6 +13707,18 @@ You must be ingesting data that records process activity from your hosts to popu ====Required field==== +* _time + +* Processes.user + +* Processes.parent_process + +* Processes.process_name + +* Processes.process + +* Processes.dest + ====ATT&CK==== @@ -10924,11 +13772,11 @@ This search looks for the creation or deletion of hidden shares using net.exe. ====Search==== -| tstats `security_content_summariesonly` count values(Processes.user) as user values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processs.process_name=net.exe OR Processes.process_name=net1.exe) by Processes.process Processes.process_name Processes.dest -| `drop_dm_object_name(Processes)` +| tstats `security_content_summariesonly` count values(Processes.user) as user values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processs.process_name=net.exe OR Processes.process_name=net1.exe) by Processes.process Processes.process_name Processes.dest +| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| search process=*share* +| `security_content_ctime(lastTime)` +| search process=*share* | `create_or_delete_windows_shares_using_net_exe_filter` ====Associated Analytic Story==== @@ -10941,6 +13789,18 @@ You must be ingesting data that records process activity from your hosts to popu ====Required field==== +* _time + +* Processes.user + +* Processes.parent_process + +* Processs.process_name + +* Processes.process + +* Processes.dest + ====ATT&CK==== @@ -10992,10 +13852,10 @@ Monitor for signs that Vssadmin or Wmic has been used to create a shadow copy. ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=vssadmin.exe Processes.process=*create* Processes.process=*shadow*) OR (Processes.process_name=wmic.exe Processes.process=*shadowcopy* Processes.process=*create*) by Processes.dest Processes.user Processes.process_name Processes.process Processes.parent_process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=vssadmin.exe Processes.process=*create* Processes.process=*shadow*) OR (Processes.process_name=wmic.exe Processes.process=*shadowcopy* Processes.process=*create*) by Processes.dest Processes.user Processes.process_name Processes.process Processes.parent_process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | `creation_of_shadow_copy_filter` ====Associated Analytic Story==== @@ -11008,6 +13868,22 @@ You must be ingesting endpoint data that tracks process activity, including pare ====Required field==== +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_id + +* Processes.parent_process_id + ====ATT&CK==== @@ -11059,10 +13935,10 @@ This search detects the use of wmic and Powershell to create a shadow copy. ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=wmic* OR Processes.process_name=powershell* Processes.process=*shadowcopy* Processes.process=*create* by Processes.user Processes.process_name Processes.process Processes.dest -| `drop_dm_object_name(Processes)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=wmic* OR Processes.process_name=powershell* Processes.process=*shadowcopy* Processes.process=*create* by Processes.user Processes.process_name Processes.process Processes.dest +| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | `creation_of_shadow_copy_with_wmic_and_powershell_filter` ====Associated Analytic Story==== @@ -11075,6 +13951,16 @@ To successfully implement this search you need to be ingesting information on pr ====Required field==== +* _time + +* Processes.process_name + +* Processes.process + +* Processes.user + +* Processes.dest + ====ATT&CK==== @@ -11117,7 +14003,7 @@ Legtimate administrator usage of wmic to create a shadow copy. Detect the hands on keyboard behavior of Windows Task Manager creating a prcoess dump of lsass.exe. Upon this behavior occurring, a file write/modification will occur in the users profile under \AppData\Local\Temp. The dump file, lsass.dmp, cannot be renamed, however if the dump occurs more than once, it will be named lsass (2).dmp. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1003.001/ T1003.001] * '''Last Updated''': 2020-02-03 @@ -11125,11 +14011,11 @@ Detect the hands on keyboard behavior of Windows Task Manager creating a prcoess
====Search==== -`sysmon` EventID=11 process_name=taskmgr.exe TargetFilename=*lsass*.dmp -| stats count min(_time) as firstTime max(_time) as lastTime by Computer, object_category, process_name, TargetFilename -| rename Computer as dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +`sysmon` EventID=11 process_name=taskmgr.exe TargetFilename=*lsass*.dmp +| stats count min(_time) as firstTime max(_time) as lastTime by Computer, object_category, process_name, TargetFilename +| rename Computer as dest +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `creation_of_lsass_dump_with_taskmgr_filter` ====Associated Analytic Story==== @@ -11142,6 +14028,18 @@ This search requires Sysmon Logs and a Sysmon configuration, which includes Even ====Required field==== +* _time + +* EventID + +* process_name + +* TargetFilename + +* Computer + +* object_category + ====ATT&CK==== @@ -11197,10 +14095,10 @@ This search detects credential dumping using copy command from a shadow copy. ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=cmd.exe (Processes.process=*\\system32\\config\\sam* OR Processes.process=*\\system32\\config\\security* OR Processes.process=*\\system32\\config\\system* OR Processes.process=*\\windows\\ntds\\ntds.dit*) by Processes.dest Processes.user Processes.process_name Processes.process Processes.parent_process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=cmd.exe (Processes.process=*\\system32\\config\\sam* OR Processes.process=*\\system32\\config\\security* OR Processes.process=*\\system32\\config\\system* OR Processes.process=*\\windows\\ntds\\ntds.dit*) by Processes.dest Processes.user Processes.process_name Processes.process Processes.parent_process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | `credential_dumping_via_copy_command_from_shadow_copy_filter` ====Associated Analytic Story==== @@ -11213,6 +14111,22 @@ You must be ingesting endpoint data that tracks process activity, including pare ====Required field==== +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_id + +* Processes.parent_process_id + ====ATT&CK==== @@ -11264,10 +14178,10 @@ This search detects the creation of a symlink to a shadow copy. ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=cmd.exe Processes.process=*mklink* Processes.process=*HarddiskVolumeShadowCopy* by Processes.dest Processes.user Processes.process_name Processes.process Processes.parent_process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=cmd.exe Processes.process=*mklink* Processes.process=*HarddiskVolumeShadowCopy* by Processes.dest Processes.user Processes.process_name Processes.process Processes.parent_process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | `credential_dumping_via_symlink_to_shadow_copy_filter` ====Associated Analytic Story==== @@ -11280,6 +14194,22 @@ You must be ingesting endpoint data that tracks process activity, including pare ====Required field==== +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_id + +* Processes.parent_process_id + ====ATT&CK==== @@ -11322,7 +14252,7 @@ unknown Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. FGdump is a newer version of pwdump tool that extracts NTLM and LanMan password hashes from Windows. Cachedump is a publicly-available tool that extracts cached password hashes from a system's registry. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/ T1003] * '''Last Updated''': 2020-10-18 @@ -11330,17 +14260,21 @@ Credential extraction is often an illegal recovery of credential material from s
====Search==== - + | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null) | where cmd_line != null AND process_name != null AND parent_process_name != null AND match_regex(parent_process_name, /(?i)System32\\services.exe/)=true AND match_regex(process_name, /(?i)cachedump\d{0,2}.exe/)=true AND match_regex(process_path, /(?i)\\Temp/)=true AND match_regex(cmd_line, /(?i)\-s/)=true -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Unusual_Processes|Unusual Processes]] + +* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -11388,6 +14322,8 @@ None identified. ====Test Dataset==== +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logFgdump.log + ''version'': 1
@@ -11399,7 +14335,7 @@ None identified. Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. FGdump is a newer version of pwdump tool that extracts NTLM and LanMan password hashes from Windows. Cachedump is a publicly-available tool that extracts cached password hashes from a system's registry. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/ T1003] * '''Last Updated''': 2020-10-18 @@ -11407,17 +14343,21 @@ Credential extraction is often an illegal recovery of credential material from s
====Search==== - + | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null) | where cmd_line != null AND process_name != null AND process_path != null AND match_regex(process_name, /(?i)cachedump\d{0,2}.exe/)=true AND match_regex(process_path, /(?i)\\Temp/)=true AND match_regex(cmd_line, /(?i)\-v/)=true -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Unusual_Processes|Unusual Processes]] + +* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -11463,6 +14403,8 @@ None identified. ====Test Dataset==== +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logFgdump.log + ''version'': 1
@@ -11474,7 +14416,7 @@ None identified. Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. LaZagne is a tool that extracts various kinds of credentials from a local computer, including account passwords, domain passwords, browser passwords, etc. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/ T1003], [https://attack.mitre.org/techniques/T1555/ T1555] * '''Last Updated''': 2020-10-18 @@ -11482,17 +14424,19 @@ Credential extraction is often an illegal recovery of credential material from s
====Search==== - + | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) | where cmd_line != null AND match_regex(cmd_line, /(?i)all\s+\-oA\s+\-output/)=true -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -11538,6 +14482,8 @@ None identified. ====Test Dataset==== +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logLazagneCredDump.log + ''version'': 1
@@ -11549,7 +14495,7 @@ None identified. Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. DSInternals is a collection of PowerShell modules commonly employed in exploits. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/ T1003] * '''Last Updated''': 2020-10-21 @@ -11560,14 +14506,18 @@ Credential extraction is often an illegal recovery of credential material from s | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), cmd_line=ucast(map_get(input_event, "process"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), cmd_line=ucast(map_get(input_event, "process"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, /(?i)ConvertFrom-ADManagedPasswordBlob/)=true OR match_regex(cmd_line, /(?i)ConvertFrom-GPPrefPassword/)=true OR match_regex(cmd_line, /(?i)ConvertFrom-UnicodePassword/)=true OR match_regex(cmd_line, /(?i)ConvertTo-GPPrefPassword/)=true OR match_regex(cmd_line, /(?i)ConvertTo-KerberosKey/)=true OR match_regex(cmd_line, /(?i)ConvertTo-LMHash/)=true OR match_regex(cmd_line, /(?i)ConvertTo-NTHash/)=true OR match_regex(cmd_line, /(?i)ConvertTo-OrgIdHash/)=true OR match_regex(cmd_line, /(?i)ConvertTo-UnicodePassword/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] + +* [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -11617,6 +14567,8 @@ None identified. ====Test Dataset==== +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllDSInternalsModules.log + ''version'': 1
@@ -11628,7 +14580,7 @@ None identified. Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. DSInternals is a collection of PowerShell modules commonly employed in exploits. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/ T1003] * '''Last Updated''': 2020-10-21 @@ -11639,14 +14591,18 @@ Credential extraction is often an illegal recovery of credential material from s | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), cmd_line=ucast(map_get(input_event, "process"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), cmd_line=ucast(map_get(input_event, "process"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, /(?i)Get-ADDBBackupKey/)=true OR match_regex(cmd_line, /(?i)Get-ADDBDomainController/)=true OR match_regex(cmd_line, /(?i)Get-ADDBKdsRootKey/)=true OR match_regex(cmd_line, /(?i)Get-ADDBSchemaAttribute/)=true OR match_regex(cmd_line, /(?i)Get-ADKeyCredential/)=true OR match_regex(cmd_line, /(?i)Get-ADReplAccount/)=true OR match_regex(cmd_line, /(?i)Get-ADReplBackupKey/)=true OR match_regex(cmd_line, /(?i)Get-ADSIAccount/)=true OR match_regex(cmd_line, /(?i)Get-AzureADUserEx/)=true OR match_regex(cmd_line, /(?i)Get-BootKey/)=true OR match_regex(cmd_line, /(?i)Get-LsaBackupKey/)=true OR match_regex(cmd_line, /(?i)Get-LsaPolicyInformation/)=true OR match_regex(cmd_line, /(?i)Get-SamPasswordPolicy/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] + +* [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -11696,6 +14652,8 @@ None identified. ====Test Dataset==== +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllDSInternalsModules.log + ''version'': 1
@@ -11707,7 +14665,7 @@ None identified. Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. Mimikatz is a collection of tools and modules commonly employed in Windows exploits. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/ T1003] * '''Last Updated''': 2020-10-21 @@ -11718,14 +14676,18 @@ Credential extraction is often an illegal recovery of credential material from s | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, /(?i)CRYPTO::Certificates/)=true OR match_regex(cmd_line, /(?i)CRYPTO::keys/)=true OR match_regex(cmd_line, /(?i)kerberos::list/)=true OR match_regex(cmd_line, /(?i)kerberos::tgt/)=true OR match_regex(cmd_line, /(?i)lsadump::sam/)=true OR match_regex(cmd_line, /(?i)lsadump::secrets/)=true OR match_regex(cmd_line, /(?i)lsadump::cache/)=true OR match_regex(cmd_line, /(?i)lsadump::lsa/)=true OR match_regex(cmd_line, /(?i)lsadump::trust/)=true OR match_regex(cmd_line, /(?i)lsadump::backupkeys/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] + +* [[Documentation:ESSOC:stories:UseCase#Unusual_Processes|Unusual Processes]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -11769,6 +14731,8 @@ None identified. ====Test Dataset==== +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllMimikatzModules.log + ''version'': 1
@@ -11780,7 +14744,7 @@ None identified. Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. PowerSploit is a collection of Microsoft PowerShell modules commonly employed in exploits. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/ T1003] * '''Last Updated''': 2020-10-21 @@ -11791,14 +14755,18 @@ Credential extraction is often an illegal recovery of credential material from s | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, /(?i)Get-ApplicationHost/)=true OR match_regex(cmd_line, /(?i)Get-CachedGPPPassword/)=true OR match_regex(cmd_line, /(?i)Get-GPPAutologon/)=true OR match_regex(cmd_line, /(?i)Get-GPPPassword/)=true OR match_regex(cmd_line, /(?i)Get-RegistryAutoLogon/)=true OR match_regex(cmd_line, /(?i)Get-SiteListPassword/)=true OR match_regex(cmd_line, /(?i)Get-SPNTicket/)=true OR match_regex(cmd_line, /(?i)Request-SPNTicket/)=true OR match_regex(cmd_line, /(?i)Get-VaultCredential/)=true OR match_regex(cmd_line, /(?i)Invoke-Kerberoast/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] + +* [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -11842,6 +14810,8 @@ None identified. ====Test Dataset==== +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logAllPowerSploitModulesWithOldNames.log + ''version'': 1
@@ -11853,7 +14823,7 @@ None identified. Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. Native Microsoft debuggers, such as kd, ntkd, livekd and windbg, can be leveraged to read credential material directly from memory and process dumps. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/ T1003] * '''Last Updated''': 2020-10-18 @@ -11861,17 +14831,21 @@ Credential extraction is often an illegal recovery of credential material from s
====Search==== - + | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null) | where cmd_line != null AND parent_process_name != null AND process_name != null AND ( match_regex(parent_process_name, /(?i)ntkd\.exe/)=true OR match_regex(parent_process_name, /(?i)livekd\.exe/)=true ) AND match_regex(process_name, /(?i)conhost\.exe/)=true AND match_regex(cmd_line, /(?i)0xffffffff/)=true AND match_regex(cmd_line, /(?i)\-ForceV1/)=true -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] + +* [[Documentation:ESSOC:stories:UseCase#Unusual_Processes|Unusual Processes]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -11919,6 +14893,8 @@ Although unlikely, using debuggers this way may be indicative of developers anal ====Test Dataset==== +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logLiveKDFullKernelDump.log + ''version'': 1
@@ -11930,7 +14906,7 @@ Although unlikely, using debuggers this way may be indicative of developers anal Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. Native Microsoft debuggers, such as kd, ntkd, livekd and windbg, can be leveraged to read credential material directly from memory and process dumps. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/ T1003] * '''Last Updated''': 2020-10-18 @@ -11938,17 +14914,21 @@ Credential extraction is often an illegal recovery of credential material from s
====Search==== - + | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null) | where cmd_line != null AND process_name != null AND ( match_regex(process_name, /^(?i)ntkd\.exe/)=true OR match_regex(process_name, /^(?i)kd\.exe/)=true ) AND match_regex(cmd_line, /(?i)\-z\s+/)=true -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] + +* [[Documentation:ESSOC:stories:UseCase#Unusual_Processes|Unusual Processes]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -11992,6 +14972,8 @@ Although unlikely, using debuggers this way may be indicative of developers anal ====Test Dataset==== +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logLiveKDFullKernelDump.log + ''version'': 1
@@ -12003,7 +14985,7 @@ Although unlikely, using debuggers this way may be indicative of developers anal Credential extraction is often an illegal recovery of credential material from secured authentication resources and repositories. This process may also involve decryption or other transformations of the stored credential material. PowerSploit and DSInternals are common exploit APIs offering PowerShell modules for various exploits of Windows and Active Directory environments. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/ T1003] * '''Last Updated''': 2020-10-18 @@ -12011,18 +14993,22 @@ Credential extraction is often an illegal recovery of credential material from s
====Search==== - + | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) | where cmd_line != null AND match_regex(cmd_line, /(?i)Get-ADDBAccount/)=true AND match_regex(cmd_line, /(?i)\-dbpath[\s;:\.\ |]+/)=true -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] + +* [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -12064,6 +15050,8 @@ None identified. ====Test Dataset==== +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003/credential_extraction/logPowerShellModule.log + ''version'': 1
@@ -12084,10 +15072,10 @@ The vssadmin.exe utility is used to interact with the Volume Shadow Copy Service ====Search==== -| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=vssadmin.exe OR Processes.process_name=wmic.exe) Processes.process=*delete* Processes.process=*shadow* by Processes.user Processes.process_name Processes.parent_process_name Processes.dest -| `drop_dm_object_name(Processes)` +| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=vssadmin.exe OR Processes.process_name=wmic.exe) Processes.process=*delete* Processes.process=*shadow* by Processes.user Processes.process_name Processes.parent_process_name Processes.dest +| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | `deleting_shadow_copies_filter` ====Associated Analytic Story==== @@ -12098,12 +15086,28 @@ The vssadmin.exe utility is used to interact with the Volume Shadow Copy Service * [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] +* [[Documentation:ESSOC:stories:UseCase#Clop_Ransomware|Clop Ransomware]] + ====How To Implement==== You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" field in the Endpoint data model. ====Required field==== +* _time + +* Processes.process + +* Processes.parent_process + +* Processes.process_name + +* Processes.user + +* Processes.parent_process_name + +* Processes.dest + ====ATT&CK==== @@ -12144,7 +15148,7 @@ vssadmin.exe and wmic.exe are standard applications shipped with modern versions This search looks for specific authentication events from the Windows Security Event logs to detect potential attempts at using the Pass-the-Hash technique. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1550.002/ T1550.002] * '''Last Updated''': 2020-10-15 @@ -12152,11 +15156,11 @@ This search looks for specific authentication events from the Windows Security E
====Search==== -`wineventlog_security` EventCode=4624 (Logon_Type=3 Logon_Process=NtLmSsp WorkstationName=WORKSTATION NOT AccountName="ANONYMOUS LOGON") OR (Logon_Type=9 Logon_Process=seclogo) -| fillnull -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode, Logon_Type, WorkstationName, user, dest +`wineventlog_security` EventCode=4624 (Logon_Type=3 Logon_Process=NtLmSsp WorkstationName=WORKSTATION NOT AccountName="ANONYMOUS LOGON") OR (Logon_Type=9 Logon_Process=seclogo) +| fillnull +| stats count min(_time) as firstTime max(_time) as lastTime by EventCode, Logon_Type, WorkstationName, user, dest | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | `detect_activity_related_to_pass_the_hash_attacks_filter` ====Associated Analytic Story==== @@ -12169,6 +15173,20 @@ To successfully implement this search, you must ingest your Windows Security Eve ====Required field==== +* _time + +* EventCode + +* Logon_Type + +* Logon_Process + +* WorkstationName + +* user + +* dest + ====ATT&CK==== @@ -12209,7 +15227,7 @@ Legitimate logon activity by authorized NTLM systems may be detected by this sea This search detects the heap-based buffer overflow of sudoedit * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1068/ T1068] * '''Last Updated''': 2021-01-27 @@ -12217,8 +15235,8 @@ This search detects the heap-based buffer overflow of sudoedit
====Search==== -`linux_hosts` -| search "sudoedit -s \\" +`linux_hosts` +| search "sudoedit -s \\" | `detect_baron_samedit_cve_2021_3156_filter` ====Associated Analytic Story==== @@ -12231,6 +15249,8 @@ Splunk Universal Forwarder running on Linux systems, capturing logs from the /va ====Required field==== +* _time + ====ATT&CK==== @@ -12271,7 +15291,7 @@ unknown This search detects the heap-based buffer overflow of sudoedit * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1068/ T1068] * '''Last Updated''': 2021-01-29 @@ -12279,10 +15299,10 @@ This search detects the heap-based buffer overflow of sudoedit
====Search==== -`linux_hosts` -| search sudoedit segfault -| stats count min(_time) as firstTime max(_time) as lastTime by host -| search count > 5 +`linux_hosts` +| search sudoedit segfault +| stats count min(_time) as firstTime max(_time) as lastTime by host +| search count > 5 | `detect_baron_samedit_cve_2021_3156_segfault_filter` ====Associated Analytic Story==== @@ -12295,6 +15315,10 @@ Splunk Universal Forwarder running on Linux systems (tested on Centos and Ubuntu ====Required field==== +* _time + +* host + ====ATT&CK==== @@ -12335,7 +15359,7 @@ If sudoedit is throwing segfaults for other reasons this will pick those up too. This search detects the heap-based buffer overflow of sudoedit * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1068/ T1068] * '''Last Updated''': 2021-01-28 @@ -12343,8 +15367,8 @@ This search detects the heap-based buffer overflow of sudoedit
====Search==== -`osquery_process` -| search "columns.cmdline"="sudoedit -s \\*" +`osquery_process` +| search "columns.cmdline"="sudoedit -s \\*" | `detect_baron_samedit_cve_2021_3156_via_osquery_filter` ====Associated Analytic Story==== @@ -12357,6 +15381,10 @@ OSQuery installed and configured to pick up process events (info at https://osqu ====Required field==== +* _time + +* columns.cmdline + ====ATT&CK==== @@ -12397,7 +15425,7 @@ unknown This search looks for Event Code 4742 (Computer Change) or EventCode 4624 (An account was successfully logged on) with an anonymous account. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1210/ T1210] * '''Last Updated''': 2020-09-18 @@ -12405,8 +15433,8 @@ This search looks for Event Code 4742 (Computer Change) or EventCode 4624 (An ac
====Search==== -`wineventlog_security` EventCode=4624 OR EventCode=4742 TargetUserName="ANONYMOUS LOGON" LogonType=3 -| stats count values(host) as host, values(TargetDomainName) as Domain, values(user) as user +`wineventlog_security` EventCode=4624 OR EventCode=4742 TargetUserName="ANONYMOUS LOGON" LogonType=3 +| stats count values(host) as host, values(TargetDomainName) as Domain, values(user) as user | `detect_computer_changed_with_anonymous_account_filter` ====Associated Analytic Story==== @@ -12419,6 +15447,18 @@ This search requires audit computer account management to be enabled on the syst ====Required field==== +* _time + +* EventCode + +* TargetUserName + +* LogonType + +* TargetDomainName + +* user + ====ATT&CK==== @@ -12459,7 +15499,7 @@ None thus far found This search looks for reading lsass memory consistent with credential dumping. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1003.001/ T1003.001] * '''Last Updated''': 2019-12-03 @@ -12467,11 +15507,11 @@ This search looks for reading lsass memory consistent with credential dumping.
====Search==== -`sysmon` EventCode=10 TargetImage=*lsass.exe (GrantedAccess=0x1010 OR GrantedAccess=0x1410) -| stats count min(_time) as firstTime max(_time) as lastTime by Computer, SourceImage, SourceProcessId, TargetImage, TargetProcessId, EventCode, GrantedAccess -| rename Computer as dest +`sysmon` EventCode=10 TargetImage=*lsass.exe (GrantedAccess=0x1010 OR GrantedAccess=0x1410) +| stats count min(_time) as firstTime max(_time) as lastTime by Computer, SourceImage, SourceProcessId, TargetImage, TargetProcessId, EventCode, GrantedAccess +| rename Computer as dest | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | `detect_credential_dumping_through_lsass_access_filter` ====Associated Analytic Story==== @@ -12486,6 +15526,24 @@ This search needs Sysmon Logs and a sysmon configuration, which includes EventCo ====Required field==== +* _time + +* EventCode + +* TargetImage + +* GrantedAccess + +* Computer + +* SourceImage + +* SourceProcessId + +* TargetImage + +* TargetProcessId + ====ATT&CK==== @@ -12526,7 +15584,7 @@ The activity may be legitimate. Other tools can access lsass for legitimate reas This search detects the memory of lsass.exe being dumped for offline credential theft attack. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1003.003/ T1003.003] * '''Last Updated''': 2020-09-15 @@ -12535,10 +15593,10 @@ This search detects the memory of lsass.exe being dumped for offline credential ====Search==== -| from read_ssa_enriched_events() -| eval tenant=ucast(map_get(input_event, "_tenant"), "string", null), machine=ucast(map_get(input_event, "dest_device_id"), "string", null), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), process=lower(ucast(map_get(input_event, "process"), "string", null)) -| where process_name LIKE "%rundll32.exe%" AND match_regex(process, /(?i)comsvcs.dll[,\s]+MiniDump/)=true -| eval start_time = timestamp, end_time = timestamp, entities = mvappend(machine), body = "TBD" +| from read_ssa_enriched_events() +| eval tenant=ucast(map_get(input_event, "_tenant"), "string", null), machine=ucast(map_get(input_event, "dest_device_id"), "string", null), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), process=lower(ucast(map_get(input_event, "process"), "string", null)) +| where process_name LIKE "%rundll32.exe%" AND match_regex(process, /(?i)comsvcs.dll[,\s]+MiniDump/)=true +| eval start_time = timestamp, end_time = timestamp, entities = mvappend(machine), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== @@ -12610,12 +15668,12 @@ This search identifies endpoints that have caused a relatively high number of ac ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(All_Changes.user) as user from datamodel=Change.All_Changes where nodename=All_Changes.Account_Management All_Changes.result="lockout" by All_Changes.dest All_Changes.result -|`drop_dm_object_name("All_Changes")` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(All_Changes.user) as user from datamodel=Change.All_Changes where nodename=All_Changes.Account_Management All_Changes.result="lockout" by All_Changes.dest All_Changes.result +|`drop_dm_object_name("All_Changes")` |`drop_dm_object_name("Account_Management")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| search count > 5 +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| search count > 5 | `detect_excessive_account_lockouts_from_endpoint_filter` ====Associated Analytic Story==== @@ -12632,6 +15690,16 @@ If Splunk>Phantom is also configured in your environment, a Playbook called "Exc ====Required field==== +* _time + +* All_Changes.user + +* nodename + +* All_Changes.result + +* All_Changes.dest + ====ATT&CK==== @@ -12681,12 +15749,12 @@ This search detects user accounts that have been locked out a relatively high nu ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Change.All_Changes where nodename=All_Changes.Account_Management All_Changes.result="lockout" by All_Changes.user All_Changes.result -|`drop_dm_object_name("All_Changes")` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Change.All_Changes where nodename=All_Changes.Account_Management All_Changes.result="lockout" by All_Changes.user All_Changes.result +|`drop_dm_object_name("All_Changes")` |`drop_dm_object_name("Account_Management")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| search count > 5 +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| search count > 5 | `detect_excessive_user_account_lockouts_filter` ====Associated Analytic Story==== @@ -12699,6 +15767,14 @@ ou must ingest your Windows security event logs in the `Change` datamodel under ====Required field==== +* _time + +* All_Changes.result + +* nodename + +* All_Changes.user + ====ATT&CK==== @@ -12735,11 +15811,94 @@ It is possible that a legitimate user is experiencing an issue causing multiple ---- +===Detect exchange web shell=== +The following query identifies suspicious .aspx created in 3 paths identified by Microsoft as known drop locations for Exchange exploitation related to HAFNIUM group. Paths include: `\HttpProxy\owa\auth\`, `\inetpub\wwwroot\aspnet_client\`, and `\HttpProxy\OAB\`. Upon triage, the suspicious .aspx file will likely look obvious on the surface. inspect the contents for script code inside. Identify additional log sources, IIS included, to review source and other potential exploitation. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1505.003/ T1505.003] +* '''Last Updated''': 2021-03-09 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=System by _time span=1h Processes.process_id Processes.process_name Processes.dest +| `drop_dm_object_name(Processes)` +| join process_guid, _time [ +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*\\HttpProxy\\owa\\auth\\*", "*\\inetpub\\wwwroot\\aspnet_client\\*", "*\\HttpProxy\\OAB\\*") Filesystem.file_name="*.aspx" by _time span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path +| `drop_dm_object_name(Filesystem)` +| fields _time dest file_create_time file_name file_path process_name process_path process] +| dedup file_create_time +| table dest file_create_time, file_name, file_path, process_name +| `detect_exchange_web_shell_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#HAFNIUM_Group|HAFNIUM Group]] + + +====How To Implement==== +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node and `Filesystem` node. + +====Required field==== + +* _time + +* Filesystem.file_path + +* Filesystem.process_id + +* Filesystem.file_name + +* Filesystem.file_hash + +* Filesystem.user + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1505.003 +| Web Shell +| Persistence +|} + + +====Kill Chain Phase==== + +* Exploitation + + +====Known False Positives==== +The query is structured in a way that `action` (read, create) is not defined. Review the results of this query, filter, and tune as necessary. It may be necessary to generate this query specific to your endpoint product. + +====Reference==== + +* https://raw.githubusercontent.com/Azure/Azure-Sentinel/master/Sample%20Data/Feeds/MSTICIoCs-ExchangeServerVulnerabilitiesDisclosedMarch2021.csv + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1505.003/windows-sysmon_proxylogon.log + + +''version'': 2 +
+
+ +---- + ===Detect html help renamed=== The following analytic identifies a renamed instance of hh.exe (HTML Help) executing a Compiled HTML Help (CHM). This particular technique will load Windows script code from a compiled help file. CHM files may contain nearly any file type embedded, but only execute html/htm. Upon a successful execution, the following script engines may be used for execution - JScript, VBScript, VBScript.Encode, JScript.Encode, JScript.Compact. Analyst may identify vbscript.dll or jscript.dll loading into hh.exe upon execution. The "htm" and "html" file extensions were the only extensions observed to be supported for the execution of Shortcut commands or WSH script code. During investigation, identify script content origination. Validate it is the legitimate version of hh.exe by reviewing the PE metadata. hh.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1218.001/ T1218.001] * '''Last Updated''': 2021-02-11 @@ -12747,11 +15906,11 @@ The following analytic identifies a renamed instance of hh.exe (HTML Help) execu
====Search==== -`sysmon` EventID=1 OriginalFileName=HH.exe NOT process_name=hh.exe -| stats count min(_time) as firstTime max(_time) as lastTime by Computer, User, parent_process_name, process_name, OriginalFileName, process_path, CommandLine -| rename Computer as dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +`sysmon` EventID=1 OriginalFileName=HH.exe NOT process_name=hh.exe +| stats count min(_time) as firstTime max(_time) as lastTime by Computer, User, parent_process_name, process_name, OriginalFileName, process_path, CommandLine +| rename Computer as dest +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `detect_html_help_renamed_filter` ====Associated Analytic Story==== @@ -12764,6 +15923,24 @@ To successfully implement this search, you need to be ingesting logs with the pr ====Required field==== +* _time + +* EventID + +* OriginalFileName + +* process_name + +* Computer + +* User + +* parent_process_name + +* process_path + +* CommandLine + ====ATT&CK==== @@ -12819,10 +15996,10 @@ The following analytic identifies hh.exe (HTML Help) execution of a Compiled HTM ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=hh.exe by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=hh.exe by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `detect_html_help_spawn_child_process_filter` ====Associated Analytic Story==== @@ -12835,6 +16012,24 @@ To successfully implement this search you need to be ingesting information on pr ====Required field==== +* _time + +* Processes.parent_process_name + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_name + +* Processes.process + +* Processes.process_id + +* Processes.parent_process_id + ====ATT&CK==== @@ -12894,10 +16089,10 @@ The following analytic identifies hh.exe (HTML Help) execution of a Compiled HTM ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=hh.exe Processes.process=*http* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=hh.exe Processes.process=*http* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `detect_html_help_url_in_command_line_filter` ====Associated Analytic Story==== @@ -12910,6 +16105,22 @@ To successfully implement this search you need to be ingesting information on pr ====Required field==== +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_id + +* Processes.parent_process_id + ====ATT&CK==== @@ -12971,10 +16182,10 @@ The following analytic identifies hh.exe (HTML Help) execution of a Compiled HTM ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=hh.exe Processes.process IN ("*its:*", "*mk:@MSITStore:*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=hh.exe Processes.process IN ("*its:*", "*mk:@MSITStore:*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `detect_html_help_using_infotech_storage_handlers_filter` ====Associated Analytic Story==== @@ -12987,6 +16198,20 @@ To successfully implement this search you need to be ingesting information on pr ====Required field==== +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_id + ====ATT&CK==== @@ -13039,7 +16264,7 @@ It is rare to see instances of InfoTech Storage Handlers being used, but it does This search detects a potential kerberoasting attack via service principal name requests * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1558.003/ T1558.003] * '''Last Updated''': 2020-10-21 @@ -13047,18 +16272,20 @@ This search detects a potential kerberoasting attack via service principal name
====Search==== - -| from read_ssa_enriched_events() -| eval _time=map_get(input_event, "_time"), EventCode=map_get(input_event, "event_code"), TicketOptions=map_get(input_event, "ticket_options"), TicketEncryptionType=map_get(input_event, "ticket_encryption_type"), ServiceName=map_get(input_event, "service_name"), ServiceID=map_get(input_event, "service_id") -| where EventCode="4769" AND TicketOptions="0x40810000" AND TicketEncryptionType="0x17" -| first_time_event input_columns=["EventCode","TicketOptions","TicketEncryptionType","ServiceName","ServiceID"] -| where first_time_EventCode_TicketOptions_TicketEncryptionType_ServiceName_ServiceID -| eval start_time=_time, end_time=_time, body="TBD", entities="TBD" -| select start_time, end_time, entities, body + +| from read_ssa_enriched_events() +| eval _time=map_get(input_event, "_time"), EventCode=map_get(input_event, "event_code"), TicketOptions=map_get(input_event, "ticket_options"), TicketEncryptionType=map_get(input_event, "ticket_encryption_type"), ServiceName=map_get(input_event, "service_name"), ServiceID=map_get(input_event, "service_id") +| where EventCode="4769" AND TicketOptions="0x40810000" AND TicketEncryptionType="0x17" +| first_time_event input_columns=["EventCode","TicketOptions","TicketEncryptionType","ServiceName","ServiceID"] +| where first_time_EventCode_TicketOptions_TicketEncryptionType_ServiceName_ServiceID +| eval start_time=_time, end_time=_time, body="TBD", entities="TBD" +| select start_time, end_time, entities, body | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] + ====How To Implement==== The test data is converted from Windows Security Event logs generated from Attach Range simulation and used in SPL search and extended to SPL2 @@ -13126,10 +16353,10 @@ This analytic identifies when Microsoft HTML Application Host (mshta.exe) utilit ====Search==== -| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=mshta.exe (Processes.process="*http://*" OR Processes.process="*https://*") by Processes.user Processes.process_name Processes.parent_process_name Processes.dest -| `drop_dm_object_name(Processes)` +| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=mshta.exe (Processes.process="*http://*" OR Processes.process="*https://*") by Processes.user Processes.process_name Processes.parent_process_name Processes.dest +| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | `detect_mshta_url_in_command_line_filter` ====Associated Analytic Story==== @@ -13142,6 +16369,18 @@ To successfully implement this search you need to be ingesting information on pr ====Required field==== +* _time + +* Processes.process + +* Processes.parent_process + +* Processes.process_name + +* Processes.user + +* Processes.dest + ====ATT&CK==== @@ -13178,6 +16417,90 @@ It is possible legitimate applications may perform this behavior and will need t * https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-sysmon.log +''version'': 1 +
+
+ +---- + +===Detect mimikatz using loaded images=== +This search looks for reading loaded Images unique to credential dumping with Mimikatz. Deprecated because mimikatz libraries changed and very noisy sysmon Event Code. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003.001/ T1003.001] +* '''Last Updated''': 2019-12-03 + +
+
+ +====Search==== +`sysmon` EventCode=7 +| stats values(ImageLoaded) as ImageLoaded values(ProcessId) as ProcessId by Computer, Image +| search ImageLoaded=*WinSCard.dll ImageLoaded=*cryptdll.dll ImageLoaded=*hid.dll ImageLoaded=*samlib.dll ImageLoaded=*vaultcli.dll +| rename Computer as dest +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `detect_mimikatz_using_loaded_images_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] + +* [[Documentation:ESSOC:stories:UseCase#Detect_Zerologon_Attack|Detect Zerologon Attack]] + +* [[Documentation:ESSOC:stories:UseCase#Cloud_Federated_Credential_Abuse|Cloud Federated Credential Abuse]] + + +====How To Implement==== +This search needs Sysmon Logs and a sysmon configuration, which includes EventCode 7 with powershell.exe. This search uses an input macro named `sysmon`. We strongly recommend that you specify your environment-specific configurations (index, source, sourcetype, etc.) for Windows Sysmon logs. Replace the macro definition with configurations for your Splunk environment. The search also uses a post-filter macro designed to filter out known false positives. + +====Required field==== + +* _time + +* EventCode + +* ImageLoaded + +* ProcessId + +* Computer + +* Image + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1003.001 +| LSASS Memory +| Credential Access +|} + + +====Kill Chain Phase==== + +* Actions on Objectives + + +====Known False Positives==== +Other tools can import the same DLLs. These tools should be part of a whitelist. False positives may be present with any process that authenticates or uses credentials, PowerShell included. Filter based on parent process. + +====Reference==== + +* https://cyberwardog.blogspot.com/2017/03/chronicles-of-threat-hunter-hunting-for.html + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/windows-sysmon.log + + ''version'': 1
@@ -13188,7 +16511,7 @@ It is possible legitimate applications may perform this behavior and will need t This search looks for newly created accounts that have been elevated to local administrators. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1136.001/ T1136.001] * '''Last Updated''': 2020-07-08 @@ -13196,24 +16519,36 @@ This search looks for newly created accounts that have been elevated to local ad
====Search==== -`wineventlog_security` EventCode=4720 OR (EventCode=4732 Group_Name=Administrators) -| transaction member_id connected=false maxspan=180m -| rename member_id as user -| stats count min(_time) as firstTime max(_time) as lastTime by user dest +`wineventlog_security` EventCode=4720 OR (EventCode=4732 Group_Name=Administrators) +| transaction member_id connected=false maxspan=180m +| rename member_id as user +| stats count min(_time) as firstTime max(_time) as lastTime by user dest | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | `detect_new_local_admin_account_filter` ====Associated Analytic Story==== * [[Documentation:ESSOC:stories:UseCase#DHS_Report_TA18-074A|DHS Report TA18-074A]] +* [[Documentation:ESSOC:stories:UseCase#HAFNIUM_Group|HAFNIUM Group]] + ====How To Implement==== You must be ingesting Windows event logs using the Splunk Windows TA and collecting event code 4720 and 4732 ====Required field==== +* _time + +* EventCode + +* Group_Name + +* member_id + +* dest + ====ATT&CK==== @@ -13260,7 +16595,7 @@ The activity may be legitimate. For this reason, it's best to verify the account This search looks for execution of process `outlook.exe` where the process is writing a `.zip` file to the disk. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1566.001/ T1566.001] * '''Last Updated''': 2020-07-21 @@ -13269,21 +16604,21 @@ This search looks for execution of process `outlook.exe` where the process is wr ====Search==== -| tstats `security_content_summariesonly` min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes where Processes.process_name=outlook.exe OR Processes.process_name=explorer.exe by _time span=5m Processes.parent_process_id Processes.process_id Processes.dest Processes.process_name Processes.parent_process_name Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes where Processes.process_name=outlook.exe OR Processes.process_name=explorer.exe by _time span=5m Processes.parent_process_id Processes.process_id Processes.dest Processes.process_name Processes.parent_process_name Processes.user +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | rename process_id as malicious_id | rename parent_process_id as outlook_id | join malicious_id type=inner[ -| tstats `security_content_summariesonly` count values(Filesystem.file_path) as file_path values(Filesystem.file_name) as file_name FROM datamodel=Endpoint.Filesystem where (Filesystem.file_path=*zip* OR Filesystem.file_name=*.lnk ) AND (Filesystem.file_path=C:\\Users* OR Filesystem.file_path=*Local\\Temp*) by _time span=5m Filesystem.process_id Filesystem.file_hash Filesystem.dest -| `drop_dm_object_name(Filesystem)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` count values(Filesystem.file_path) as file_path values(Filesystem.file_name) as file_name FROM datamodel=Endpoint.Filesystem where (Filesystem.file_path=*zip* OR Filesystem.file_name=*.lnk ) AND (Filesystem.file_path=C:\\Users* OR Filesystem.file_path=*Local\\Temp*) by _time span=5m Filesystem.process_id Filesystem.file_hash Filesystem.dest +| `drop_dm_object_name(Filesystem)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | rename process_id as malicious_id -| fields malicious_id outlook_id dest file_path file_name file_hash count file_id] -| table firstTime lastTime user malicious_id outlook_id process_name parent_process_name file_name file_path -| where file_name != "" +| fields malicious_id outlook_id dest file_path file_name file_hash count file_id] +| table firstTime lastTime user malicious_id outlook_id process_name parent_process_name file_name file_path +| where file_name != "" | `detect_oulook_exe_writing_a__zip_file_filter` ====Associated Analytic Story==== @@ -13296,6 +16631,20 @@ You must be ingesting data that records filesystem and process activity from you ====Required field==== +* _time + +* Processes.process_name + +* Processes.parent_process_id + +* Processes.process_id + +* Processes.dest + +* Processes.parent_process_name + +* Processes.user + ====ATT&CK==== @@ -13336,7 +16685,7 @@ It is not uncommon for outlook to write legitimate zip files to the disk. This search looks for specific authentication events from the Windows Security Event logs to detect potential attempts using Pass-the-Hash technique. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1550.002/ T1550.002] * '''Last Updated''': 2020-10-21 @@ -13344,18 +16693,20 @@ This search looks for specific authentication events from the Windows Security E
====Search==== - -| from read_ssa_enriched_events() -| eval _time=map_get(input_event, "_time"), EventCode=map_get(input_event, "event_code"), LogonType=map_get(input_event, "logon_type"), LogonProcess=map_get(input_event, "logon_process"), ComputerName=map_get(input_event, "dest_ip_primary_artifact"), AccountName=map_get(input_event, "dest_user_primary_artifact") -| where (LogonType="3" AND LogonProcess="NtLmSsp" AND AccountName IS NOT NULL) OR (LogonType="9" AND LogonProcess="seclogo") -| first_time_event input_columns=["EventCode","LogonProcess","ComputerName"] -| where first_time_EventCode_LogonProcess_ComputerName -| eval start_time=_time, end_time=_time, body="TBD", entities="TBD" -| select start_time, end_time, entities, body + +| from read_ssa_enriched_events() +| eval _time=map_get(input_event, "_time"), EventCode=map_get(input_event, "event_code"), LogonType=map_get(input_event, "logon_type"), LogonProcess=map_get(input_event, "logon_process"), ComputerName=map_get(input_event, "dest_ip_primary_artifact"), AccountName=map_get(input_event, "dest_user_primary_artifact") +| where (LogonType="3" AND LogonProcess="NtLmSsp" AND AccountName IS NOT NULL) OR (LogonType="9" AND LogonProcess="seclogo") +| first_time_event input_columns=["EventCode","LogonProcess","ComputerName"] +| where first_time_EventCode_LogonProcess_ComputerName +| eval start_time=_time, end_time=_time, body="TBD", entities="TBD" +| select start_time, end_time, entities, body | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Lateral_Movement|Lateral Movement]] + ====How To Implement==== The test data is converted from Windows Security Event logs generated from Attach Range simulation and used in SPL search and extended to SPL2 @@ -13411,7 +16762,7 @@ Legitimate logon activity by authorized NTLM systems may be detected by this sea ---- ===Detect path interception by creation of program exe=== -The detection Detect Path Interception By Creation Of program exe is detecting the abuse of unquoted service paths, which is a popular technique for privilege escalation. +The detection Detect Path Interception By Creation Of program exe is detecting the abuse of unquoted service paths, which is a popular technique for privilege escalation. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint @@ -13423,17 +16774,17 @@ The detection Detect Path Interception By Creation Of program exe is detecting t ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=services.exe by Processes.user Processes.process_name Processes.process Processes.dest index -| `drop_dm_object_name(Processes)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=services.exe by Processes.user Processes.process_name Processes.process Processes.dest +| `drop_dm_object_name(Processes)` | rex field=process "^.*?\\\\(?[^\\\\]*\.(?:exe |bat |com -|ps1))" -| eval process_name = lower(process_name) -| eval service_process = lower(service_process) -| where process_name != service_process -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +|ps1))" +| eval process_name = lower(process_name) +| eval service_process = lower(service_process) +| where process_name != service_process +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `detect_path_interception_by_creation_of_program_exe_filter` ====Associated Analytic Story==== @@ -13446,6 +16797,18 @@ You must be ingesting data that records process activity from your hosts to popu ====Required field==== +* _time + +* Processes.parent_process_name + +* Processes.user + +* Processes.process_name + +* Processes.process + +* Processes.dest + ====ATT&CK==== @@ -13498,10 +16861,10 @@ This search looks for executions of cmd.exe spawned by a process that is often a ====Search==== | tstats `security_content_summariesonly` count values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=cmd.exe by Processes.parent_process_name Processes.process_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` +| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -|search [`prohibited_apps_launching_cmd`] +| `security_content_ctime(lastTime)` +|search [`prohibited_apps_launching_cmd`] | `detect_prohibited_applications_spawning_cmd_exe_filter` ====Associated Analytic Story==== @@ -13512,7 +16875,7 @@ This search looks for executions of cmd.exe spawned by a process that is often a * [[Documentation:ESSOC:stories:UseCase#Suspicious_Zoom_Child_Processes|Suspicious Zoom Child Processes]] -* [[Documentation:ESSOC:stories:UseCase#Sunburst_Malware|Sunburst Malware]] +* [[Documentation:ESSOC:stories:UseCase#NOBELIUM_Group|NOBELIUM Group]] ====How To Implement==== @@ -13520,6 +16883,18 @@ You must be ingesting data that records process activity from your hosts and pop ====Required field==== +* _time + +* Processes.process + +* Processes.process_name + +* Processes.parent_process_name + +* Processes.dest + +* Processes.user + ====ATT&CK==== @@ -13560,7 +16935,7 @@ There are circumstances where an application may legitimately execute and intera This search looks for executions of cmd.exe spawned by a process that is often abused by attackers and that does not typically launch cmd.exe. This is a SPL2 implementation of the rule `Detect Prohibited Applications Spawning cmd.exe` by @bpatel. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059] * '''Last Updated''': 2020-7-13 @@ -13571,18 +16946,26 @@ This search looks for executions of cmd.exe spawned by a process that is often a | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) | eval process_name=ucast(map_get(input_event, "process_name"), "string", null), parent_process=lower(ucast(map_get(input_event, "parent_process_name"), "string", null)), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null) -| where process_name="cmd.exe" -| rex field=parent_process "(?[^\\\\]+)$" +| where process_name="cmd.exe" +| rex field=parent_process "(?[^\\\\]+)$" | where field0="winword.exe" OR field0="excel.exe" OR field0="outlook.exe" OR field0="powerpnt.exe" OR field0="visio.exe" OR field0="mspub.exe" OR field0="acrobat.exe" OR field0="acrord32.exe" OR field0="chrome.exe" OR field0="iexplore.exe" OR field0="opera.exe" OR field0="firefox.exe" OR field0="java.exe" OR field0="powershell.exe" -| eval start_time=timestamp, end_time=timestamp, entities=mvappend(dest_device_id, dest_user_id), body="TBD" +| eval start_time=timestamp, end_time=timestamp, entities=mvappend(dest_device_id, dest_user_id), body="TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Suspicious_Command-Line_Executions|Suspicious Command-Line Executions]] + +* [[Documentation:ESSOC:stories:UseCase#Suspicious_MSHTA_Activity|Suspicious MSHTA Activity]] + +* [[Documentation:ESSOC:stories:UseCase#Suspicious_Zoom_Child_Processes|Suspicious Zoom Child Processes]] + +* [[Documentation:ESSOC:stories:UseCase#Sunburst_Malware|Sunburst Malware]] + ====How To Implement==== You must be ingesting sysmon logs. This search has been modified to process raw sysmon data from attack_range's nxlogs on DSP. @@ -13646,10 +17029,10 @@ This search looks for events where `PsExec.exe` is run with the `accepteula` fla ====Search==== -| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process=*psexec* Processes.process=*accepteula* by Processes.process_name Processes.dest Processes.parent_process_name +| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process=*psexec* Processes.process=*accepteula* by Processes.process_name Processes.dest Processes.parent_process_name | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | `detect_psexec_with_accepteula_flag_filter` ====Associated Analytic Story==== @@ -13658,12 +17041,24 @@ This search looks for events where `PsExec.exe` is run with the `accepteula` fla * [[Documentation:ESSOC:stories:UseCase#DHS_Report_TA18-074A|DHS Report TA18-074A]] +* [[Documentation:ESSOC:stories:UseCase#HAFNIUM_Group|HAFNIUM Group]] + ====How To Implement==== You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. ====Required field==== +* _time + +* Processes.process + +* Processes.process_name + +* Processes.dest + +* Processes.parent_process_name + ====ATT&CK==== @@ -13705,7 +17100,7 @@ This search will return a table of rare processes, the names of the systems runn * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': +* '''ATT&CK''': * '''Last Updated''': 2020-03-16
@@ -13713,17 +17108,17 @@ This search will return a table of rare processes, the names of the systems runn ====Search==== -| tstats `security_content_summariesonly` count values(Processes.dest) as dest values(Processes.user) as user min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes by Processes.process_name -| rename Processes.process_name as process -| rex field=user "(?.*)\\\\(?.*)" +| tstats `security_content_summariesonly` count values(Processes.dest) as dest values(Processes.user) as user min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes by Processes.process_name +| rename Processes.process_name as process +| rex field=user "(?.*)\\\\(?.*)" | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | search [ -| tstats count from datamodel=Endpoint.Processes by Processes.process_name -| rare Processes.process_name limit=30 +| tstats count from datamodel=Endpoint.Processes by Processes.process_name +| rare Processes.process_name limit=30 | rename Processes.process_name as process | `filter_rare_process_allow_list` -| table process ] +| table process ] | `detect_rare_executables_filter` ====Associated Analytic Story==== @@ -13740,6 +17135,14 @@ To successfully implement this search, you must be ingesting data that records p ====Required field==== +* _time + +* Processes.dest + +* Processes.user + +* Processes.process_name + @@ -13780,10 +17183,10 @@ The following analytic identifies regasm.exe spawning a process. This particular ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=regasm.exe by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=regasm.exe by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `detect_regasm_spawning_a_process_filter` ====Associated Analytic Story==== @@ -13796,6 +17199,22 @@ To successfully implement this search you need to be ingesting information on pr ====Required field==== +* _time + +* Processes.parent_process_name + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process + +* Processes.process_id + +* Processes.parent_process_id + ====ATT&CK==== @@ -13844,7 +17263,7 @@ Although unlikely, limited instances of regasm.exe or regsvcs.exe may cause a fa The following analytic identifies regasm.exe with a network connection to a public IP address, exluding private IP space. This particular technique has been used in the wild to bypass application control products. Regasm.exe and Regsvcs.exe are signed by Microsoft. By contacting a remote command and control server, the adversary will have the ability to escalate privileges and complete the objectives. During investigation, identify and retrieve the content being loaded. Review parallel processes for additional suspicious behavior. Gather any other file modifications and review accordingly. Review the reputation of the remote IP or domain and block as needed. regsvcs.exe and regasm.exe are natively found in C:\Windows\Microsoft.NET\Framework\v*\regasm|regsvcs.exe and C:\Windows\Microsoft.NET\Framework64\v*\regasm|regsvcs.exe. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1218.009/ T1218.009] * '''Last Updated''': 2021-02-16 @@ -13852,11 +17271,11 @@ The following analytic identifies regasm.exe with a network connection to a publ
====Search==== -`sysmon` EventID=3 dest_ip!=10.0.0.0/12 dest_ip!=172.16.0.0/12 dest_ip!=192.168.0.0/16 process_name=regasm.exe -| rename Computer as dest -| stats count min(_time) as firstTime max(_time) as lastTime by dest, User, process_name, src_ip, dest_host, dest_ip -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +`sysmon` EventID=3 dest_ip!=10.0.0.0/12 dest_ip!=172.16.0.0/12 dest_ip!=192.168.0.0/16 process_name=regasm.exe +| rename Computer as dest +| stats count min(_time) as firstTime max(_time) as lastTime by dest, User, process_name, src_ip, dest_host, dest_ip +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `detect_regasm_with_network_connection_filter` ====Associated Analytic Story==== @@ -13869,6 +17288,24 @@ To successfully implement this search, you need to be ingesting logs with the pr ====Required field==== +* _time + +* EventID + +* dest_ip + +* process_name + +* Computer + +* User + +* src_ip + +* dest_host + +* dest_ip + ====ATT&CK==== @@ -13915,7 +17352,7 @@ Although unlikely, limited instances of regasm.exe with a network connection may The following analytic identifies regasm.exe with no command line arguments. This particular behavior occurs when another process injects into regasm.exe, no command line arguments will be present. During investigation, identify any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. Regasm.exe are natively found in C:\Windows\Microsoft.NET\Framework\v*\regasm|regsvcs.exe and C:\Windows\Microsoft.NET\Framework64\v*\regasm|regsvcs.exe. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1218.009/ T1218.009] * '''Last Updated''': 2021-02-12 @@ -13923,12 +17360,12 @@ The following analytic identifies regasm.exe with no command line arguments. Thi
====Search==== -`sysmon` EventID=1 (process_name=regasm.exe OR OriginalFileName=RegAsm.exe) -| regex CommandLine="(regasm\.exe.{0,4}$)" -| stats count min(_time) as firstTime max(_time) as lastTime by dest, User, ParentImage,ParentCommandLine, process_name, OriginalFileName, process_path, CommandLine -| rename Computer as dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +`sysmon` EventID=1 (process_name=regasm.exe OR OriginalFileName=RegAsm.exe) +| regex CommandLine="(regasm\.exe.{0,4}$)" +| stats count min(_time) as firstTime max(_time) as lastTime by dest, User, ParentImage,ParentCommandLine, process_name, OriginalFileName, process_path, CommandLine +| rename Computer as dest +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `detect_regasm_with_no_command_line_arguments_filter` ====Associated Analytic Story==== @@ -13941,6 +17378,28 @@ To successfully implement this search, you need to be ingesting logs with the pr ====Required field==== +* _time + +* EventID + +* process_name + +* OriginalFileName + +* CommandLine + +* dest + +* User + +* ParentImage + +* ParentCommandLine + +* process_path + +* Computer + ====ATT&CK==== @@ -13996,10 +17455,10 @@ The following analytic identifies regsvcs.exe spawning a process. This particula ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=regsvcs.exe by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=regsvcs.exe by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `detect_regsvcs_spawning_a_process_filter` ====Associated Analytic Story==== @@ -14012,6 +17471,24 @@ To successfully implement this search you need to be ingesting information on pr ====Required field==== +* _time + +* Processes.parent_process_name + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_name + +* Processes.process + +* Processes.process_id + +* Processes.parent_process_id + ====ATT&CK==== @@ -14058,7 +17535,7 @@ Although unlikely, limited instances of regasm.exe or regsvcs.exe may cause a fa The following analytic identifies Regsvcs.exe with a network connection to a public IP address, exluding private IP space. This particular technique has been used in the wild to bypass application control products. Regasm.exe and Regsvcs.exe are signed by Microsoft. By contacting a remote command and control server, the adversary will have the ability to escalate privileges and complete the objectives. During investigation, identify and retrieve the content being loaded. Review parallel processes for additional suspicious behavior. Gather any other file modifications and review accordingly. Review the reputation of the remote IP or domain and block as needed. regsvcs.exe and regasm.exe are natively found in C:\Windows\Microsoft.NET\Framework\v*\regasm|regsvcs.exe and C:\Windows\Microsoft.NET\Framework64\v*\regasm|regsvcs.exe. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1218.009/ T1218.009] * '''Last Updated''': 2021-02-16 @@ -14066,11 +17543,11 @@ The following analytic identifies Regsvcs.exe with a network connection to a pub
====Search==== -`sysmon` EventID=3 dest_ip!=10.0.0.0/12 dest_ip!=172.16.0.0/12 dest_ip!=192.168.0.0/16 process_name=regsvcs.exe -| rename Computer as dest -| stats count min(_time) as firstTime max(_time) as lastTime by dest, User, process_name, src_ip, dest_host, dest_ip -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +`sysmon` EventID=3 dest_ip!=10.0.0.0/12 dest_ip!=172.16.0.0/12 dest_ip!=192.168.0.0/16 process_name=regsvcs.exe +| rename Computer as dest +| stats count min(_time) as firstTime max(_time) as lastTime by dest, User, process_name, src_ip, dest_host, dest_ip +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `detect_regsvcs_with_network_connection_filter` ====Associated Analytic Story==== @@ -14083,6 +17560,22 @@ To successfully implement this search, you need to be ingesting logs with the pr ====Required field==== +* _time + +* EventID + +* dest_ip + +* process_name + +* Computer + +* User + +* src_ip + +* dest_host + ====ATT&CK==== @@ -14129,7 +17622,7 @@ Although unlikely, limited instances of regsvcs.exe may cause a false positive. The following analytic identifies regsvcs.exe with no command line arguments. This particular behavior occurs when another process injects into regsvcs.exe, no command line arguments will be present. During investigation, identify any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. Regasm.exe are natively found in C:\Windows\Microsoft.NET\Framework\v*\regasm|regsvcs.exe and C:\Windows\Microsoft.NET\Framework64\v*\regasm|regsvcs.exe. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1218.009/ T1218.009] * '''Last Updated''': 2021-02-12 @@ -14137,12 +17630,12 @@ The following analytic identifies regsvcs.exe with no command line arguments. Th
====Search==== -`sysmon` EventID=1 (process_name=regsvcs.exe OR OriginalFileName=RegSvcs.exe) -| regex CommandLine="(regsvcs\.exe.{0,4}$)" -| stats count min(_time) as firstTime max(_time) as lastTime by dest, User, ParentImage,ParentCommandLine, process_name, OriginalFileName, process_path, CommandLine -| rename Computer as dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +`sysmon` EventID=1 (process_name=regsvcs.exe OR OriginalFileName=RegSvcs.exe) +| regex CommandLine="(regsvcs\.exe.{0,4}$)" +| stats count min(_time) as firstTime max(_time) as lastTime by dest, User, ParentImage,ParentCommandLine, process_name, OriginalFileName, process_path, CommandLine +| rename Computer as dest +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `detect_regsvcs_with_no_command_line_arguments_filter` ====Associated Analytic Story==== @@ -14155,6 +17648,30 @@ To successfully implement this search, you need to be ingesting logs with the pr ====Required field==== +* _time + +* EventID + +* process_name + +* OriginalFileName + +* CommandLine + +* dest + +* User + +* ParentImage + +* ParentCommandLine + +* OriginalFileName + +* process_path + +* Computer + ====ATT&CK==== @@ -14199,7 +17716,7 @@ Although unlikely, limited instances of regsvcs.exe may cause a false positive. ===Detect regsvr32 application control bypass=== Adversaries may abuse Regsvr32.exe to proxy execution of malicious code. Regsvr32.exe is a command-line program used to register and unregister object linking and embedding controls, including dynamic link libraries (DLLs), on Windows systems. Regsvr32.exe is also a Microsoft signed binary.This variation of the technique is often referred to as a "Squiblydoo" attack. \ -Upon investigating, look for network connections to remote destinations (internal or external). Be cautious to modify the query to look for "scrobj.dll", the ".dll" is not required to load scrobj. "scrobj.dll" will be loaded by "regsvr32.exe" upon execution. +Upon investigating, look for network connections to remote destinations (internal or external). Be cautious to modify the query to look for "scrobj.dll", the ".dll" is not required to load scrobj. "scrobj.dll" will be loaded by "regsvr32.exe" upon execution. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint @@ -14211,22 +17728,40 @@ Upon investigating, look for network connections to remote destinations (interna ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=regsvr32.exe OR Processes.process_name!=regsvr32.exe) Processes.process=*scrobj* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=regsvr32.exe OR Processes.process_name!=regsvr32.exe) Processes.process=*scrobj* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | `detect_regsvr32_application_control_bypass_filter` ====Associated Analytic Story==== * [[Documentation:ESSOC:stories:UseCase#Suspicious_Regsvr32_Activity|Suspicious Regsvr32 Activity]] +* [[Documentation:ESSOC:stories:UseCase#Cobalt_Strike|Cobalt Strike]] + ====How To Implement==== You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints, to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" field in the Endpoint data model. Tune the query by modifying/removing the !=regsv32.exe. ====Required field==== +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_id + +* Processes.parent_process_id + ====ATT&CK==== @@ -14284,10 +17819,10 @@ The following analytic identifies rundll32.exe loading advpack.dll and ieadvpack ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=rundll32.exe Processes.process=*advpack* by Processes.user Processes.process_name Processes.process Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=rundll32.exe Processes.process=*advpack* by Processes.user Processes.process_name Processes.process Processes.dest +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `detect_rundll32_application_control_bypass___advpack_filter` ====Associated Analytic Story==== @@ -14300,6 +17835,16 @@ To successfully implement this search you need to be ingesting information on pr ====Required field==== +* _time + +* Processes.process_name + +* Processes.process + +* Processes.user + +* Processes.dest + ====ATT&CK==== @@ -14359,10 +17904,10 @@ The following analytic identifies rundll32.exe loading setupapi.dll and iesetupa ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=rundll32.exe Processes.process=*setupapi* by Processes.user Processes.process_name Processes.process Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=rundll32.exe Processes.process=*setupapi* by Processes.user Processes.process_name Processes.process Processes.dest +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `detect_rundll32_application_control_bypass___setupapi_filter` ====Associated Analytic Story==== @@ -14375,6 +17920,16 @@ To successfully implement this search you need to be ingesting information on pr ====Required field==== +* _time + +* Processes.process + +* Processes.process_name + +* Processes.user + +* Processes.dest + ====ATT&CK==== @@ -14434,10 +17989,10 @@ The following analytic identifies rundll32.exe loading syssetup.dll by calling t ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=rundll32.exe Processes.process=*syssetup* by Processes.user Processes.process_name Processes.process Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=rundll32.exe Processes.process=*syssetup* by Processes.user Processes.process_name Processes.process Processes.dest +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `detect_rundll32_application_control_bypass___syssetup_filter` ====Associated Analytic Story==== @@ -14450,6 +18005,16 @@ To successfully implement this search you need to be ingesting information on pr ====Required field==== +* _time + +* Processes.process + +* Processes.process_name + +* Processes.user + +* Processes.dest + ====ATT&CK==== @@ -14509,22 +18074,38 @@ The following analytic identifies "rundll32.exe" execution with inline protocol ====Search==== -| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=rundll32.exe (Processes.process=*vbscript* OR Processes.process=*javascript* OR Processes.process=*about*) by Processes.user Processes.process_name Processes.parent_process_name Processes.dest -| `drop_dm_object_name(Processes)` +| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=rundll32.exe (Processes.process=*vbscript* OR Processes.process=*javascript* OR Processes.process=*about*) by Processes.user Processes.process_name Processes.parent_process_name Processes.dest +| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | `detect_rundll32_inline_hta_execution_filter` ====Associated Analytic Story==== * [[Documentation:ESSOC:stories:UseCase#Suspicious_MSHTA_Activity|Suspicious MSHTA Activity]] +* [[Documentation:ESSOC:stories:UseCase#NOBELIUM_Group|NOBELIUM Group]] + ====How To Implement==== To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. ====Required field==== +* _time + +* Processes.process + +* Processes.process_name + +* Processes.user + +* Processes.dest + +* Processes.parent_process_name + +* Processes.parent_process + ====ATT&CK==== @@ -14580,10 +18161,10 @@ This search looks for the execution of the cscript.exe or wscript.exe processes, ====Search==== -| tstats `security_content_summariesonly` count values(Processes.process) min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name="cmd.exe" (Processes.process_name=cscript.exe OR Processes.process_name =wscript.exe) by Processes.parent_process Processes.process_name Processes.user Processes.dest -| `drop_dm_object_name("Processes")` +| tstats `security_content_summariesonly` count values(Processes.process) min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name="cmd.exe" (Processes.process_name=cscript.exe OR Processes.process_name =wscript.exe) by Processes.parent_process Processes.process_name Processes.user Processes.dest +| `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` +|`security_content_ctime(lastTime)` | `detect_use_of_cmd_exe_to_launch_script_interpreters_filter` ====Associated Analytic Story==== @@ -14598,6 +18179,20 @@ To successfully implement this search, you must be ingesting data that records p ====Required field==== +* _time + +* Processes.process + +* Processes.parent_process_name + +* Processes.process_name + +* Processes.parent_process + +* Processes.user + +* Processes.dest + ====ATT&CK==== @@ -14647,10 +18242,10 @@ The following analytic identifies "mshta.exe" execution with inline protocol han ====Search==== -| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=mshta.exe (Processes.process=*vbscript* OR Processes.process=*javascript* OR Processes.process=*about*) by Processes.user Processes.process_name Processes.parent_process_name Processes.dest -| `drop_dm_object_name(Processes)` +| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=mshta.exe (Processes.process=*vbscript* OR Processes.process=*javascript* OR Processes.process=*about*) by Processes.user Processes.process_name Processes.parent_process_name Processes.dest +| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | `detect_mshta_inline_hta_execution_filter` ====Associated Analytic Story==== @@ -14663,6 +18258,20 @@ To successfully implement this search you need to be ingesting information on pr ====Required field==== +* _time + +* Processes.process + +* Processes.parent_process + +* Processes.user + +* Processes.process_name + +* Processes.parent_process_name + +* Processes.dest + ====ATT&CK==== @@ -14709,7 +18318,7 @@ Although unlikely, some legitimate applications may exhibit this behavior, trigg The following analytic identifies renamed instances of mshta.exe executing. Mshta.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. This analytic utilizes the internal name of the PE to identify if is the legitimate mshta binary. Further analysis should be performed to review the executed content and validation it is the real mshta. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1218.005/ T1218.005] * '''Last Updated''': 2021-01-20 @@ -14717,9 +18326,9 @@ The following analytic identifies renamed instances of mshta.exe executing. Msht
====Search==== -`sysmon` EventID=1 (OriginalFileName=mshta.exe AND process_name!=mshta.exe) -| stats count min(_time) as firstTime max(_time) as lastTime by Computer, User, parent_process_name, process_name, OriginalFileName, process_path, CommandLine -| rename Computer as dest +`sysmon` EventID=1 (OriginalFileName=mshta.exe AND process_name!=mshta.exe) +| stats count min(_time) as firstTime max(_time) as lastTime by Computer, User, parent_process_name, process_name, OriginalFileName, process_path, CommandLine +| rename Computer as dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `detect_mshta_renamed_filter` @@ -14734,6 +18343,24 @@ To successfully implement this search, you need to be ingesting logs with the pr ====Required field==== +* _time + +* EventID + +* OriginalFileName + +* process_name + +* Computer + +* User + +* parent_process_name + +* process_path + +* CommandLine + ====ATT&CK==== @@ -14765,7 +18392,7 @@ Although unlikely, some legitimate applications may use a moved copy of mshta.ex ====Test Dataset==== -* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127.001/windows-sysmon.log +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.005/atomic_red_team/windows-sysmon.log ''version'': 1 @@ -14787,14 +18414,14 @@ This search looks for fast execution of processes used for system network config ====Search==== -| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes by Processes.dest Processes.process_name Processes.user _time -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `drop_dm_object_name(Processes)` -| search `system_network_configuration_discovery_tools` -| transaction dest connected=false maxpause=5m -|where eventcount>=5 -| table firstTime lastTime dest user process_name process parent_process eventcount +| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes by Processes.dest Processes.process_name Processes.user _time +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `drop_dm_object_name(Processes)` +| search `system_network_configuration_discovery_tools` +| transaction dest connected=false maxpause=5m +|where eventcount>=5 +| table firstTime lastTime dest user process_name process parent_process eventcount | `detect_processes_used_for_system_network_configuration_discovery_filter` ====Associated Analytic Story==== @@ -14807,6 +18434,18 @@ You must be ingesting data that records registry activity from your hosts to pop ====Required field==== +* _time + +* Processes.process + +* Processes.parent_process + +* Processes.dest + +* Processes.process_name + +* Processes.user + ====ATT&CK==== @@ -14860,10 +18499,10 @@ This search looks for specific command-line arguments that may indicate the exec ====Search==== -| tstats `security_content_summariesonly` count min(_time) values(Processes.process) as process max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process="* /stext *" OR Processes.process="* /scomma *" ) by Processes.parent_process Processes.process_name Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` count min(_time) values(Processes.process) as process max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process="* /stext *" OR Processes.process="* /scomma *" ) by Processes.parent_process Processes.process_name Processes.user +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +|`security_content_ctime(lastTime)` | `detection_of_tools_built_by_nirsoft_filter` ====Associated Analytic Story==== @@ -14876,6 +18515,16 @@ You must be ingesting endpoint data that tracks process activity, including pare ====Required field==== +* _time + +* Processes.process + +* Processes.parent_process + +* Processes.process_name + +* Processes.user + ====ATT&CK==== @@ -14916,7 +18565,7 @@ While legitimate, these NirSoft tools are prone to abuse. You should verfiy that The search looks for modifications to registry keys that control the enforcement of Windows User Account Control (UAC). * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1548.002/ T1548.002] * '''Last Updated''': 2020-11-18 @@ -14925,8 +18574,8 @@ The search looks for modifications to registry keys that control the enforcement ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path=*HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\EnableLUA* Registry.registry_value_name="DWORD (0x00000000)" by Registry.dest, Registry.registry_key_name Registry.user Registry.registry_path Registry.registry_value_name Registry.action -| `drop_dm_object_name(Registry)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path=*HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Policies\\System\\EnableLUA* Registry.registry_value_name="DWORD (0x00000000)" by Registry.dest, Registry.registry_key_name Registry.user Registry.registry_path Registry.registry_value_name Registry.action +| `drop_dm_object_name(Registry)` | `disabling_remote_user_account_control_filter` ====Associated Analytic Story==== @@ -14941,6 +18590,20 @@ To successfully implement this search, you must be ingesting data that records r ====Required field==== +* _time + +* Registry.registry_path + +* Registry.registry_value_name + +* Registry.dest + +* Registry.registry_key_name + +* Registry.user + +* Registry.action + ====ATT&CK==== @@ -14990,10 +18653,10 @@ Detect the usage of comsvcs.dll for dumping the lsass process. ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=rundll32.exe Processes.process=*comsvcs.dll* Processes.process=*MiniDump* by Processes.user Processes.process_name Processes.process Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=rundll32.exe Processes.process=*comsvcs.dll* Processes.process=*MiniDump* by Processes.user Processes.process_name Processes.process Processes.dest +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `dump_lsass_via_comsvcs_dll_filter` ====Associated Analytic Story==== @@ -15002,12 +18665,24 @@ Detect the usage of comsvcs.dll for dumping the lsass process. * [[Documentation:ESSOC:stories:UseCase#Suspicious_Rundll32_Activity|Suspicious Rundll32 Activity]] +* [[Documentation:ESSOC:stories:UseCase#HAFNIUM_Group|HAFNIUM Group]] + ====How To Implement==== You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints, to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" field in the Endpoint data model. ====Required field==== +* _time + +* Processes.process_name + +* Processes.process + +* Processes.user + +* Processes.dest + ====ATT&CK==== @@ -15062,22 +18737,34 @@ During triage, confirm this is procdump.exe executing. If it is the first time a ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=procdump.exe (Processes.process=*-ma* OR Processes.process=*-mm*) Processes.process=*lsass* by Processes.user Processes.process_name Processes.process Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=procdump.exe OR Processes.process_name=procdump64.exe (Processes.process=*-ma* OR Processes.process=*-mm*) Processes.process=*lsass* by Processes.user Processes.process_name Processes.process Processes.dest +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `dump_lsass_via_procdump_filter` ====Associated Analytic Story==== * [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] +* [[Documentation:ESSOC:stories:UseCase#HAFNIUM_Group|HAFNIUM Group]] + ====How To Implement==== To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. ====Required field==== +* _time + +* Processes.process_name + +* Processes.process + +* Processes.user + +* Processes.dest + ====ATT&CK==== @@ -15125,7 +18812,7 @@ Detect a renamed instance of procdump.exe dumping the lsass process. This query During triage, confirm this is procdump.exe executing. If it is the first time a Sysinternals utility has been ran, it is possible there will be a -accepteula on the command line. Review other endpoint data sources for cross process (injection) into lsass.exe. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1003.001/ T1003.001] * '''Last Updated''': 2021-02-01 @@ -15133,23 +18820,39 @@ During triage, confirm this is procdump.exe executing. If it is the first time a
====Search==== -`sysmon` OriginalFileName=procdump process_name!=procdump*.exe EventID=1 (CommandLine=*-ma* OR CommandLine=*-mm*) CommandLine=*lsass* -| rename Computer as dest -| stats count min(_time) as firstTime max(_time) as lastTime by dest, parent_process_name, process_name, OriginalFileName, CommandLine -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +`sysmon` OriginalFileName=procdump process_name!=procdump*.exe EventID=1 (CommandLine=*-ma* OR CommandLine=*-mm*) CommandLine=*lsass* +| rename Computer as dest +| stats count min(_time) as firstTime max(_time) as lastTime by dest, parent_process_name, process_name, OriginalFileName, CommandLine +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `dump_lsass_via_procdump_rename_filter` ====Associated Analytic Story==== * [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] +* [[Documentation:ESSOC:stories:UseCase#HAFNIUM_Group|HAFNIUM Group]] + ====How To Implement==== To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. ====Required field==== +* _time + +* OriginalFileName + +* process_name + +* EventID + +* CommandLine + +* Computer + +* parent_process_name + ====ATT&CK==== @@ -15186,6 +18889,93 @@ None identified. * https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1003.001/atomic_red_team/windows-sysmon.log +''version'': 1 +
+
+ +---- + +===Eventvwr uac bypass=== +The following search identifies Eventvwr bypass by identifying the registry modification into a specific path that eventvwr.msc looks to (but is not valid) upon execution. A successful attack will include a suspicious command to be executed upon eventvwr.msc loading. Upon triage, review the parallel processes that have executed. Identify any additional registry modifications on the endpoint that may look suspicious. Remediate as necessary. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1548.002/ T1548.002] +* '''Last Updated''': 2021-03-01 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path="*mscfile\\shell\\open\\command\\*" by Registry.user, Registry.dest , Registry.registry_value_name +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` +| `drop_dm_object_name(Registry)` +| `eventvwr_uac_bypass_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Windows_Defense_Evasion_Tactics|Windows Defense Evasion Tactics]] + + +====How To Implement==== +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. + +====Required field==== + +* _time + +* Registry.registry_key_name + +* Registry.registry_path + +* Registry.user + +* Registry.dest + +* Registry.registry_value_name + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1548.002 +| Bypass User Account Control +| Defense Evasion, Privilege Escalation +|} + + +====Kill Chain Phase==== + +* Exploitation + +* Privilege Escalation + + +====Known False Positives==== +Some false positives may be present and will need to be filtered. + +====Reference==== + +* https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/ + +* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1548.002/T1548.002.md + +* https://attack.mitre.org/techniques/T1548/002 + +* https://enigma0x3.net/2016/08/15/fileless-uac-bypass-using-eventvwr-exe-and-registry-hijacking/ + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.002/atomic_red_team/windows-sysmon.log + + ''version'': 1
@@ -15205,10 +18995,10 @@ This search looks for processes launched from files that have double extensions ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process = *.doc.exe OR Processes.process = *.htm.exe OR Processes.process = *.html.exe OR Processes.process = *.txt.exe OR Processes.process = *.pdf.exe OR Processes.process = *.doc.exe by Processes.dest Processes.user Processes.process Processes.parent_process -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `drop_dm_object_name(Processes)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process = *.doc.exe OR Processes.process = *.htm.exe OR Processes.process = *.html.exe OR Processes.process = *.txt.exe OR Processes.process = *.pdf.exe OR Processes.process = *.doc.exe by Processes.dest Processes.user Processes.process Processes.parent_process +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `drop_dm_object_name(Processes)` | `execution_of_file_with_multiple_extensions_filter` ====Associated Analytic Story==== @@ -15221,6 +19011,16 @@ To successfully implement this search, you must be ingesting data that records p ====Required field==== +* _time + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + ====ATT&CK==== @@ -15262,7 +19062,7 @@ The search looks for file writes with extensions consistent with a SamSam ransom * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': +* '''ATT&CK''': * '''Last Updated''': 2018-12-14
@@ -15270,12 +19070,12 @@ The search looks for file writes with extensions consistent with a SamSam ransom ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Filesystem.user) as user values(Filesystem.dest) as dest values(Filesystem.file_path) as file_path from datamodel=Endpoint.Filesystem by Filesystem.file_name -| `drop_dm_object_name(Filesystem)` -| `security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Filesystem.user) as user values(Filesystem.dest) as dest values(Filesystem.file_path) as file_path from datamodel=Endpoint.Filesystem by Filesystem.file_name +| `drop_dm_object_name(Filesystem)` +| `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` -| rex field=file_name "(?\.[^\.]+)$" -| search file_extension=.stubbin OR file_extension=.berkshire OR file_extension=.satoshi OR file_extension=.sophos OR file_extension=.keyxml +| rex field=file_name "(?\.[^\.]+)$" +| search file_extension=.stubbin OR file_extension=.berkshire OR file_extension=.satoshi OR file_extension=.sophos OR file_extension=.keyxml | `file_with_samsam_extension_filter` ====Associated Analytic Story==== @@ -15288,6 +19088,16 @@ You must be ingesting data that records file-system activity from your hosts to ====Required field==== +* _time + +* Filesystem.user + +* Filesystem.dest + +* Filesystem.file_path + +* Filesystem.file_name + @@ -15326,12 +19136,12 @@ This search looks for child processes spawned by zoom.exe or zoom.us that has no ====Search==== -| tstats `security_content_summariesonly` min(_time) as firstTime values(Processes.parent_process_name) as parent_process_name values(Processes.parent_process_id) as parent_process_id values(Processes.process_name) as process_name values(Processes.process) as process from datamodel=Endpoint.Processes where (Processes.parent_process_name=zoom.exe OR Processes.parent_process_name=zoom.us) by Processes.process_id Processes.dest -| `drop_dm_object_name(Processes)` -| lookup zoom_first_time_child_process dest as dest process_name as process_name OUTPUT firstTimeSeen -| where isnull(firstTimeSeen) OR firstTimeSeen > relative_time(now(), "`previously_seen_zoom_child_processes_window`") -| `security_content_ctime(firstTime)` -| table firstTime dest, process_id, process_name, parent_process_id, parent_process_name +| tstats `security_content_summariesonly` min(_time) as firstTime values(Processes.parent_process_name) as parent_process_name values(Processes.parent_process_id) as parent_process_id values(Processes.process_name) as process_name values(Processes.process) as process from datamodel=Endpoint.Processes where (Processes.parent_process_name=zoom.exe OR Processes.parent_process_name=zoom.us) by Processes.process_id Processes.dest +| `drop_dm_object_name(Processes)` +| lookup zoom_first_time_child_process dest as dest process_name as process_name OUTPUT firstTimeSeen +| where isnull(firstTimeSeen) OR firstTimeSeen > relative_time(now(), "`previously_seen_zoom_child_processes_window`") +| `security_content_ctime(firstTime)` +| table firstTime dest, process_id, process_name, parent_process_id, parent_process_name |`first_time_seen_child_process_of_zoom_filter` ====Associated Analytic Story==== @@ -15344,6 +19154,22 @@ You must be ingesting data that records process activity from your hosts to popu ====Required field==== +* _time + +* Processes.parent_process_name + +* Processes.parent_process_id + +* Processes.process_name + +* Processes.process + +* Processes.parent_process_name + +* Processes.process_id + +* Processes.dest + ====ATT&CK==== @@ -15384,7 +19210,7 @@ A new child process of zoom isn't malicious by that fact alone. Further investig This search looks for the first and last time a Windows service is seen running in your environment. This table is then cached. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1569.002/ T1569.002] * '''Last Updated''': 2020-07-21 @@ -15392,12 +19218,12 @@ This search looks for the first and last time a Windows service is seen running
====Search==== -`wineventlog_system` EventCode=7036 -| rex field=Message "The (?[-\(\)\s\w]+) service entered the (?\w+) state" -| where state="running" -| lookup previously_seen_running_windows_services service as service OUTPUT firstTimeSeen -| where isnull(firstTimeSeen) OR firstTimeSeen > relative_time(now(), `previously_seen_windows_services_window`) -| table _time dest service +`wineventlog_system` EventCode=7036 +| rex field=Message "The (?[-\(\)\s\w]+) service entered the (?\w+) state" +| where state="running" +| lookup previously_seen_running_windows_services service as service OUTPUT firstTimeSeen +| where isnull(firstTimeSeen) OR firstTimeSeen > relative_time(now(), `previously_seen_windows_services_window`) +| table _time dest service | `first_time_seen_running_windows_service_filter` ====Associated Analytic Story==== @@ -15406,7 +19232,7 @@ This search looks for the first and last time a Windows service is seen running * [[Documentation:ESSOC:stories:UseCase#Orangeworm_Attack_Group|Orangeworm Attack Group]] -* [[Documentation:ESSOC:stories:UseCase#Sunburst_Malware|Sunburst Malware]] +* [[Documentation:ESSOC:stories:UseCase#NOBELIUM_Group|NOBELIUM Group]] ====How To Implement==== @@ -15414,6 +19240,14 @@ While this search does not require you to adhere to Splunk CIM, you must be inge ====Required field==== +* _time + +* EventCode + +* Message + +* dest + ====ATT&CK==== @@ -15454,7 +19288,7 @@ A previously unseen service is not necessarily malicious. Verify that the servic This search looks for command-line arguments that use a `/c` parameter to execute a command that has not previously been seen. This is an implementation on SPL2 of the rule `First time seen command line argument` by @bpatel. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques// ], [https://attack.mitre.org/techniques/T1202/ T1202] * '''Last Updated''': 2021-2-1 @@ -15463,20 +19297,22 @@ This search looks for command-line arguments that use a `/c` parameter to execut ====Search==== -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) +| from read_ssa_enriched_events() +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) | eval dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null), cmd_line=ucast(map_get(input_event, "process"), "string", null), cmd_line_norm=lower(cmd_line), cmd_line_norm=replace(cmd_line_norm, /[0-9a-f]{8}-[0-9a-f]{4}-[1-5][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}/, "GUID"), cmd_line_norm=replace(cmd_line_norm, /(?<=\s)+\\[^:]*(?=\\.*\.\w{3}(\s |$)+)/, "\\PATH"), /* replaces " \\Something\\Something\\command.ext" => "PATH\\command.ext" */ cmd_line_norm=replace(cmd_line_norm, /\w:\\[^:]*(?=\\.*\.\w{3}(\s -|$)+)/, "\\PATH"), /* replaces "C:\\Something\\Something\\command.ext" => "PATH\\command.ext" */ cmd_line_norm=replace(cmd_line_norm, /\d+/, "N") -| where process_name="cmd.exe" AND match_regex(ucast(cmd_line, "string", ""), /.* \/[cC] .*/)=true -| select cmd_line, cmd_line_norm, timestamp, dest_device_id, dest_user_id -| first_time_event input_columns=["cmd_line_norm"] -| where first_time_cmd_line_norm -| eval start_time = timestamp, end_time = timestamp, entities = mvappend(dest_device_id, dest_user_id), body = "TBD" +|$)+)/, "\\PATH"), /* replaces "C:\\Something\\Something\\command.ext" => "PATH\\command.ext" */ cmd_line_norm=replace(cmd_line_norm, /\d+/, "N") +| where process_name="cmd.exe" AND match_regex(ucast(cmd_line, "string", ""), /.* \/[cC] .*/)=true +| select cmd_line, cmd_line_norm, timestamp, dest_device_id, dest_user_id +| first_time_event input_columns=["cmd_line_norm"] +| where first_time_cmd_line_norm +| eval start_time = timestamp, end_time = timestamp, entities = mvappend(dest_device_id, dest_user_id), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Unusual_Processes|Unusual Processes]] + ====How To Implement==== You must be populating the endpoint data model for SSA and specifically the process_name and the process fields @@ -15505,9 +19341,9 @@ You must be populating the endpoint data model for SSA and specifically the proc | Command and Scripting Interpreter | Execution |- -| -| -| +| +| +| |- | T1202 | Indirect Command Execution @@ -15537,6 +19373,107 @@ Legitimate programs can also use command-line arguments to execute. Please verif ---- +===Fodhelper uac bypass=== +Fodhelper.exe has a known UAC bypass as it attempts to look for specific registry keys upon execution, that do not exist. Therefore, an attacker can write its malicious commands in these registry keys to be executed by fodhelper.exe with the highest privilege. \ +1. `HKCU:\Software\Classes\ms-settings\shell\open\command`\ +1. `HKCU:\Software\Classes\ms-settings\shell\open\command\DelegateExecute`\ +1. `HKCU:\Software\Classes\ms-settings\shell\open\command\(default)`\ +Upon triage, fodhelper.exe will have a child process and read access will occur on the registry keys. Isolate the endpoint and review parallel processes for additional behavior. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1112/ T1112], [https://attack.mitre.org/techniques/T1548.002/ T1548.002] +* '''Last Updated''': 2021-03-01 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=fodhelper.exe by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `fodhelper_uac_bypass_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Windows_Defense_Evasion_Tactics|Windows Defense Evasion Tactics]] + + +====How To Implement==== +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. + +====Required field==== + +* _time + +* Processes.parent_process_name + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_name + +* Processes.process + +* Processes.process_id + +* Processes.parent_process_id + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1112 +| Modify Registry +| Defense Evasion +|- +| T1548.002 +| Bypass User Account Control +| Defense Evasion, Privilege Escalation +|} + + +====Kill Chain Phase==== + +* Exploitation + +* Privilege Escalation + + +====Known False Positives==== +Limited to no false positives are expected. + +====Reference==== + +* https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/ + +* https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1548.002/T1548.002.md + +* https://github.com/gushmazuko/WinBypass/blob/master/FodhelperBypass.ps1 + +* https://attack.mitre.org/techniques/T1548/002 + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548.002/atomic_red_team/windows-sysmon.log + + +''version'': 1 +
+
+ +---- + ===Hiding files and directories with attrib exe=== Attackers leverage an existing Windows binary, attrib.exe, to mark specific as hidden by using specific flags so that the victim does not see the file. The search looks for specific command-line arguments to detect the use of attrib.exe to hide files. @@ -15550,8 +19487,8 @@ Attackers leverage an existing Windows binary, attrib.exe, to mark specific as h ====Search==== -| tstats `security_content_summariesonly` count min(_time) values(Processes.process) as process max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=attrib.exe (Processes.process=*+h*) by Processes.parent_process Processes.process_name Processes.user Processes.dest -| `drop_dm_object_name("Processes")` +| tstats `security_content_summariesonly` count min(_time) values(Processes.process) as process max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=attrib.exe (Processes.process=*+h*) by Processes.parent_process Processes.process_name Processes.user Processes.dest +| `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `hiding_files_and_directories_with_attrib_exe_filter` @@ -15568,6 +19505,18 @@ You must be ingesting data that records process activity from your hosts to popu ====Required field==== +* _time + +* Processes.process + +* Processes.process_name + +* Processes.parent_process + +* Processes.user + +* Processes.dest + ====ATT&CK==== @@ -15588,7 +19537,7 @@ You must be ingesting data that records process activity from your hosts to popu ====Known False Positives==== -Some applications and users may legitimately use attrib.exe to interact with the files. +Some applications and users may legitimately use attrib.exe to interact with the files. ====Reference==== @@ -15604,11 +19553,174 @@ Some applications and users may legitimately use attrib.exe to interact with the ---- +===High file deletion frequency=== +This search looks for high frequency of file deletion relative to process name and process id. These events usually happen when the ransomware tries to encrypt the files with the ransomware file extensions and sysmon treat the original files to be deleted as soon it was replace as encrypted data. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1485/ T1485] +* '''Last Updated''': 2021-03-16 + +
+
+ +====Search==== +`sysmon` EventCode=23 TargetFilename IN ("*\.cmd", "*\.ini","*\.gif", "*\.jpg", "*\.jpeg", "*\.db", "*\.ps1", "*\.doc*", "*\.xls*", "*\.ppt*", "*\.bmp","*\.zip", "*\.rar", "*\.7z", "*\.chm", "*\.png", "*\.log", "*\.vbs", "*\.js") +| stats values(TargetFilename) as deleted_files min(_time) as firstTime max(_time) as lastTime count by Computer user EventCode Image ProcessID +|where count >=100 +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `high_file_deletion_frequency_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Clop_Ransomware|Clop Ransomware]] + + +====How To Implement==== +To successfully implement this search, you need to be ingesting logs with the deleted target file name, process name and process id from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. + +====Required field==== + +* EventCode + +* TargetFilename + +* Computer + +* user + +* Image + +* ProcessID + +* _time + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1485 +| Data Destruction +| Impact +|} + + +====Kill Chain Phase==== + +* Exploitation + + +====Known False Positives==== +user may delete bunch of pictures or files in a folder. + +====Reference==== + +* https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html + +* https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log + + +''version'': 1 +
+
+ +---- + +===High process termination frequency=== +This analytics are designed to indentify a high frequency of process termination on a machine which is a common behavior of ransomware malware before encrypting files. This technique is designed to avoid an exception error while accessing (docs, images, database and etc..) in the infected machine for encryption. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1486/ T1486] +* '''Last Updated''': 2021-03-16 + +
+
+ +====Search==== +`sysmon` EventCode=5 +|bin _time span=3s +|stats values(Image) as proc_terminated min(_time) as firstTime max(_time) as lastTime count by Computer EventCode ProcessID +| where count >= 15 +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `high_process_termination_frequency_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Clop_Ransomware|Clop Ransomware]] + + +====How To Implement==== +To successfully implement this search, you need to be ingesting logs with the Image (process full path of terminated process) from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. + +====Required field==== + +* EventCode + +* Image + +* Computer + +* _time + +* ProcessID + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1486 +| Data Encrypted for Impact +| Impact +|} + + +====Kill Chain Phase==== + +* Exploitation + + +====Known False Positives==== +admin or user tool that can terminate multiple process. + +====Reference==== + +* https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html + +* https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log + + +''version'': 1 +
+
+ +---- + ===Illegal access to user content via powersploit modules=== This detection identifies access to PowerSploit modules that enable illegaly access user content, such as key logging, audio recording, screenshots, tapping into http and RDP sessions, etc. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1021/ T1021], [https://attack.mitre.org/techniques/T1113/ T1113], [https://attack.mitre.org/techniques/T1123/ T1123], [https://attack.mitre.org/techniques/T1563/ T1563] * '''Last Updated''': 2020-11-09 @@ -15619,14 +19731,16 @@ This detection identifies access to PowerSploit modules that enable illegaly acc | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, /(?i)Get-HttpStatus/)=true OR match_regex(cmd_line, /(?i)Get-Keystrokes/)=true OR match_regex(cmd_line, /(?i)Get-MicrophoneAudio/)=true OR match_regex(cmd_line, /(?i)Get-NetRDPSession/)=true OR match_regex(cmd_line, /(?i)Get-TimedScreenshot/)=true OR match_regex(cmd_line, /(?i)Get-WebConfig/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -15682,6 +19796,8 @@ None identified. ====Test Dataset==== +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1021/illegal_access_to_content/logAllPowerSploitModulesWithOldNames.log + ''version'': 1
@@ -15693,7 +19809,7 @@ None identified. This detection identifies access to PowerSploit modules that create accounts illegaly. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1585/ T1585] * '''Last Updated''': 2020-11-09 @@ -15704,14 +19820,16 @@ This detection identifies access to PowerSploit modules that create accounts ill | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, /(?i)New-DomainUser/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -15755,6 +19873,8 @@ None identified. ====Test Dataset==== +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1585/illegal_account_creation/logAllPowerSploitModulesWithOldNames.log + ''version'': 1
@@ -15766,7 +19886,7 @@ None identified. This detection identifies access to PowerSploit modules that delete event logs. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1070/ T1070] * '''Last Updated''': 2020-11-09 @@ -15777,14 +19897,16 @@ This detection identifies access to PowerSploit modules that delete event logs. | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, /(?i)event::drop/)=true OR match_regex(cmd_line, /(?i)event::clear/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Windows_Log_Manipulation|Windows Log Manipulation]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -15828,6 +19950,8 @@ None identified. ====Test Dataset==== +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1070/illegal_log_deletion/logAllMimikatzModules.log + ''version'': 1
@@ -15839,7 +19963,7 @@ None identified. This detection identifies use of DSInternals modules that enable or disable accounts illegaly. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1098/ T1098] * '''Last Updated''': 2020-11-09 @@ -15850,14 +19974,16 @@ This detection identifies use of DSInternals modules that enable or disable acco | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, /(?i)Disable-ADDBAccount/)=true OR match_regex(cmd_line, /(?i)Enable-ADDBAccount/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -15905,6 +20031,8 @@ None identified. ====Test Dataset==== +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/logAllDSInternalsModules.log + ''version'': 1
@@ -15916,7 +20044,7 @@ None identified. This detection identifies use of DSInternals modules for illegal management of Active Directoty elements and policies. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1098/ T1098], [https://attack.mitre.org/techniques/T1207/ T1207], [https://attack.mitre.org/techniques/T1484/ T1484] * '''Last Updated''': 2020-11-09 @@ -15927,14 +20055,16 @@ This detection identifies use of DSInternals modules for illegal management of A | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, /(?i)Remove-ADDBObject/)=true OR match_regex(cmd_line, /(?i)Set-ADDBDomainController/)=true OR match_regex(cmd_line, /(?i)Set-ADDBPrimaryGroup/)=true OR match_regex(cmd_line, /(?i)Set-LsaPolicyInformation/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -15986,6 +20116,8 @@ None identified. ====Test Dataset==== +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1484/logAllDSInternalsModules.log + ''version'': 1
@@ -15997,7 +20129,7 @@ None identified. This detection identifies access to PowerSploit modules that enable illegal management of computers and Active Directory elements. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1098/ T1098], [https://attack.mitre.org/techniques/T1207/ T1207], [https://attack.mitre.org/techniques/T1484/ T1484] * '''Last Updated''': 2020-11-09 @@ -16008,15 +20140,17 @@ This detection identifies access to PowerSploit modules that enable illegal mana | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, /(?i)Set-DomainObject/)=true OR match_regex(cmd_line, /(?i)Set-ADObject/)=true OR match_regex(cmd_line, /(?i)Set-DomainObjectOwner/)=true OR match_regex(cmd_line, /(?i)Set-MasterBootRecord/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -16068,6 +20202,8 @@ None identified. ====Test Dataset==== +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1484/logAllPowerSploitModulesWithOldNames.log + ''version'': 1
@@ -16079,7 +20215,7 @@ None identified. This detection identifies access to PowerSploit modules that illegaly elevate general privileges or ensure persistence, e.g., enable manipulation of registry, task scheduling, persistent WMI, access to OS objects under desired identities. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1053/ T1053], [https://attack.mitre.org/techniques/T1134/ T1134], [https://attack.mitre.org/techniques/T1548/ T1548] * '''Last Updated''': 2020-11-09 @@ -16090,14 +20226,18 @@ This detection identifies access to PowerSploit modules that illegaly elevate ge | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, /(?i)Add-DomainObjectAcl/)=true OR match_regex(cmd_line, /(?i)Add-ObjectAcl/)=true OR match_regex(cmd_line, /(?i)Enable-Privilege/)=true OR match_regex(cmd_line, /(?i)New-ElevatedPersistenceOption/)=true OR match_regex(cmd_line, /(?i)New-UserPersistenceOption/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] + +* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -16149,6 +20289,8 @@ None identified. ====Test Dataset==== +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/logAllPowerSploitModulesWithOldNames.log + ''version'': 1
@@ -16160,7 +20302,7 @@ None identified. This detection identifies use of Mimikatz modules for illegal privilege elevation. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1134/ T1134], [https://attack.mitre.org/techniques/T1548/ T1548] * '''Last Updated''': 2020-11-09 @@ -16171,14 +20313,16 @@ This detection identifies use of Mimikatz modules for illegal privilege elevatio | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, /(?i)privilege::debug/)=true OR match_regex(cmd_line, /(?i)token::elevate/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Windows_Privilege_Escalation|Windows Privilege Escalation]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -16226,6 +20370,8 @@ None identified. ====Test Dataset==== +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1548/logAllMimikatzModules.log + ''version'': 1
@@ -16237,7 +20383,7 @@ None identified. This detection identifies use of Mimikatz modules for illegal control over services and processes, including the authentication service. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1055/ T1055], [https://attack.mitre.org/techniques/T1106/ T1106], [https://attack.mitre.org/techniques/T1569/ T1569] * '''Last Updated''': 2020-11-09 @@ -16248,14 +20394,16 @@ This detection identifies use of Mimikatz modules for illegal control over servi | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, /(?i)process::start/)=true OR match_regex(cmd_line, /(?i)service::\+/)=true OR match_regex(cmd_line, /(?i)service::\-/)=true OR match_regex(cmd_line, /(?i)service::start/)=true OR match_regex(cmd_line, /(?i)service::stop/)=true OR match_regex(cmd_line, /(?i)service::suspend/)=true OR match_regex(cmd_line, /(?i)misc::memssp/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Windows_Service_Abuse|Windows Service Abuse]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -16307,6 +20455,8 @@ None identified. ====Test Dataset==== +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1569/logAllMimikatzModules.log + ''version'': 1
@@ -16318,7 +20468,7 @@ None identified. This detection identifies access to PowerSploit modules that enable illegal control of services and processes, such as installing or spoofing of malicious services, injecting malicious code in DLLs and EXEs, invoking shell code and WMI commands, modifying access to service objects, etc. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1055/ T1055], [https://attack.mitre.org/techniques/T1106/ T1106], [https://attack.mitre.org/techniques/T1569/ T1569] * '''Last Updated''': 2020-11-09 @@ -16329,15 +20479,19 @@ This detection identifies access to PowerSploit modules that enable illegal cont | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, /(?i)Install-SSP/)=true OR match_regex(cmd_line, /(?i)Set-CriticalProcess/)=true OR match_regex(cmd_line, /(?i)Install-ServiceBinary/)=true OR match_regex(cmd_line, /(?i)Restore-ServiceBinary/)=true OR match_regex(cmd_line, /(?i)Write-ServiceBinary/)=true OR match_regex(cmd_line, /(?i)Set-ServiceBinaryPath/)=true OR match_regex(cmd_line, /(?i)Invoke-ReflectivePEInjection/)=true OR match_regex(cmd_line, /(?i)Invoke-DllInjection/)=true OR match_regex(cmd_line, /(?i)Invoke-ServiceAbuse/)=true OR match_regex(cmd_line, /(?i)Invoke-Shellcode/)=true OR match_regex(cmd_line, /(?i)Invoke-WScriptUACBypass/)=true OR match_regex(cmd_line, /(?i)Invoke-WmiCommand/)=true OR match_regex(cmd_line, /(?i)Write-HijackDll/)=true OR match_regex(cmd_line, /(?i)Add-ServiceDacl/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Windows_Service_Abuse|Windows Service Abuse]] + +* [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -16389,6 +20543,8 @@ None identified. ====Test Dataset==== +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1569/logAllPowerSploitModulesWithOldNames.log + ''version'': 1
@@ -16400,7 +20556,7 @@ None identified. This search detects a potential kerberoasting attack via service principal name requests * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1558.003/ T1558.003] * '''Last Updated''': 2020-10-16 @@ -16408,10 +20564,10 @@ This search detects a potential kerberoasting attack via service principal name
====Search==== -`wineventlog_security` EventCode=4769 Ticket_Options=0x40810000 Ticket_Encryption_Type=0x17 -| stats count min(_time) as firstTime max(_time) as lastTime by dest, service, service_id, Ticket_Encryption_Type, Ticket_Options -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` +`wineventlog_security` EventCode=4769 Ticket_Options=0x40810000 Ticket_Encryption_Type=0x17 +| stats count min(_time) as firstTime max(_time) as lastTime by dest, service, service_id, Ticket_Encryption_Type, Ticket_Options +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` | `kerberoasting_spn_request_with_rc4_encryption_filter` ====Associated Analytic Story==== @@ -16424,6 +20580,20 @@ You must be ingesting endpoint data that tracks process activity, and include th ====Required field==== +* _time + +* EventCode + +* Ticket_Options + +* Ticket_Encryption_Type + +* dest + +* service + +* service_id + ====ATT&CK==== @@ -16469,7 +20639,7 @@ This search looks for processes referencing the plist files that determine which * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': +* '''ATT&CK''': * '''Last Updated''': 2020-02-07
@@ -16477,10 +20647,10 @@ This search looks for processes referencing the plist files that determine which ====Search==== -| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process="*com.apple.loginwindow*" by Processes.user Processes.process_name Processes.parent_process_name Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process="*com.apple.loginwindow*" by Processes.user Processes.process_name Processes.parent_process_name Processes.dest +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `macos___re_opened_applications_filter` ====Associated Analytic Story==== @@ -16491,6 +20661,20 @@ In order to properly run this search, Splunk needs to ingest process data from y ====Required field==== +* _time + +* Processes.process + +* Processes.parent_process + +* Processes.user + +* Processes.process_name + +* Processes.parent_process_name + +* Processes.dest + @@ -16529,10 +20713,10 @@ This search looks for PowerShell processes started with parameters to modify the ====Search==== -| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=powershell.exe Processes.process=*-WindowStyle* Processes.process=*hidden* Processes.process="*New-Object*" by Processes.user Processes.process_name Processes.parent_process_name Processes.process Processes.dest -| `drop_dm_object_name(Processes)` +| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=powershell.exe Processes.process=*-WindowStyle* Processes.process=*hidden* Processes.process="*New-Object*" by Processes.user Processes.process_name Processes.parent_process_name Processes.process Processes.dest +| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | `malicious_powershell_process___connect_to_internet_with_hidden_window_filter` ====Associated Analytic Story==== @@ -16541,12 +20725,26 @@ This search looks for PowerShell processes started with parameters to modify the * [[Documentation:ESSOC:stories:UseCase#Possible_Backdoor_Activity_Associated_With_MUDCARP_Espionage_Campaigns|Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns]] +* [[Documentation:ESSOC:stories:UseCase#HAFNIUM_Group|HAFNIUM Group]] + ====How To Implement==== You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. ====Required field==== +* _time + +* Processes.process + +* Processes.process_name + +* Processes.user + +* Processes.parent_process_name + +* Processes.dest + ====ATT&CK==== @@ -16598,17 +20796,17 @@ This search looks for PowerShell processes that have encoded the script within t ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = powershell.exe (Processes.process=*-EncodedCommand* OR Processes.process=*-enc*) by Processes.user Processes.process_name Processes.process Processes.parent_process_name Processes.dest Processes.process_id -| `drop_dm_object_name(Processes)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = powershell.exe (Processes.process=*-EncodedCommand* OR Processes.process=*-enc*) by Processes.user Processes.process_name Processes.process Processes.parent_process_name Processes.dest Processes.process_id +| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | `malicious_powershell_process___encoded_command_filter` ====Associated Analytic Story==== * [[Documentation:ESSOC:stories:UseCase#Malicious_PowerShell|Malicious PowerShell]] -* [[Documentation:ESSOC:stories:UseCase#Sunburst_Malware|Sunburst Malware]] +* [[Documentation:ESSOC:stories:UseCase#NOBELIUM_Group|NOBELIUM Group]] ====How To Implement==== @@ -16616,6 +20814,20 @@ You must be ingesting data that records process activity from your hosts to popu ====Required field==== +* _time + +* Processes.process_name + +* Processes.process + +* Processes.user + +* Processes.parent_process_name + +* Processes.dest + +* Processes.process_id + ====ATT&CK==== @@ -16667,22 +20879,38 @@ This search looks for PowerShell processes started with parameters used to bypas ====Search==== -| tstats `security_content_summariesonly` values(Processes.process_id) as process_id, values(Processes.parent_process_id) as parent_process_id values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=powershell.exe (Processes.process="* -ex*" OR Processes.process="* bypass *") by Processes.process_id, Processes.user, Processes.dest -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` values(Processes.process_id) as process_id, values(Processes.parent_process_id) as parent_process_id values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=powershell.exe (Processes.process="* -ex*" OR Processes.process="* bypass *") by Processes.process_id, Processes.user, Processes.dest +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `malicious_powershell_process___execution_policy_bypass_filter` ====Associated Analytic Story==== * [[Documentation:ESSOC:stories:UseCase#DHS_Report_TA18-074A|DHS Report TA18-074A]] +* [[Documentation:ESSOC:stories:UseCase#HAFNIUM_Group|HAFNIUM Group]] + ====How To Implement==== You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. ====Required field==== +* _time + +* Processes.process_id + +* Processes.parent_process_id + +* Processes.process + +* Processes.process_name + +* Processes.user + +* Processes.dest + ====ATT&CK==== @@ -16734,12 +20962,12 @@ This search looks for PowerShell processes launched with arguments that have cha ====Search==== -| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=powershell.exe by Processes.user Processes.process_name Processes.parent_process_name Processes.dest Processes.process -| `drop_dm_object_name(Processes)` +| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=powershell.exe by Processes.user Processes.process_name Processes.parent_process_name Processes.dest Processes.process +| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` -| eval num_obfuscation = (mvcount(split(process,"`"))-1) + (mvcount(split(process, "^"))-1) + (mvcount(split(process, "'"))-1) -| `malicious_powershell_process_with_obfuscation_techniques_filter` +| eval num_obfuscation = (mvcount(split(process,"`"))-1) + (mvcount(split(process, "^"))-1) + (mvcount(split(process, "'"))-1) +| `malicious_powershell_process_with_obfuscation_techniques_filter` | search num_obfuscation > 10 ====Associated Analytic Story==== @@ -16752,6 +20980,20 @@ You must be ingesting data that records process activity from your hosts to popu ====Required field==== +* _time + +* Processes.process + +* Processes.parent_process + +* Processes.process_name + +* Processes.user + +* Processes.parent_process_name + +* Processes.dest + ====ATT&CK==== @@ -16794,7 +21036,7 @@ These characters might be legitimately on the command-line, but it is not common This search looks for registry activity associated with modifications to the registry key `HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors`. In this scenario, an attacker can load an arbitrary .dll into the print-monitor registry by giving the full path name to the after.dll. The system will execute the .dll with elevated (SYSTEM) permissions and will persist after reboot. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1547.010/ T1547.010] * '''Last Updated''': 2020-11-23 @@ -16803,8 +21045,8 @@ This search looks for registry activity associated with modifications to the reg ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.action=modified AND Registry.registry_path="*CurrentControlSet\\Control\\Print\\Monitors*" by Registry.dest, Registry.registry_key_name Registry.user Registry.registry_path Registry.registry_value_name Registry.action -| `drop_dm_object_name(Registry)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.action=modified AND Registry.registry_path="*CurrentControlSet\\Control\\Print\\Monitors*" by Registry.dest, Registry.registry_key_name Registry.user Registry.registry_path Registry.registry_value_name Registry.action +| `drop_dm_object_name(Registry)` | `monitor_registry_keys_for_print_monitors_filter` ====Associated Analytic Story==== @@ -16819,6 +21061,20 @@ To successfully implement this search, you must be ingesting data that records r ====Required field==== +* _time + +* Registry.action + +* Registry.registry_path + +* Registry.dest + +* Registry.registry_key_name + +* Registry.user + +* Registry.registry_value_name + ====ATT&CK==== @@ -16859,7 +21115,7 @@ You will encounter noise from legitimate print-monitor registry entries. Attacker activity may compromise executing several LOLBAS applications in conjunction to accomplish their objectives. We are looking for more than usual LOLBAS applications over a window of time, by building profiles per machine. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1053/ T1053] * '''Last Updated''': 2020-08-25 @@ -16867,20 +21123,22 @@ Attacker activity may compromise executing several LOLBAS applications in conjun
====Search==== - -| from read_ssa_enriched_events() -| eval device=ucast(map_get(input_event, "dest_device_id"), "string", null), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) -| where process_name=="regsvcs.exe" OR process_name=="ftp.exe" OR process_name=="dfsvc.exe" OR process_name=="rasautou.exe" OR process_name=="schtasks.exe" OR process_name=="xwizard.exe" OR process_name=="findstr.exe" OR process_name=="esentutl.exe" OR process_name=="cscript.exe" OR process_name=="reg.exe" OR process_name=="csc.exe" OR process_name=="atbroker.exe" OR process_name=="print.exe" OR process_name=="pcwrun.exe" OR process_name=="vbc.exe" OR process_name=="rpcping.exe" OR process_name=="wsreset.exe" OR process_name=="ilasm.exe" OR process_name=="certutil.exe" OR process_name=="replace.exe" OR process_name=="mshta.exe" OR process_name=="bitsadmin.exe" OR process_name=="wscript.exe" OR process_name=="ieexec.exe" OR process_name=="cmd.exe" OR process_name=="microsoft.workflow.compiler.exe" OR process_name=="runscripthelper.exe" OR process_name=="makecab.exe" OR process_name=="forfiles.exe" OR process_name=="desktopimgdownldr.exe" OR process_name=="control.exe" OR process_name=="msbuild.exe" OR process_name=="register-cimprovider.exe" OR process_name=="tttracer.exe" OR process_name=="ie4uinit.exe" OR process_name=="sc.exe" OR process_name=="bash.exe" OR process_name=="hh.exe" OR process_name=="cmstp.exe" OR process_name=="mmc.exe" OR process_name=="jsc.exe" OR process_name=="scriptrunner.exe" OR process_name=="odbcconf.exe" OR process_name=="extexport.exe" OR process_name=="msdt.exe" OR process_name=="diskshadow.exe" OR process_name=="extrac32.exe" OR process_name=="eventvwr.exe" OR process_name=="mavinject.exe" OR process_name=="regasm.exe" OR process_name=="gpscript.exe" OR process_name=="rundll32.exe" OR process_name=="regsvr32.exe" OR process_name=="regedit.exe" OR process_name=="msiexec.exe" OR process_name=="gfxdownloadwrapper.exe" OR process_name=="presentationhost.exe" OR process_name=="regini.exe" OR process_name=="wmic.exe" OR process_name=="runonce.exe" OR process_name=="syncappvpublishingserver.exe" OR process_name=="verclsid.exe" OR process_name=="psr.exe" OR process_name=="infdefaultinstall.exe" OR process_name=="explorer.exe" OR process_name=="expand.exe" OR process_name=="installutil.exe" OR process_name=="netsh.exe" OR process_name=="wab.exe" OR process_name=="dnscmd.exe" OR process_name=="at.exe" OR process_name=="pcalua.exe" OR process_name=="cmdkey.exe" OR process_name=="msconfig.exe" -| stats count(process_name) as lolbas_counter by device,span(timestamp, 300s) -| eval lolbas_counter=lolbas_counter*1.0 -| rename window_end as timestamp -| adaptive_threshold algorithm="quantile" value="lolbas_counter" entity="device" window=2419200000L -| where label AND quantile>0.99 -| eval start_time = window_start, end_time = timestamp, entities = mvappend(device), body = "TBD" + +| from read_ssa_enriched_events() +| eval device=ucast(map_get(input_event, "dest_device_id"), "string", null), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) +| where process_name=="regsvcs.exe" OR process_name=="ftp.exe" OR process_name=="dfsvc.exe" OR process_name=="rasautou.exe" OR process_name=="schtasks.exe" OR process_name=="xwizard.exe" OR process_name=="findstr.exe" OR process_name=="esentutl.exe" OR process_name=="cscript.exe" OR process_name=="reg.exe" OR process_name=="csc.exe" OR process_name=="atbroker.exe" OR process_name=="print.exe" OR process_name=="pcwrun.exe" OR process_name=="vbc.exe" OR process_name=="rpcping.exe" OR process_name=="wsreset.exe" OR process_name=="ilasm.exe" OR process_name=="certutil.exe" OR process_name=="replace.exe" OR process_name=="mshta.exe" OR process_name=="bitsadmin.exe" OR process_name=="wscript.exe" OR process_name=="ieexec.exe" OR process_name=="cmd.exe" OR process_name=="microsoft.workflow.compiler.exe" OR process_name=="runscripthelper.exe" OR process_name=="makecab.exe" OR process_name=="forfiles.exe" OR process_name=="desktopimgdownldr.exe" OR process_name=="control.exe" OR process_name=="msbuild.exe" OR process_name=="register-cimprovider.exe" OR process_name=="tttracer.exe" OR process_name=="ie4uinit.exe" OR process_name=="sc.exe" OR process_name=="bash.exe" OR process_name=="hh.exe" OR process_name=="cmstp.exe" OR process_name=="mmc.exe" OR process_name=="jsc.exe" OR process_name=="scriptrunner.exe" OR process_name=="odbcconf.exe" OR process_name=="extexport.exe" OR process_name=="msdt.exe" OR process_name=="diskshadow.exe" OR process_name=="extrac32.exe" OR process_name=="eventvwr.exe" OR process_name=="mavinject.exe" OR process_name=="regasm.exe" OR process_name=="gpscript.exe" OR process_name=="rundll32.exe" OR process_name=="regsvr32.exe" OR process_name=="regedit.exe" OR process_name=="msiexec.exe" OR process_name=="gfxdownloadwrapper.exe" OR process_name=="presentationhost.exe" OR process_name=="regini.exe" OR process_name=="wmic.exe" OR process_name=="runonce.exe" OR process_name=="syncappvpublishingserver.exe" OR process_name=="verclsid.exe" OR process_name=="psr.exe" OR process_name=="infdefaultinstall.exe" OR process_name=="explorer.exe" OR process_name=="expand.exe" OR process_name=="installutil.exe" OR process_name=="netsh.exe" OR process_name=="wab.exe" OR process_name=="dnscmd.exe" OR process_name=="at.exe" OR process_name=="pcalua.exe" OR process_name=="cmdkey.exe" OR process_name=="msconfig.exe" +| stats count(process_name) as lolbas_counter by device,span(timestamp, 300s) +| eval lolbas_counter=lolbas_counter*1.0 +| rename window_end as timestamp +| adaptive_threshold algorithm="quantile" value="lolbas_counter" entity="device" window=2419200000L +| where label AND quantile>0.99 +| eval start_time = window_start, end_time = timestamp, entities = mvappend(device), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Unusual_Processes|Unusual Processes]] + ====How To Implement==== Collect endpoint data such as sysmon or 4688 events. @@ -16947,10 +21205,10 @@ This search looks for the execution of `nltest.exe` with command-line arguments ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=nltest.exe OR Processes.process_name!=nltest.exe) (Processes.process=*/domain_trusts* OR Processes.process=*/all_trusts*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=nltest.exe OR Processes.process_name!=nltest.exe) (Processes.process=*/domain_trusts* OR Processes.process=*/all_trusts*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `nltest_domain_trust_discovery_filter` ====Associated Analytic Story==== @@ -16963,6 +21221,22 @@ To successfully implement this search you need to be ingesting information on pr ====Required field==== +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_id + +* Processes.parent_process_id + ====ATT&CK==== @@ -17007,6 +21281,97 @@ Administrators may use nltest for troubleshooting purposes, otherwise, rarely us * https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1482/atomic_red_team/windows-sysmon.log +''version'': 1 +
+
+ +---- + +===Nishang powershelltcponeline=== +This query detects the Nishang Invoke-PowerShellTCPOneLine utility that spawns a call back to a remote command and control server. This is a powershell oneliner. In addition, this will capture on the command-line additional utilities used by Nishang. Triage the endpoint and identify any parallel processes that look suspicious. Review the reputation of the remote IP or domain contacted by the powershell process. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059.001/ T1059.001] +* '''Last Updated''': 2021-03-03 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=powershell.exe OR Processes.process_name=pwsh.exe OR Processes.process_name=PowerShell_ISE.exe (Processes.process=*Net.Sockets.TCPClient* AND Processes.process=*System.Text.ASCIIEncoding*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `nishang_powershelltcponeline_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#HAFNIUM_Group|HAFNIUM Group]] + + +====How To Implement==== +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. + +====Required field==== + +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_name + +* Processes.process_id + +* Processes.parent_process_id + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1059.001 +| PowerShell +| Execution +|} + + +====Kill Chain Phase==== + +* Exploitation + + +====Known False Positives==== +Limited false positives may be present. Filter as needed based on initial analysis. + +====Reference==== + +* https://github.com/samratashok/nishang/blob/master/Shells/Invoke-PowerShellTcpOneLine.ps1 + +* https://www.volexity.com/blog/2021/03/02/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities/ + +* https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/ + +* https://blog.rapid7.com/2021/03/03/rapid7s-insightidr-enables-detection-and-response-to-microsoft-exchange-0-day/ + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.001/atomic_red_team/windows-sysmon.log + + ''version'': 1
@@ -17028,22 +21393,40 @@ This technique uses "Install from Media" (IFM), which will extract a copy of the ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=ntdsutil.exe Processes.process=*ntds* Processes.process=*create*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process_name=ntdsutil.exe Processes.process=*ntds* Processes.process=*create*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | `ntdsutil_export_ntds_filter` ====Associated Analytic Story==== * [[Documentation:ESSOC:stories:UseCase#Credential_Dumping|Credential Dumping]] +* [[Documentation:ESSOC:stories:UseCase#HAFNIUM_Group|HAFNIUM Group]] + ====How To Implement==== You must be ingesting endpoint data that tracks process activity, including parent-child relationships from your endpoints, to populate the Endpoint data model in the Processes node. The command-line arguments are mapped to the "process" field in the Endpoint data model. ====Required field==== +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_id + +* Processes.parent_process_id + ====ATT&CK==== @@ -17101,10 +21484,10 @@ Microsoft Windows contains accessibility features that can be launched with a ke ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Filesystem.user) as user values(Filesystem.dest) as dest values(Filesystem.file_path) as file_path from datamodel=Endpoint.Filesystem where (Filesystem.file_path=*\\Windows\\System32\\sethc.exe* OR Filesystem.file_path=*\\Windows\\System32\\utilman.exe* OR Filesystem.file_path=*\\Windows\\System32\\osk.exe* OR Filesystem.file_path=*\\Windows\\System32\\Magnify.exe* OR Filesystem.file_path=*\\Windows\\System32\\Narrator.exe* OR Filesystem.file_path=*\\Windows\\System32\\DisplaySwitch.exe* OR Filesystem.file_path=*\\Windows\\System32\\AtBroker.exe*) by Filesystem.file_name Filesystem.dest -| `drop_dm_object_name(Filesystem)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Filesystem.user) as user values(Filesystem.dest) as dest values(Filesystem.file_path) as file_path from datamodel=Endpoint.Filesystem where (Filesystem.file_path=*\\Windows\\System32\\sethc.exe* OR Filesystem.file_path=*\\Windows\\System32\\utilman.exe* OR Filesystem.file_path=*\\Windows\\System32\\osk.exe* OR Filesystem.file_path=*\\Windows\\System32\\Magnify.exe* OR Filesystem.file_path=*\\Windows\\System32\\Narrator.exe* OR Filesystem.file_path=*\\Windows\\System32\\DisplaySwitch.exe* OR Filesystem.file_path=*\\Windows\\System32\\AtBroker.exe*) by Filesystem.file_name Filesystem.dest +| `drop_dm_object_name(Filesystem)` +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` | `overwriting_accessibility_binaries_filter` ====Associated Analytic Story==== @@ -17117,6 +21500,16 @@ You must be ingesting data that records the filesystem activity from your hosts ====Required field==== +* _time + +* Filesystem.dest + +* Filesystem.file_path + +* Filesystem.file_name + +* Filesystem.dest + ====ATT&CK==== @@ -17157,7 +21550,7 @@ Microsoft may provide updates to these binaries. Verify that these changes do no This detection identifies use of PowerSploit modules that facilitate access probing with admin credentials as well as probing access to system services. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1098/ T1098] * '''Last Updated''': 2020-11-04 @@ -17168,14 +21561,16 @@ This detection identifies use of PowerSploit modules that facilitate access prob | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, /(?i)Test-AdminAccess/)=true OR match_regex(cmd_line, /(?i)Invoke-CheckLocalAdminAccess/)=true OR match_regex(cmd_line, /(?i)Test-ServiceDaclPermission/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Windows_Privilege_Escalation|Windows Privilege Escalation]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -17234,7 +21629,7 @@ None identified. This search looks for a process launching an `*.lnk` file under `C:\User*` or `*\Local\Temp\*`. This is common behavior used by various spear phishing tools. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1566.002/ T1566.002] * '''Last Updated''': 2021-01-28 @@ -17243,17 +21638,17 @@ This search looks for a process launching an `*.lnk` file under `C:\User*` or `* ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_name="*.lnk" AND Filesystem.file_path="C:\\Temp*" by _time span=1h Filesystem.process_id Filesystem.file_name Filesystem.file_path Filesystem.file_hash Filesystem.user -| `drop_dm_object_name(Filesystem)` -| rename process_id as lnk_pid +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_name="*.lnk" AND Filesystem.file_path="C:\\Temp*" by _time span=1h Filesystem.process_id Filesystem.file_name Filesystem.file_path Filesystem.file_hash Filesystem.user +| `drop_dm_object_name(Filesystem)` +| rename process_id as lnk_pid | join lnk_pid, _time [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=* by _time span=1h Processes.parent_process_id Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process -| `drop_dm_object_name(Processes)` -| rename parent_process_id as lnk_pid -| fields _time lnk_pid process_id dest process_name process_path process] -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| table firstTime, lastTime, lnk_pid, process_id, user, dest, file_name, file_path, process_name, process, process_path, file_hash +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=* by _time span=1h Processes.parent_process_id Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process +| `drop_dm_object_name(Processes)` +| rename parent_process_id as lnk_pid +| fields _time lnk_pid process_id dest process_name process_path process] +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| table firstTime, lastTime, lnk_pid, process_id, user, dest, file_name, file_path, process_name, process, process_path, file_hash | `process_creating_lnk_file_in_suspicious_location_filter` ====Associated Analytic Story==== @@ -17266,6 +21661,22 @@ You must be ingesting data that records filesystem and process activity from you ====Required field==== +* _time + +* Filesystem.file_name + +* Filesystem.file_path + +* Filesystem.process_id + +* Filesystem.file_name + +* Filesystem.file_path + +* Filesystem.file_hash + +* Filesystem.user + ====ATT&CK==== @@ -17308,11 +21719,101 @@ This detection should yield little or no false positive results. It is uncommon ---- +===Process deleting its process file path=== +This detection is to identify a suspicious process that tries to delete the process file path related to its process. This technique is known to be defense evasion once a certain condition of malware is satisfied or not. Clop ransomware use this technique where it will try to delete its process file path using a .bat command if the keyboard layout is not the layout it tries to infect. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003.002/ T1003.002] +* '''Last Updated''': 2021-03-17 + +
+
+ +====Search==== +`sysmon` EventCode=1 cmdline = "*/c del*" Image = "*\\cmd.exe" +|eval result = if(like(process,"%".parent_process."%"), "Found", "Not Found") +| stats min(_time) as firstTime max(_time) as lastTime count by Computer user ParentImage ParentCommandLine Image cmdline EventCode ProcessID result +| where result = "Found" +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `process_deleting_its_process_file_path_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Clop_Ransomware|Clop Ransomware]] + + +====How To Implement==== +You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. + +====Required field==== + +* EventCode + +* Computer + +* user + +* ParentImage + +* ParentCommandLine + +* Image + +* cmdline + +* ProcessID + +* result + +* _time + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1003.002 +| Security Account Manager +| Credential Access +|} + + +====Kill Chain Phase==== + +* Exploitation + + +====Known False Positives==== +unknown + +====Reference==== + +* https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html + +* https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log + + +''version'': 1 +
+
+ +---- + ===Process execution via wmi=== This search looks for processes launched via WMI. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1047/ T1047] * '''Last Updated''': 2020-03-16 @@ -17321,8 +21822,8 @@ This search looks for processes launched via WMI. ====Search==== -| tstats `security_content_summariesonly` count values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes where Processes.parent_process_name = *WmiPrvSE.exe by Processes.user Processes.dest Processes.process_name -| `drop_dm_object_name("Processes")` +| tstats `security_content_summariesonly` count values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes where Processes.parent_process_name = *WmiPrvSE.exe by Processes.user Processes.dest Processes.process_name +| `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `process_execution_via_wmi_filter` @@ -17337,6 +21838,18 @@ You must be ingesting endpoint data that tracks process activity, including pare ====Required field==== +* _time + +* Processes.process + +* Processes.parent_process_name + +* Processes.user + +* Processes.dest + +* Processes.process_name + ====ATT&CK==== @@ -17377,8 +21890,8 @@ Although unlikely, administrators may use wmi to execute commands for legitimate This search looks for processes in an MacOS system that is tapping keyboard events in MacOS, and essentially monitoring all keystrokes made by a user. This is a common technique used by RATs to log keystrokes from a victim, although it can also be used by legitimate processes like Siri to react on human input * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': +* '''Datamodel''': +* '''ATT&CK''': * '''Last Updated''': 2019-01-25
@@ -17386,11 +21899,11 @@ This search looks for processes in an MacOS system that is tapping keyboard even ====Search==== -| from datamodel Alerts.Alerts -| search app=osquery:results name=pack_osx-attacks_Keyboard_Event_Taps +| from datamodel Alerts.Alerts +| search app=osquery:results name=pack_osx-attacks_Keyboard_Event_Taps | rename columns.cmdline as cmd, columns.name as process_name, columns.pid as process_id -| dedup host,process_name -| table host,process_name, cmd, process_id +| dedup host,process_name +| table host,process_name, cmd, process_id | `processes_tapping_keyboard_events_filter` ====Associated Analytic Story==== @@ -17403,6 +21916,20 @@ In order to properly run this search, Splunk needs to ingest data from your osqu ====Required field==== +* _time + +* app + +* name + +* columns.cmdline + +* columns.name + +* columns.pid + +* host + @@ -17439,10 +21966,10 @@ This search looks for processes launching netsh.exe. Netsh is a command-line scr ====Search==== -| tstats `security_content_summariesonly` count values(Processes.process) AS Processes.process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process=*netsh* by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.user Processes.dest -|`drop_dm_object_name("Processes")` -|`security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` count values(Processes.process) AS Processes.process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process=*netsh* by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.user Processes.dest +|`drop_dm_object_name("Processes")` +|`security_content_ctime(firstTime)` +|`security_content_ctime(lastTime)` |`processes_launching_netsh_filter` ====Associated Analytic Story==== @@ -17459,6 +21986,20 @@ To successfully implement this search, you must be ingesting data that records p ====Required field==== +* _time + +* Processes.process + +* Processes.parent_process_name + +* Processes.parent_process + +* Processes.process_name + +* Processes.user + +* Processes.dest + ====ATT&CK==== @@ -17495,11 +22036,94 @@ Some VPN applications are known to launch netsh.exe. Outside of these instances, ---- +===Ransomware notes bulk creation=== +The following analytics identifies a big number of instance of ransomware notes (filetype e.g .txt, .html, .hta) file creation to the infected machine. This behavior is a good sensor if the ransomware note filename is quite new for security industry or the ransomware note filename is not in your lookup table list for monitoring. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1486/ T1486] +* '''Last Updated''': 2021-03-12 + +
+
+ +====Search==== +`sysmon` EventCode=11 file_name IN ("*\.txt","*\.html","*\.hta") +| stats min(_time) as firstTime max(_time) as lastTime dc(TargetFilename) as unique_readme_path_count values(TargetFilename) as list_of_readme_path by Computer Image file_name +| where unique_readme_path_count >= 50 +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `ransomware_notes_bulk_creation_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Clop_Ransomware|Clop Ransomware]] + + +====How To Implement==== +You must be ingesting data that records the filesystem activity from your hosts to populate the Endpoint file-system data model node. If you are using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which you want to collect data. + +====Required field==== + +* EventCode + +* file_name + +* _time + +* TargetFilename + +* Computer + +* Image + +* user + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1486 +| Data Encrypted for Impact +| Impact +|} + + +====Kill Chain Phase==== + +* Obfuscation + + +====Known False Positives==== +unknown + +====Reference==== + +* https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html + +* https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log + + +''version'': 1 +
+
+ +---- + ===Rare parent-child process relationship=== An attacker may use LOLBAS tools spawned from vulnerable applications not typically used by system administrators. This search leverages the Splunk Streaming ML DSP plugin to find rare parent/child relationships. The list of application has been extracted from https://github.com/LOLBAS-Project/LOLBAS/tree/master/yml/OSBinaries * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1203/ T1203], [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1053/ T1053], [https://attack.mitre.org/techniques/T1072/ T1072] * '''Last Updated''': 2020-08-13 @@ -17508,22 +22132,24 @@ An attacker may use LOLBAS tools spawned from vulnerable applications not typica ====Search==== -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) -| eval parent_process=lower(ucast(map_get(input_event, "parent_process_name"), "string", null)), parent_process_name=mvindex(split(parent_process, "\\"), -1), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null) -| where parent_process_name!=null -| select parent_process_name, process_name, timestamp, dest_device_id, dest_user_id -| conditional_anomaly conditional="parent_process_name" target="process_name" -| rename output as input -| where input < 1 -| adaptive_threshold algorithm="quantile" entity="parent_process_name" window=604800000L +| from read_ssa_enriched_events() +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) +| eval parent_process=lower(ucast(map_get(input_event, "parent_process_name"), "string", null)), parent_process_name=mvindex(split(parent_process, "\\"), -1), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null) +| where parent_process_name!=null +| select parent_process_name, process_name, timestamp, dest_device_id, dest_user_id +| conditional_anomaly conditional="parent_process_name" target="process_name" +| rename output as input +| where input < 1 +| adaptive_threshold algorithm="quantile" entity="parent_process_name" window=604800000L | where label AND quantile<0.1 AND (process_name="powershell.exe" OR process_name="regsvcs.exe" OR process_name="ftp.exe" OR process_name="dfsvc.exe" OR process_name="rasautou.exe" OR process_name="schtasks.exe" OR process_name="xwizard.exe" OR process_name="findstr.exe" OR process_name="esentutl.exe" OR process_name="cscript.exe" OR process_name="reg.exe" OR process_name="csc.exe" OR process_name="atbroker.exe" OR process_name="print.exe" OR process_name="pcwrun.exe" OR process_name="vbc.exe" OR process_name="rpcping.exe" OR process_name="wsreset.exe" OR process_name="ilasm.exe" OR process_name="certutil.exe" OR process_name="replace.exe" OR process_name="mshta.exe" OR process_name="bitsadmin.exe" OR process_name="wscript.exe" OR process_name="ieexec.exe" OR process_name="cmd.exe" OR process_name="microsoft.workflow.compiler.exe" OR process_name="runscripthelper.exe" OR process_name="makecab.exe" OR process_name="forfiles.exe" OR process_name="desktopimgdownldr.exe" OR process_name="control.exe" OR process_name="msbuild.exe" OR process_name="register-cimprovider.exe" OR process_name="tttracer.exe" OR process_name="ie4uinit.exe" OR process_name="sc.exe" OR process_name="bash.exe" OR process_name="hh.exe" OR process_name="cmstp.exe" OR process_name="mmc.exe" OR process_name="jsc.exe" OR process_name="scriptrunner.exe" OR process_name="odbcconf.exe" OR process_name="extexport.exe" OR process_name="msdt.exe" OR process_name="diskshadow.exe" OR process_name="extrac32.exe" OR process_name="eventvwr.exe" OR process_name="mavinject.exe" OR process_name="regasm.exe" OR process_name="gpscript.exe" OR process_name="rundll32.exe" OR process_name="regsvr32.exe" OR process_name="regedit.exe" OR process_name="msiexec.exe" OR process_name="gfxdownloadwrapper.exe" OR process_name="presentationhost.exe" OR process_name="regini.exe" OR process_name="wmic.exe" OR process_name="runonce.exe" OR process_name="syncappvpublishingserver.exe" OR process_name="verclsid.exe" OR process_name="psr.exe" OR process_name="infdefaultinstall.exe" OR process_name="explorer.exe" OR process_name="expand.exe" OR process_name="installutil.exe" OR process_name="netsh.exe" OR process_name="wab.exe" OR process_name="dnscmd.exe" OR process_name="at.exe" OR process_name="pcalua.exe" OR process_name="cmdkey.exe" OR process_name="msconfig.exe") -| eval start_time = timestamp, end_time = timestamp, entities = mvappend(dest_device_id, dest_user_id), body = "TBD" -| into write_ssa_detected_events(); +| eval start_time = timestamp, end_time = timestamp, entities = mvappend(dest_device_id, dest_user_id), body = "TBD" +| into write_null(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Unusual_Processes|Unusual Processes]] + ====How To Implement==== Collect endpoint data such as sysmon or 4688 events. @@ -17591,7 +22217,7 @@ Some custom tools used by admins could be used rarely to launch remotely applica This detection identifies access to PowerSploit modules that discover accounts, groups and policies that can be accessed or taken over. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1087/ T1087], [https://attack.mitre.org/techniques/T1484/ T1484] * '''Last Updated''': 2020-11-05 @@ -17602,14 +22228,16 @@ This detection identifies access to PowerSploit modules that discover accounts, | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, /(?i)Find-DomainLocalGroupMember/)=true OR match_regex(cmd_line, /(?i)Invoke-EnumerateLocalAdmin/)=true OR match_regex(cmd_line, /(?i)Find-DomainUserEvent/)=true OR match_regex(cmd_line, /(?i)Invoke-EventHunter/)=true OR match_regex(cmd_line, /(?i)Find-DomainUserLocation/)=true OR match_regex(cmd_line, /(?i)Invoke-UserHunter/)=true OR match_regex(cmd_line, /(?i)Get-DomainForeignGroupMember/)=true OR match_regex(cmd_line, /(?i)Find-ForeignGroup/)=true OR match_regex(cmd_line, /(?i)Get-DomainForeignUser/)=true OR match_regex(cmd_line, /(?i)Find-ForeignUser/)=true OR match_regex(cmd_line, /(?i)Get-DomainGPO/)=true OR match_regex(cmd_line, /(?i)Get-NetGPO/)=true OR match_regex(cmd_line, /(?i)Get-DomainGPOComputerLocalGroupMapping/)=true OR match_regex(cmd_line, /(?i)Find-GPOComputerAdmin/)=true OR match_regex(cmd_line, /(?i)Get-DomainGPOLocalGroup/)=true OR match_regex(cmd_line, /(?i)Get-NetGPOGroup/)=true OR match_regex(cmd_line, /(?i)Get-DomainGPOUserLocalGroupMapping/)=true OR match_regex(cmd_line, /(?i)Find-GPOLocation/)=true OR match_regex(cmd_line, /(?i)Get-DomainGroup/)=true OR match_regex(cmd_line, /(?i)Get-NetGroup/)=true OR match_regex(cmd_line, /(?i)Get-DomainGroupMember/)=true OR match_regex(cmd_line, /(?i)Get-NetGroupMember/)=true OR match_regex(cmd_line, /(?i)Get-DomainManagedSecurityGroup/)=true OR match_regex(cmd_line, /(?i)Find-ManagedSecurityGroups/)=true OR match_regex(cmd_line, /(?i)Get-DomainOU/)=true OR match_regex(cmd_line, /(?i)Get-NetOU/)=true OR match_regex(cmd_line, /(?i)Get-DomainUser/)=true OR match_regex(cmd_line, /(?i)Get-NetUser/)=true OR match_regex(cmd_line, /(?i)Get-DomainUserEvent/)=true OR match_regex(cmd_line, /(?i)Get-UserEvent/)=true OR match_regex(cmd_line, /(?i)Get-NetLocalGroup/)=true OR match_regex(cmd_line, /(?i)Get-NetLocalGroupMember/)=true OR match_regex(cmd_line, /(?i)Get-NetLoggedon/)=true OR match_regex(cmd_line, /(?i)Get-RegLoggedOn/)=true OR match_regex(cmd_line, /(?i)Get-WMIRegLastLoggedOn/)=true OR match_regex(cmd_line, /(?i)Get-LastLoggedOn/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Windows_Discovery_Techniques|Windows Discovery Techniques]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -17672,7 +22300,7 @@ None identified. This detection identifies use of Mimikatz modules for discovery of accounts and groups and access to them. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1087/ T1087], [https://attack.mitre.org/techniques/T1484/ T1484] * '''Last Updated''': 2020-11-05 @@ -17683,14 +22311,16 @@ This detection identifies use of Mimikatz modules for discovery of accounts and | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, /(?i)net::user/)=true OR match_regex(cmd_line, /(?i)net::group/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Windows_Discovery_Techniques|Windows Discovery Techniques]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -17753,7 +22383,7 @@ None identified. This detection identifies access to PowerSploit modules for reconnaissance and access to elements of Active Directory infrastructure, such as domain identifiers, AD sites and forests, and trust relations. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1199/ T1199], [https://attack.mitre.org/techniques/T1482/ T1482], [https://attack.mitre.org/techniques/T1590/ T1590], [https://attack.mitre.org/techniques/T1591/ T1591], [https://attack.mitre.org/techniques/T1595/ T1595] * '''Last Updated''': 2020-11-06 @@ -17764,14 +22394,16 @@ This detection identifies access to PowerSploit modules for reconnaissance and a | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, /(?i)Get-DomainSID/)=true OR match_regex(cmd_line, /(?i)Get-DomainSite/)=true OR match_regex(cmd_line, /(?i)Get-NetSite/)=true OR match_regex(cmd_line, /(?i)Get-DomainSubnet/)=true OR match_regex(cmd_line, /(?i)Get-NetSubnet/)=true OR match_regex(cmd_line, /(?i)Get-DomainTrust/)=true OR match_regex(cmd_line, /(?i)Get-NetDomainTrust/)=true OR match_regex(cmd_line, /(?i)Get-DomainTrustMapping/)=true OR match_regex(cmd_line, /(?i)Invoke-MapDomainTrust/)=true OR match_regex(cmd_line, /(?i)Get-Forest/)=true OR match_regex(cmd_line, /(?i)Get-NetForest/)=true OR match_regex(cmd_line, /(?i)Get-ForestDomain/)=true OR match_regex(cmd_line, /(?i)Get-NetForestDomain/)=true OR match_regex(cmd_line, /(?i)Get-ForestGlobalCatalog/)=true OR match_regex(cmd_line, /(?i)Get-NetForestCatalog/)=true OR match_regex(cmd_line, /(?i)Get-ForestTrust/)=true OR match_regex(cmd_line, /(?i)Get-NetForestTrust/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Windows_Discovery_Techniques|Windows Discovery Techniques]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -17842,7 +22474,7 @@ None identified. This detection identifies access to PowerSploit modules that discover computers, servers and domains that can be accessed or taken over. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1592/ T1592], [https://attack.mitre.org/techniques/T1590/ T1590], [https://attack.mitre.org/techniques/T1087/ T1087] * '''Last Updated''': 2020-11-06 @@ -17853,14 +22485,16 @@ This detection identifies access to PowerSploit modules that discover computers, | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, /(?i)Get-ComputerDetail/)=true OR match_regex(cmd_line, /(?i)Get-Domain/)=true OR match_regex(cmd_line, /(?i)Get-NetDomain/)=true OR match_regex(cmd_line, /(?i)Get-DomainComputer/)=true OR match_regex(cmd_line, /(?i)Get-NetComputer/)=true OR match_regex(cmd_line, /(?i)Get-DomainController/)=true OR match_regex(cmd_line, /(?i)Get-NetDomainController/)=true OR match_regex(cmd_line, /(?i)Get-DomainFileServer/)=true OR match_regex(cmd_line, /(?i)Get-NetFileServer/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Windows_Discovery_Techniques|Windows Discovery Techniques]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -17923,7 +22557,7 @@ None identified. This detection identifies use of Mimikatz modules for discovery of computers and servers and access to them. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1592/ T1592] * '''Last Updated''': 2020-11-06 @@ -17934,14 +22568,16 @@ This detection identifies use of Mimikatz modules for discovery of computers and | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, /(?i)net::ServerInfo/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Windows_Discovery_Techniques|Windows Discovery Techniques]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -17996,7 +22632,7 @@ None identified. This detection identifies access to PowerSploit modules that discover and access operating system elements, such as processes, services, registry locations, security packages and files. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1007/ T1007], [https://attack.mitre.org/techniques/T1012/ T1012], [https://attack.mitre.org/techniques/T1046/ T1046], [https://attack.mitre.org/techniques/T1047/ T1047], [https://attack.mitre.org/techniques/T1057/ T1057], [https://attack.mitre.org/techniques/T1083/ T1083], [https://attack.mitre.org/techniques/T1518/ T1518], [https://attack.mitre.org/techniques/T1592.002/ T1592.002] * '''Last Updated''': 2020-11-06 @@ -18007,14 +22643,16 @@ This detection identifies access to PowerSploit modules that discover and access | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, /(?i)Find-DomainProcess/)=true OR match_regex(cmd_line, /(?i)Invoke-ProcessHunter/)=true OR match_regex(cmd_line, /(?i)Get-ServiceDetail/)=true OR match_regex(cmd_line, /(?i)Get-WMIProcess/)=true OR match_regex(cmd_line, /(?i)Get-NetProcess/)=true OR match_regex(cmd_line, /(?i)Get-SecurityPackage/)=true OR match_regex(cmd_line, /(?i)Find-DomainObjectPropertyOutlier/)=true OR match_regex(cmd_line, /(?i)Get-DomainObject/)=true OR match_regex(cmd_line, /(?i)Get-ADObject/)=true OR match_regex(cmd_line, /(?i)Get-WMIRegMountedDrive/)=true OR match_regex(cmd_line, /(?i)Get-RegistryMountedDrive/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Windows_Discovery_Techniques|Windows Discovery Techniques]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -18097,7 +22735,7 @@ None identified. This detection identifies use of Mimikatz modules for discovery and access to services and processes. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1007/ T1007], [https://attack.mitre.org/techniques/T1046/ T1046], [https://attack.mitre.org/techniques/T1057/ T1057] * '''Last Updated''': 2020-11-06 @@ -18108,14 +22746,16 @@ This detection identifies use of Mimikatz modules for discovery and access to se | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, /(?i)process::list/)=true OR match_regex(cmd_line, /(?i)service::list/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Windows_Discovery_Techniques|Windows Discovery Techniques]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -18178,7 +22818,7 @@ None identified. This detection identifies use of Mimikatz modules for discovery and access to network shares. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1021.002/ T1021.002], [https://attack.mitre.org/techniques/T1135/ T1135], [https://attack.mitre.org/techniques/T1039/ T1039] * '''Last Updated''': 2020-11-06 @@ -18189,14 +22829,16 @@ This detection identifies use of Mimikatz modules for discovery and access to ne | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, /(?i)net::share/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Windows_Discovery_Techniques|Windows Discovery Techniques]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -18259,7 +22901,7 @@ None identified. This detection identifies access to PowerSploit modules that discover and access network and distributed file system shares. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1021.002/ T1021.002], [https://attack.mitre.org/techniques/T1135/ T1135], [https://attack.mitre.org/techniques/T1039/ T1039] * '''Last Updated''': 2020-11-06 @@ -18270,14 +22912,16 @@ This detection identifies access to PowerSploit modules that discover and access | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, /(?i)Find-DomainShare/)=true OR match_regex(cmd_line, /(?i)Invoke-ShareFinder/)=true OR match_regex(cmd_line, /(?i)Find-InterestingDomainShareFile/)=true OR match_regex(cmd_line, /(?i)Invoke-FileFinder/)=true OR match_regex(cmd_line, /(?i)Find-InterestingFile/)=true OR match_regex(cmd_line, /(?i)Get-DomainDFSShare/)=true OR match_regex(cmd_line, /(?i)Get-DFSshare/)=true OR match_regex(cmd_line, /(?i)Get-NetShare/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Windows_Discovery_Techniques|Windows Discovery Techniques]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -18340,7 +22984,7 @@ None identified. This detection identifies use of PowerSploit modules that discover opportunities for malicious access and persistence. Some examples include access to admin accounts, weak access control policies, landing paths for dropping malicious software or data to exfiltrate, registry locations to land autorun parameters, task scheduling opportunities, as well as services and system files that can be compromised. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1053/ T1053], [https://attack.mitre.org/techniques/T1068/ T1068], [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1543/ T1543], [https://attack.mitre.org/techniques/T1547/ T1547], [https://attack.mitre.org/techniques/T1574/ T1574] * '''Last Updated''': 2020-11-05 @@ -18351,14 +22995,16 @@ This detection identifies use of PowerSploit modules that discover opportunities | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, /(?i)Find-LocalAdminAccess/)=true OR match_regex(cmd_line, /(?i)Find-InterestingDomainAcl/)=true OR match_regex(cmd_line, /(?i)Invoke-ACLScanner/)=true OR match_regex(cmd_line, /(?i)Find-PathDLLHijack/)=true OR match_regex(cmd_line, /(?i)Find-ProcessDLLHijack/)=true OR match_regex(cmd_line, /(?i)Get-DomainObjectAcl/)=true OR match_regex(cmd_line, /(?i)Get-ObjectAcl/)=true OR match_regex(cmd_line, /(?i)Get-DomainPolicy/)=true OR match_regex(cmd_line, /(?i)Get-ModifiablePath/)=true OR match_regex(cmd_line, /(?i)Get-ModifiableRegistryAutoRun/)=true OR match_regex(cmd_line, /(?i)Get-ModifiableScheduledTaskFile/)=true OR match_regex(cmd_line, /(?i)Get-ModifiableService/)=true OR match_regex(cmd_line, /(?i)Get-ModifiableServiceFile/)=true OR match_regex(cmd_line, /(?i)Get-PathAcl/)=true OR match_regex(cmd_line, /(?i)Get-UnattendedInstallFile/)=true OR match_regex(cmd_line, /(?i)Get-UnquotedService/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Windows_Discovery_Techniques|Windows Discovery Techniques]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -18433,7 +23079,7 @@ None identified. This detection identifies access to PowerSploit modules for reconnaissance of connectivity. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1021.002/ T1021.002], [https://attack.mitre.org/techniques/T1135/ T1135], [https://attack.mitre.org/techniques/T1039/ T1039] * '''Last Updated''': 2020-11-06 @@ -18444,14 +23090,16 @@ This detection identifies access to PowerSploit modules for reconnaissance of co | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, /(?i)Get-DomainDNSRecord/)=true OR match_regex(cmd_line, /(?i)Get-DNSRecord/)=true OR match_regex(cmd_line, /(?i)Get-DomainDNSZone/)=true OR match_regex(cmd_line, /(?i)Get-DNSZone/)=true OR match_regex(cmd_line, /(?i)Invoke-ReverseDnsLookup/)=true OR match_regex(cmd_line, /(?i)Get-WMIRegCachedRDPConnection/)=true OR match_regex(cmd_line, /(?i)Get-CachedRDPConnection/)=true OR match_regex(cmd_line, /(?i)Get-WMIRegProxy/)=true OR match_regex(cmd_line, /(?i)Get-Proxy/)=true OR match_regex(cmd_line, /(?i)Invoke-Portscan/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Windows_Discovery_Techniques|Windows Discovery Techniques]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -18514,7 +23162,7 @@ None identified. This detection identifies reconnaissance of credential stores and use of CryptoAPI services by Mimikatz modules. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1589.001/ T1589.001], [https://attack.mitre.org/techniques/T1590.001/ T1590.001], [https://attack.mitre.org/techniques/T1590.003/ T1590.003], [https://attack.mitre.org/techniques/T1068/ T1068], [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1098/ T1098] * '''Last Updated''': 2020-11-03 @@ -18525,14 +23173,16 @@ This detection identifies reconnaissance of credential stores and use of CryptoA | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, /(?i)crypto::capi/)=true OR match_regex(cmd_line, /(?i)crypto::cng/)=true OR match_regex(cmd_line, /(?i)crypto::providers/)=true OR match_regex(cmd_line, /(?i)crypto::stores/)=true OR match_regex(cmd_line, /(?i)crypto::sc/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Windows_Discovery_Techniques|Windows Discovery Techniques]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -18607,7 +23257,7 @@ None identified. This detection identifies use of PowerSploit modules for assessment of presence of defensive tools. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1595.002/ T1595.002], [https://attack.mitre.org/techniques/T1592.002/ T1592.002] * '''Last Updated''': 2020-11-05 @@ -18618,14 +23268,16 @@ This detection identifies use of PowerSploit modules for assessment of presence | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, /(?i)Find-AVSignature/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Windows_Discovery_Techniques|Windows Discovery Techniques]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -18684,7 +23336,7 @@ None identified. This detection identifies use of PowerSploit modules for assessment of privilege escalation opportunities. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1068/ T1068], [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1098/ T1098] * '''Last Updated''': 2020-11-05 @@ -18695,14 +23347,16 @@ This detection identifies use of PowerSploit modules for assessment of privilege | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, /(?i)Invoke-PrivescAudit/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Windows_Discovery_Techniques|Windows Discovery Techniques]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -18765,7 +23419,7 @@ None identified. This detection identifies use of Mimikatz modules for discovery of process or service hijacking opportunities via Microsoft Detours compatibility. Microsoft Detours is an open source library for intercepting, monitoring and instrumenting binary functions on Microsoft Windows. Detours intercepts Win32 functions by re-writing the in-memory code for target functions. The Detours package also contains utilities to attach arbitrary DLLs and data segments called payloads to any Win32 binary. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1543/ T1543], [https://attack.mitre.org/techniques/T1055/ T1055], [https://attack.mitre.org/techniques/T1574/ T1574] * '''Last Updated''': 2020-11-05 @@ -18776,14 +23430,16 @@ This detection identifies use of Mimikatz modules for discovery of process or se | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, /(?i)misc::detours/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Windows_Discovery_Techniques|Windows Discovery Techniques]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -18857,10 +23513,10 @@ The search looks for reg.exe modifying registry keys that define Windows service ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Processes.process_name) as process_name values(Processes.parent_process_name) as parent_process_name values(Processes.user) as user FROM datamodel=Endpoint.Processes where Processes.process_name=reg.exe Processes.process=*reg* Processes.process=*add* Processes.process=*Services* by Processes.process_id Processes.dest Processes.process -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Processes.process_name) as process_name values(Processes.parent_process_name) as parent_process_name values(Processes.user) as user FROM datamodel=Endpoint.Processes where Processes.process_name=reg.exe Processes.process=*reg* Processes.process=*add* Processes.process=*Services* by Processes.process_id Processes.dest Processes.process +| `drop_dm_object_name("Processes")` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `reg_exe_manipulating_windows_services_registry_keys_filter` ====Associated Analytic Story==== @@ -18875,6 +23531,20 @@ To successfully implement this search, you must be ingesting data that records r ====Required field==== +* _time + +* Processes.process_name + +* Processes.parent_process_name + +* Processes.user + +* Processes.process + +* Processes.process_id + +* Processes.dest + ====ATT&CK==== @@ -18915,7 +23585,7 @@ It is unusual for a service to be created or modified by directly manipulating t The search looks for modifications to registry keys that can be used to launch an application or service at system startup. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1547.001/ T1547.001] * '''Last Updated''': 2020-11-27 @@ -18924,10 +23594,10 @@ The search looks for modifications to registry keys that can be used to launch a ====Search==== -| tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path=*currentversion\\run* OR Registry.registry_path=*currentVersion\\Windows\\Appinit_Dlls* OR Registry.registry_path=CurrentVersion\\Winlogon\\Shell* OR Registry.registry_path=*CurrentVersion\\Winlogon\\Userinit* OR Registry.registry_path=*CurrentVersion\\Winlogon\\VmApplet* OR Registry.registry_path=*currentversion\\policies\\explorer\\run* OR Registry.registry_path=*currentversion\\runservices* OR Registry.registry_path=*\\CurrentControlSet\\Control\\Lsa\\* OR Registry.registry_path="*Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options*" OR Registry.registry_path=HKLM\\SOFTWARE\\Microsoft\\Netsh\\*) by Registry.dest Registry.user -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `drop_dm_object_name(Registry)` +| tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name values(Registry.registry_path) as registry_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path=*currentversion\\run* OR Registry.registry_path=*currentVersion\\Windows\\Appinit_Dlls* OR Registry.registry_path=CurrentVersion\\Winlogon\\Shell* OR Registry.registry_path=*CurrentVersion\\Winlogon\\Userinit* OR Registry.registry_path=*CurrentVersion\\Winlogon\\VmApplet* OR Registry.registry_path=*currentversion\\policies\\explorer\\run* OR Registry.registry_path=*currentversion\\runservices* OR Registry.registry_path=*\\CurrentControlSet\\Control\\Lsa\\* OR Registry.registry_path="*Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options*" OR Registry.registry_path=HKLM\\SOFTWARE\\Microsoft\\Netsh\\*) by Registry.dest Registry.user +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` +| `drop_dm_object_name(Registry)` | `registry_keys_used_for_persistence_filter` ====Associated Analytic Story==== @@ -18952,6 +23622,16 @@ To successfully implement this search, you must be ingesting data that records r ====Required field==== +* _time + +* Registry.registry_key_name + +* Registry.registry_path + +* Registry.dest + +* Registry.user + ====ATT&CK==== @@ -18992,7 +23672,7 @@ There are many legitimate applications that must execute on system startup and w This search looks for modifications to registry keys that can be used to elevate privileges. The registry keys under "Image File Execution Options" are used to intercept calls to an executable and can be used to attach malicious binaries to benign system binaries. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1546.012/ T1546.012] * '''Last Updated''': 2020-11-27 @@ -19001,10 +23681,10 @@ This search looks for modifications to registry keys that can be used to elevate ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path="*Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options*") AND (Registry.registry_key_name=GlobalFlag OR Registry.registry_key_name=Debugger) by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `drop_dm_object_name(Registry)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where (Registry.registry_path="*Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options*") AND (Registry.registry_key_name=GlobalFlag OR Registry.registry_key_name=Debugger) by Registry.dest Registry.user Registry.registry_path Registry.registry_key_name +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` +| `drop_dm_object_name(Registry)` | `registry_keys_used_for_privilege_escalation_filter` ====Associated Analytic Story==== @@ -19021,6 +23701,16 @@ To successfully implement this search, you must be ingesting data that records r ====Required field==== +* _time + +* Registry.registry_path + +* Registry.registry_key_name + +* Registry.dest + +* Registry.user + ====ATT&CK==== @@ -19063,7 +23753,7 @@ There are many legitimate applications that must execute upon system startup and This search looks for registry activity associated with application compatibility shims, which can be leveraged by attackers for various nefarious purposes. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1546.011/ T1546.011] * '''Last Updated''': 2020-11-26 @@ -19072,10 +23762,10 @@ This search looks for registry activity associated with application compatibilit ====Search==== -| tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path=*CurrentVersion\\AppCompatFlags\\Custom* OR Registry.registry_path=*CurrentVersion\\AppCompatFlags\\InstalledSDB* by Registry.dest Registry.user -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `drop_dm_object_name(Registry)` +| tstats `security_content_summariesonly` count values(Registry.registry_key_name) as registry_key_name min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Registry where Registry.registry_path=*CurrentVersion\\AppCompatFlags\\Custom* OR Registry.registry_path=*CurrentVersion\\AppCompatFlags\\InstalledSDB* by Registry.dest Registry.user +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` +| `drop_dm_object_name(Registry)` | `registry_keys_for_creating_shim_databases_filter` ====Associated Analytic Story==== @@ -19090,6 +23780,16 @@ To successfully implement this search, you must populate the Change_Analysis dat ====Required field==== +* _time + +* Registry.registry_key_name + +* Registry.registry_path + +* Registry.dest + +* Registry.user + ====ATT&CK==== @@ -19139,10 +23839,10 @@ This search looks for the remote desktop process mstsc.exe running on systems up ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process=*mstsc.exe AND Processes.dest_category!=common_rdp_source by Processes.dest Processes.user Processes.process +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process=*mstsc.exe AND Processes.dest_category!=common_rdp_source by Processes.dest Processes.user Processes.process | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `drop_dm_object_name(Processes)` +| `security_content_ctime(lastTime)` +| `drop_dm_object_name(Processes)` | `remote_desktop_process_running_on_system_filter` ====Associated Analytic Story==== @@ -19157,6 +23857,16 @@ To successfully implement this search, you must be ingesting data that records p ====Required field==== +* _time + +* Processes.process + +* Processes.dest_category + +* Processes.dest + +* Processes.user + ====ATT&CK==== @@ -19204,10 +23914,10 @@ This search looks for wmic.exe being launched with parameters to spawn a process ====Search==== -| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = wmic.exe Processes.process="*/node*" Processes.process="*process*" Processes.process="*call*" Processes.process="*create*" by Processes.process_name Processes.parent_process_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = wmic.exe Processes.process="*/node*" Processes.process="*process*" Processes.process="*call*" Processes.process="*create*" by Processes.process_name Processes.parent_process_name Processes.dest Processes.user +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +|`security_content_ctime(lastTime)` | `remote_process_instantiation_via_wmi_filter` ====Associated Analytic Story==== @@ -19222,6 +23932,18 @@ You must be ingesting data that records process activity from your hosts to popu ====Required field==== +* _time + +* Processes.process_name + +* Processes.process + +* Processes.parent_process_name + +* Processes.dest + +* Processes.user + ====ATT&CK==== @@ -19258,6 +23980,89 @@ The wmic.exe utility is a benign Windows application. It may be used legitimatel ---- +===Resize shadowstorage volume=== +The following analytics identifies the resizing of shadowstorage by ransomware malware to avoid the shadow volumes being made again. this technique is an alternative by ransomware attacker than deleting the shadowstorage which is known alert in defensive team. one example of ransomware that use this technique is CLOP ransomware where it drops a .bat file that will resize the shadowstorage to minimum size as much as possible + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1490/ T1490] +* '''Last Updated''': 2021-03-12 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` values(Processes.process) as cmdline values(Processes.parent_process_name) as parent_process values(Processes.process_name) as process_name min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name = "cmd.exe" OR Processes.parent_process_name = "powershell.exe" OR Processes.parent_process_name = "powershell_ise.exe" OR Processes.parent_process_name = "wmic.exe" Processes.process_name = "vssadmin.exe" Processes.process="*resize*" Processes.process="*shadowstorage*" Processes.process="*/maxsize*" by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.dest Processes.user Processes.process_id Processes.process_guid +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +|`security_content_ctime(lastTime)` +| `resize_shadowstorage_volume_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Clop_Ransomware|Clop Ransomware]] + + +====How To Implement==== +To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. + +====Required field==== + +* Processes.process + +* Process.parent_process_name + +* _time + +* Processes.process_name + +* Processes.parent_process + +* Processes.dest + +* Processes.user + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1490 +| Inhibit System Recovery +| Impact +|} + + +====Kill Chain Phase==== + +* Exploitation + + +====Known False Positives==== +network admin can resize the shadowstorage for valid purposes. + +====Reference==== + +* https://www.fireeye.com/blog/threat-research/2020/10/fin11-email-campaigns-precursor-for-ransomware-data-theft.html + +* https://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/clop/clop_a/windows-sysmon.log + + +''version'': 1 +
+
+ +---- + ===Rundll loading dll by ordinal=== This search looks for executing scripts with rundll32. Adversaries may abuse rundll32.exe to proxy execution of malicious code. Using rundll32.exe, vice executing directly, may avoid triggering security tools that may not monitor execution of the rundll32.exe process because of allowlists or false positives from normal operations. @@ -19271,10 +24076,10 @@ This search looks for executing scripts with rundll32. Adversaries may abuse run ====Search==== -| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = rundll32.exe by Processes.process_name Processes.parent_process_name Processes.process Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = rundll32.exe by Processes.process_name Processes.parent_process_name Processes.process Processes.dest Processes.user +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `rundll_loading_dll_by_ordinal_filter` ====Associated Analytic Story==== @@ -19287,6 +24092,18 @@ You must be ingesting data that records process activity from your hosts to popu ====Required field==== +* _time + +* Processes.process_name + +* Processes.parent_process_name + +* Processes.process + +* Processes.dest + +* Processes.user + ====ATT&CK==== @@ -19327,7 +24144,7 @@ While not common, loading a DLL under %AppData% and calling a function by ordina The search looks for files that contain the key word *Ryuk* under any folder in the C drive, which is consistent with Ryuk propagation. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1486/ T1486] * '''Last Updated''': 2020-11-06 @@ -19336,10 +24153,10 @@ The search looks for files that contain the key word *Ryuk* under any folder in ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem WHERE "Filesystem.file_path"=C:\\*Ryuk* BY "Filesystem.dest", "Filesystem.user", "Filesystem.file_path" -| `drop_dm_object_name(Filesystem)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem WHERE "Filesystem.file_path"=C:\\*Ryuk* BY "Filesystem.dest", "Filesystem.user", "Filesystem.file_path" +| `drop_dm_object_name(Filesystem)` +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` | `ryuk_test_files_detected_filter` ====Associated Analytic Story==== @@ -19352,6 +24169,14 @@ You must be ingesting data that records the filesystem activity from your hosts ====Required field==== +* _time + +* Filesystem.file_path + +* Filesystem.dest + +* Filesystem.user + ====ATT&CK==== @@ -19382,6 +24207,97 @@ If there are files with this keywoord as file names it might trigger false possi * https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/malware/ryuk/windows-sysmon.log +''version'': 1 +
+
+ +---- + +===Ryuk wake on lan command=== +This Splunk query identifies the use of Wake-on-LAN utilized by Ryuk ransomware. The Ryuk Ransomware uses the Wake-on-Lan feature to turn on powered off devices on a compromised network to have greater success encrypting them. This is a high fidelity indicator of Ryuk ransomware executing on an endpoint. Upon triage, isolate the endpoint. Additional file modification events will be within the users profile (\appdata\roaming) and in public directories (users\public\). Review all Scheduled Tasks on the isolated endpoint and across the fleet. Suspicious Scheduled Tasks will include a path to a unknown binary and those endpoints should be isolated until triaged. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059.003/ T1059.003] +* '''Last Updated''': 2021-03-01 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process="*8 LAN*" OR Processes.process="*9 REP*") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `ryuk_wake_on_lan_command_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Ryuk_Ransomware|Ryuk Ransomware]] + + +====How To Implement==== +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. + +====Required field==== + +* _time + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_name + +* Processes.process + +* Processes.process_id + +* Processes.parent_process_id + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1059.003 +| Windows Command Shell +| Execution +|} + + +====Kill Chain Phase==== + +* Exploitation + +* Lateral Movement + + +====Known False Positives==== +Limited to no known false positives. + +====Reference==== + +* https://www.bleepingcomputer.com/news/security/ryuk-ransomware-uses-wake-on-lan-to-encrypt-offline-devices/ + +* https://www.bleepingcomputer.com/news/security/ryuk-ransomware-now-self-spreads-to-other-windows-lan-devices/ + +* https://www.cert.ssi.gouv.fr/uploads/CERTFR-2021-CTI-006.pdf + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1059.003/ryuk/windows-sysmon.log + + ''version'': 1
@@ -19401,10 +24317,10 @@ The search looks for a file named "test.txt" written to the windows system direc ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Filesystem.user) as user values(Filesystem.dest) as dest values(Filesystem.file_name) as file_name from datamodel=Endpoint.Filesystem where Filesystem.file_path=*\\windows\\system32\\test.txt by Filesystem.file_path -| `drop_dm_object_name(Filesystem)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Filesystem.user) as user values(Filesystem.dest) as dest values(Filesystem.file_name) as file_name from datamodel=Endpoint.Filesystem where Filesystem.file_path=*\\windows\\system32\\test.txt by Filesystem.file_path +| `drop_dm_object_name(Filesystem)` +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` | `samsam_test_file_write_filter` ====Associated Analytic Story==== @@ -19417,6 +24333,16 @@ You must be ingesting data that records the file-system activity from your hosts ====Required field==== +* _time + +* Filesystem.user + +* Filesystem.dest + +* Filesystem.file_name + +* Filesystem.file_path + ====ATT&CK==== @@ -19466,10 +24392,10 @@ This search looks for arguments to sc.exe indicating the creation or modificatio ====Search==== -| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = sc.exe (Processes.process="* create *" OR Processes.process="* config *") by Processes.process_name Processes.parent_process_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = sc.exe (Processes.process="* create *" OR Processes.process="* config *") by Processes.process_name Processes.parent_process_name Processes.dest Processes.user +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `sc_exe_manipulating_windows_services_filter` ====Associated Analytic Story==== @@ -19484,7 +24410,7 @@ This search looks for arguments to sc.exe indicating the creation or modificatio * [[Documentation:ESSOC:stories:UseCase#Disabling_Security_Tools|Disabling Security Tools]] -* [[Documentation:ESSOC:stories:UseCase#Sunburst_Malware|Sunburst Malware]] +* [[Documentation:ESSOC:stories:UseCase#NOBELIUM_Group|NOBELIUM Group]] ====How To Implement==== @@ -19492,6 +24418,18 @@ To successfully implement this search you need to be ingesting information on pr ====Required field==== +* _time + +* Processes.process_name + +* Processes.process + +* Processes.parent_process_name + +* Processes.dest + +* Processes.user + ====ATT&CK==== @@ -19541,17 +24479,17 @@ This search looks for flags passed to schtasks.exe on the command-line that indi ====Search==== -| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=schtasks.exe (Processes.process=*delete* OR Processes.process=*create*) by Processes.user Processes.process_name Processes.parent_process_name Processes.dest -| `drop_dm_object_name(Processes)` +| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=schtasks.exe (Processes.process=*delete* OR Processes.process=*create*) by Processes.user Processes.process_name Processes.parent_process_name Processes.dest +| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | `scheduled_task_deleted_or_created_via_cmd_filter` ====Associated Analytic Story==== * [[Documentation:ESSOC:stories:UseCase#DHS_Report_TA18-074A|DHS Report TA18-074A]] -* [[Documentation:ESSOC:stories:UseCase#Sunburst_Malware|Sunburst Malware]] +* [[Documentation:ESSOC:stories:UseCase#NOBELIUM_Group|NOBELIUM Group]] ====How To Implement==== @@ -19559,6 +24497,20 @@ You must be ingesting endpoint data that tracks process activity, including pare ====Required field==== +* _time + +* Processes.process + +* Processes.parent_process + +* Processes.process_name + +* Processes.user + +* Processes.parent_process_name + +* Processes.dest + ====ATT&CK==== @@ -19608,17 +24560,17 @@ This search looks for flags passed to schtasks.exe on the command-line that indi ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = schtasks.exe Processes.process="*/create*" (Processes.process="* /s *" OR Processes.process="* /S *") by Processes.process_name Processes.process Processes.parent_process_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = schtasks.exe Processes.process="*/create*" (Processes.process="* /s *" OR Processes.process="* /S *") by Processes.process_name Processes.process Processes.parent_process_name Processes.dest Processes.user +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `schtasks_scheduling_job_on_remote_system_filter` ====Associated Analytic Story==== * [[Documentation:ESSOC:stories:UseCase#Lateral_Movement|Lateral Movement]] -* [[Documentation:ESSOC:stories:UseCase#Sunburst_Malware|Sunburst Malware]] +* [[Documentation:ESSOC:stories:UseCase#NOBELIUM_Group|NOBELIUM Group]] ====How To Implement==== @@ -19626,6 +24578,18 @@ You must be ingesting data that records process activity from your hosts to popu ====Required field==== +* _time + +* Processes.process_name + +* Processes.process + +* Processes.parent_process_name + +* Processes.dest + +* Processes.user + ====ATT&CK==== @@ -19675,10 +24639,10 @@ This search looks for flags passed to schtasks.exe on the command-line that indi ====Search==== -| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=schtasks.exe Processes.process="*shutdown*" Processes.process="*/create *" by Processes.process_name Processes.parent_process_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=schtasks.exe Processes.process="*shutdown*" Processes.process="*/create *" by Processes.process_name Processes.parent_process_name Processes.dest Processes.user +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `schtasks_used_for_forcing_a_reboot_filter` ====Associated Analytic Story==== @@ -19693,6 +24657,18 @@ To successfully implement this search you need to be ingesting logs with both th ====Required field==== +* _time + +* Processes.process + +* Processes.process_name + +* Processes.parent_process_name + +* Processes.dest + +* Processes.user + ====ATT&CK==== @@ -19733,7 +24709,7 @@ Administrators may create jobs on systems forcing reboots to perform updates, ma This search looks for scripts launched via WMI. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1047/ T1047] * '''Last Updated''': 2020-03-16 @@ -19742,8 +24718,8 @@ This search looks for scripts launched via WMI. ====Search==== -| tstats `security_content_summariesonly` count values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes where Processes.process_name = "scrcons.exe" by Processes.user Processes.dest Processes.process_name -| `drop_dm_object_name("Processes")` +| tstats `security_content_summariesonly` count values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes where Processes.process_name = "scrcons.exe" by Processes.user Processes.dest Processes.process_name +| `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `script_execution_via_wmi_filter` @@ -19758,6 +24734,14 @@ You must be ingesting endpoint data that tracks process activity, including pare ====Required field==== +* _time + +* Processes.process_name + +* Processes.user + +* Processes.dest + ====ATT&CK==== @@ -19798,7 +24782,7 @@ Although unlikely, administrators may use wmi to launch scripts for legitimate p This detection identifies illegal setting of credentials via DSInternals modules. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1068/ T1068], [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1098/ T1098] * '''Last Updated''': 2020-11-03 @@ -19809,14 +24793,16 @@ This detection identifies illegal setting of credentials via DSInternals modules | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), cmd_line=ucast(map_get(input_event, "process"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), process_name=ucast(map_get(input_event, "process_name"), "string", null), process_path=ucast(map_get(input_event, "process_path"), "string", null), cmd_line=ucast(map_get(input_event, "process"), "string", null), parent_process_name=ucast(map_get(input_event, "parent_process_name"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, /(?i)Add-ADDBSidHistory/)=true OR match_regex(cmd_line, /(?i)Add-ADReplNgcKey/)=true OR match_regex(cmd_line, /(?i)Set-ADDBAccountPassword/)=true OR match_regex(cmd_line, /(?i)Set-ADDBAccountPasswordHash/)=true OR match_regex(cmd_line, /(?i)Set-ADDBBootKey/)=true OR match_regex(cmd_line, /(?i)Set-SamAccountPasswordHash/)=true OR match_regex(cmd_line, /(?i)Set-AzureADUserEx/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -19874,6 +24860,8 @@ None identified. ====Test Dataset==== +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/logAllDSInternalsModules.log + ''version'': 1
@@ -19885,7 +24873,7 @@ None identified. This detection identifies illegal setting of credentials via Mimikatz modules. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1068/ T1068], [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1098/ T1098] * '''Last Updated''': 2020-11-03 @@ -19896,14 +24884,16 @@ This detection identifies illegal setting of credentials via Mimikatz modules. | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, /(?i)misc::addsid/)=true OR match_regex(cmd_line, /(?i)CRYPTO::scauth/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -19955,6 +24945,8 @@ None identified. ====Test Dataset==== +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/logAllMimikatzModules.log + ''version'': 1
@@ -19966,7 +24958,7 @@ None identified. This detection identifies illegal setting of credentials via PowerSploit modules. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1068/ T1068], [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1098/ T1098] * '''Last Updated''': 2020-11-03 @@ -19977,14 +24969,16 @@ This detection identifies illegal setting of credentials via PowerSploit modules | from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), cmd_line=ucast(map_get(input_event, "process"), "string", null) | where cmd_line != null AND ( match_regex(cmd_line, /(?i)Set-DomainUserPassword/)=true ) -| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend( ucast(map_get(input_event, "dest_user_id"), "string", null), ucast(map_get(input_event, "dest_device_id"), "string", null)), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] + ====How To Implement==== You must be ingesting Windows Security logs from devices of interest, including the event ID 4688 with enabled command line logging. @@ -20036,6 +25030,8 @@ None identified. ====Test Dataset==== +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1098/logAllPowerSploitModulesWithOldNames.log + ''version'': 1
@@ -20047,7 +25043,7 @@ None identified. This search looks for shim database files being written to default directories. The sdbinst.exe application is used to install shim database files (.sdb). According to Microsoft, a shim is a small library that transparently intercepts an API, changes the parameters passed, handles the operation itself, or redirects the operation elsewhere. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1546.011/ T1546.011] * '''Last Updated''': 2020-12-08 @@ -20056,10 +25052,10 @@ This search looks for shim database files being written to default directories. ====Search==== -| tstats `security_content_summariesonly` count values(Filesystem.action) values(Filesystem.file_hash) as file_hash values(Filesystem.file_path) as file_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path=*Windows\\AppPatch\\Custom* by Filesystem.file_name Filesystem.dest -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -|`drop_dm_object_name(Filesystem)` +| tstats `security_content_summariesonly` count values(Filesystem.action) values(Filesystem.file_hash) as file_hash values(Filesystem.file_path) as file_path min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path=*Windows\\AppPatch\\Custom* by Filesystem.file_name Filesystem.dest +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` +|`drop_dm_object_name(Filesystem)` | `shim_database_file_creation_filter` ====Associated Analytic Story==== @@ -20072,6 +25068,16 @@ You must be ingesting data that records the filesystem activity from your hosts ====Required field==== +* _time + +* Filesystem.file_hash + +* Filesystem.file_path + +* Filesystem.file_name + +* Filesystem.dest + ====ATT&CK==== @@ -20121,10 +25127,10 @@ This search detects the process execution and arguments required to silently cre ====Search==== -| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = sdbinst.exe by Processes.process_name Processes.parent_process_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = sdbinst.exe by Processes.process_name Processes.parent_process_name Processes.dest Processes.user +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `shim_database_installation_with_suspicious_parameters_filter` ====Associated Analytic Story==== @@ -20137,6 +25143,16 @@ You must be ingesting data that records process activity from your hosts to popu ====Required field==== +* _time + +* Processes.process_name + +* Processes.parent_process_name + +* Processes.dest + +* Processes.user + ====ATT&CK==== @@ -20186,13 +25202,13 @@ This search detects accounts that were created and deleted in a short time perio ====Search==== -| tstats `security_content_summariesonly` values(All_Changes.result_id) as result_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Change where All_Changes.result_id=4720 OR All_Changes.result_id=4726 by _time span=4h All_Changes.user All_Changes.dest -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| `drop_dm_object_name("All_Changes")` -| search result_id = 4720 result_id=4726 -| transaction user connected=false maxspan=240m -| table firstTime lastTime count user dest result_id +| tstats `security_content_summariesonly` values(All_Changes.result_id) as result_id count min(_time) as firstTime max(_time) as lastTime from datamodel=Change where All_Changes.result_id=4720 OR All_Changes.result_id=4726 by _time span=4h All_Changes.user All_Changes.dest +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` +| `drop_dm_object_name("All_Changes")` +| search result_id = 4720 result_id=4726 +| transaction user connected=false maxspan=240m +| table firstTime lastTime count user dest result_id | `short_lived_windows_accounts_filter` ====Associated Analytic Story==== @@ -20205,6 +25221,14 @@ This search requires you to have enabled your Group Management Audit Logs in you ====Required field==== +* _time + +* All_Changes.result_id + +* All_Changes.user + +* All_Changes.dest + ====ATT&CK==== @@ -20256,13 +25280,13 @@ This search looks for process names that consist only of a single letter. ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes by Processes.dest, Processes.user, Processes.process, Processes.process_name -| `drop_dm_object_name(Processes)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` -| eval process_name_length = len(process_name), endExe = if(substr(process_name, -4) == ".exe", 1, 0) -| search process_name_length=5 AND endExe=1 -| table count, firstTime, lastTime, dest, user, process, process_name +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes by Processes.dest, Processes.user, Processes.process, Processes.process_name +| `drop_dm_object_name(Processes)` +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` +| eval process_name_length = len(process_name), endExe = if(substr(process_name, -4) == ".exe", 1, 0) +| search process_name_length=5 AND endExe=1 +| table count, firstTime, lastTime, dest, user, process, process_name | `single_letter_process_on_endpoint_filter` ====Associated Analytic Story==== @@ -20275,6 +25299,16 @@ You must be ingesting data that records process activity from your hosts to popu ====Required field==== +* _time + +* Processes.dest + +* Processes.user + +* Processes.process + +* Processes.process_name + ====ATT&CK==== @@ -20315,8 +25349,8 @@ Single-letter executables are not always malicious. Investigate this activity wi The search looks for a sharp increase in the number of files written to a particular host * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': +* '''Datamodel''': +* '''ATT&CK''': * '''Last Updated''': 2020-03-16
@@ -20324,12 +25358,12 @@ The search looks for a sharp increase in the number of files written to a partic ====Search==== -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Filesystem where Filesystem.action=created by _time span=1h, Filesystem.dest -| `drop_dm_object_name(Filesystem)` -| eventstats max(_time) as maxtime -| stats count as num_data_samples max(eval(if(_time >= relative_time(maxtime, "-1d@d"), count, null))) as "count" avg(eval(if(_time upperBound) AND num_data_samples >=20, 1, 0) -| search isOutlier=1 +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Filesystem where Filesystem.action=created by _time span=1h, Filesystem.dest +| `drop_dm_object_name(Filesystem)` +| eventstats max(_time) as maxtime +| stats count as num_data_samples max(eval(if(_time >= relative_time(maxtime, "-1d@d"), count, null))) as "count" avg(eval(if(_time upperBound) AND num_data_samples >=20, 1, 0) +| search isOutlier=1 | `spike_in_file_writes_filter` ====Associated Analytic Story==== @@ -20346,6 +25380,12 @@ In order to implement this search, you must populate the Endpoint file-system da ====Required field==== +* _time + +* Filesystem.action + +* Filesystem.dest + @@ -20373,7 +25413,7 @@ It is important to understand that if you happen to install any new applications The malware sunburst will load the malicious dll by SolarWinds.BusinessLayerHost.exe. After a period of 12-14 days, the malware will attempt to resolve a subdomain of avsvmcloud.com. This detections will correlate both events. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1203/ T1203] * '''Last Updated''': 2020-12-14 @@ -20381,18 +25421,18 @@ The malware sunburst will load the malicious dll by SolarWinds.BusinessLayerHost
====Search==== -(`sysmon` EventCode=7 ImageLoaded=*SolarWinds.Orion.Core.BusinessLayer.dll) OR (`sysmon` EventCode=22 QueryName=*avsvmcloud.com) -| eventstats dc(EventCode) AS dc_events -| where dc_events=2 -| stats min(_time) as firstTime max(_time) as lastTime values(ImageLoaded) AS ImageLoaded values(QueryName) AS QueryName by host -| rename host as dest +(`sysmon` EventCode=7 ImageLoaded=*SolarWinds.Orion.Core.BusinessLayer.dll) OR (`sysmon` EventCode=22 QueryName=*avsvmcloud.com) +| eventstats dc(EventCode) AS dc_events +| where dc_events=2 +| stats min(_time) as firstTime max(_time) as lastTime values(ImageLoaded) AS ImageLoaded values(QueryName) AS QueryName by host +| rename host as dest | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | `sunburst_correlation_dll_and_network_event_filter` ====Associated Analytic Story==== -* [[Documentation:ESSOC:stories:UseCase#Sunburst_Malware|Sunburst Malware]] +* [[Documentation:ESSOC:stories:UseCase#NOBELIUM_Group|NOBELIUM Group]] ====How To Implement==== @@ -20400,6 +25440,14 @@ This detection relies on sysmon logs with the Event ID 7, Driver loaded. Please ====Required field==== +* _time + +* EventCode + +* ImageLoaded + +* QueryName + ====ATT&CK==== @@ -20430,6 +25478,271 @@ unknown ====Test Dataset==== +''version'': 1 +
+
+ +---- + +===Suspicious curl network connection=== +The following analytic identifies the use of a curl contacting suspicious remote domains to checkin to command and control servers or download further implants. In the context of Silver Sparrow, curl is identified contacting s3.amazonaws.com. This particular behavior is common with MacOS adware-malicious software. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1105/ T1105] +* '''Last Updated''': 2021-02-22 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=curl Processes.process=s3.amazonaws.com by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `suspicious_curl_network_connection_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Silver_Sparrow|Silver Sparrow]] + +* [[Documentation:ESSOC:stories:UseCase#Ingress_Tool_Transfer|Ingress Tool Transfer]] + + +====How To Implement==== +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. + +====Required field==== + +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_id + +* Processes.parent_process_id + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1105 +| Ingress Tool Transfer +| Command and Control +|} + + +====Kill Chain Phase==== + +* Actions on Objectives + + +====Known False Positives==== +Unknown. Filter as needed. + +====Reference==== + +* https://redcanary.com/blog/clipping-silver-sparrows-wings/ + +* https://marcosantadev.com/manage-plist-files-plistbuddy/ + + +====Test Dataset==== + + +''version'': 1 +
+
+ +---- + +===Suspicious dllhost no command line arguments=== +The following analytic identifies DLLHost.exe with no command line arguments. It is unusual for DLLHost.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, identify any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. DLLHost.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1055/ T1055] +* '''Last Updated''': 2021-02-23 + +
+
+ +====Search==== +`sysmon` EventID=1 (process_name=dllhost.exe OR OriginalFileName=dllhost.exe) +| regex CommandLine="(dllhost\.exe.{0,4}$)" +| stats count min(_time) as firstTime max(_time) as lastTime by dest, User, ParentImage,ParentCommandLine, process_name, OriginalFileName, process_path, CommandLine +| rename Computer as dest +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `suspicious_dllhost_no_command_line_arguments_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Cobalt_Strike|Cobalt Strike]] + + +====How To Implement==== +To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. + +====Required field==== + +* _time + +* EventID + +* process_name + +* OriginalFileName + +* CommandLine + +* dest + +* User + +* ParentImage + +* ParentCommandLine + +* process_path + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1055 +| Process Injection +| Defense Evasion, Privilege Escalation +|} + + +====Kill Chain Phase==== + +* Exploitation + + +====Known False Positives==== +Limited false positives may be present in small environments. Tuning may be required based on parent process. + +====Reference==== + +* https://raw.githubusercontent.com/threatexpress/malleable-c2/c3385e481159a759f79b8acfe11acf240893b830/jquery-c2.4.2.profile + +* https://blog.cobaltstrike.com/2021/02/09/learn-pipe-fitting-for-all-of-your-offense-projects/ + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log + + +''version'': 1 +
+
+ +---- + +===Suspicious gpupdate no command line arguments=== +The following analytic identifies gpupdate.exe with no command line arguments. It is unusual for gpupdate.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, identify any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. gpupdate.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1055/ T1055] +* '''Last Updated''': 2021-02-23 + +
+
+ +====Search==== +`sysmon` EventID=1 (process_name=gpupdate.exe OR OriginalFileName=GPUpdate.exe) +| regex CommandLine="(gpupdate\.exe.{0,4}$)" +| stats count min(_time) as firstTime max(_time) as lastTime by dest, User, ParentImage,ParentCommandLine, process_name, OriginalFileName, process_path, CommandLine +| rename Computer as dest +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `suspicious_gpupdate_no_command_line_arguments_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Cobalt_Strike|Cobalt Strike]] + + +====How To Implement==== +To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. + +====Required field==== + +* _time + +* EventID + +* process_name + +* OriginalFileName + +* CommandLine + +* dest + +* User + +* ParentImage + +* ParentCommandLine + +* process_path + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1055 +| Process Injection +| Defense Evasion, Privilege Escalation +|} + + +====Kill Chain Phase==== + +* Exploitation + + +====Known False Positives==== +Limited false positives may be present in small environments. Tuning may be required based on parent process. + +====Reference==== + +* https://raw.githubusercontent.com/xx0hcd/Malleable-C2-Profiles/0ef8cf4556e26f6d4190c56ba697c2159faa5822/crimeware/trick_ryuk.profile + +* https://blog.cobaltstrike.com/2021/02/09/learn-pipe-fitting-for-all-of-your-offense-projects/ + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log + + ''version'': 1
@@ -20440,7 +25753,7 @@ unknown The following analytic identifies renamed instances of msbuild.exe executing. Msbuild.exe is natively found in C:\Windows\Microsoft.NET\Framework\v4.0.30319 and C:\Windows\Microsoft.NET\Framework64\v4.0.30319. During investigation, identify the code executed and what is executing a renamed instance of MSBuild. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1127.001/ T1127.001], [https://attack.mitre.org/techniques/T1036.003/ T1036.003] * '''Last Updated''': 2021-01-12 @@ -20448,9 +25761,9 @@ The following analytic identifies renamed instances of msbuild.exe executing. Ms
====Search==== -`sysmon` EventID=1 (OriginalFileName=msbuild.exe OR process_name=msbuild.exe) -| stats count min(_time) as firstTime max(_time) as lastTime by Computer, User, parent_process_name, process_name, OriginalFileName, process_path, CommandLine -| rename Computer as dest +`sysmon` EventID=1 (OriginalFileName=msbuild.exe OR process_name=msbuild.exe) +| stats count min(_time) as firstTime max(_time) as lastTime by Computer, User, parent_process_name, process_name, OriginalFileName, process_path, CommandLine +| rename Computer as dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `suspicious_msbuild_rename_filter` @@ -20459,12 +25772,32 @@ The following analytic identifies renamed instances of msbuild.exe executing. Ms * [[Documentation:ESSOC:stories:UseCase#Trusted_Developer_Utilities_Proxy_Execution_MSBuild|Trusted Developer Utilities Proxy Execution MSBuild]] +* [[Documentation:ESSOC:stories:UseCase#Cobalt_Strike|Cobalt Strike]] + ====How To Implement==== To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. ====Required field==== +* _time + +* EventID + +* OriginalFileName + +* process_name + +* Computer + +* User + +* parent_process_name + +* process_path + +* CommandLine + ====ATT&CK==== @@ -20524,10 +25857,10 @@ The following analytic identifies wmiprvse.exe spawning msbuild.exe. This behavi ====Search==== -| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=wmiprvse.exe AND Processes.process_name=msbuild.exe by Processes.dest Processes.parent_process Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=wmiprvse.exe AND Processes.process_name=msbuild.exe by Processes.dest Processes.parent_process Processes.user +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `suspicious_msbuild_spawn_filter` ====Associated Analytic Story==== @@ -20540,6 +25873,20 @@ To successfully implement this search you need to be ingesting information on pr ====Required field==== +* _time + +* Processes.process_name + +* Processes.process + +* Processes.parent_process_name + +* Processes.dest + +* Processes.parent_process + +* Processes.user + ====ATT&CK==== @@ -20574,6 +25921,170 @@ Although unlikely, some legitimate applications may exhibit this behavior, trigg * https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1127.001/windows-sysmon.log +''version'': 1 +
+
+ +---- + +===Suspicious plistbuddy usage=== +The following analytic identifies the use of a native MacOS utility, PlistBuddy, creating or modifying a properly list (.plist) file. In the instance of Silver Sparrow, the following commands were executed:\ +- PlistBuddy -c "Add :Label string init_verx" ~/Library/Launchagents/init_verx.plist \ +- PlistBuddy -c "Add :RunAtLoad bool true" ~/Library/Launchagents/init_verx.plist \ +- PlistBuddy -c "Add :StartInterval integer 3600" ~/Library/Launchagents/init_verx.plist \ +- PlistBuddy -c "Add :ProgramArguments array" ~/Library/Launchagents/init_verx.plist \ +- PlistBuddy -c "Add :ProgramArguments:0 string /bin/sh" ~/Library/Launchagents/init_verx.plist \ +- PlistBuddy -c "Add :ProgramArguments:1 string -c" ~/Library/Launchagents/init_verx.plist \ +Upon triage, capture the property list file being written to disk and review for further indicators. Contain the endpoint and triage further. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1543.001/ T1543.001] +* '''Last Updated''': 2021-02-22 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=PlistBuddy (Processes.process=*LaunchAgents* OR Processes.process=*RunAtLoad* OR Processes.process=*true*) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `suspicious_plistbuddy_usage_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Silver_Sparrow|Silver Sparrow]] + + +====How To Implement==== +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. + +====Required field==== + +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_id + +* Processes.parent_process_id + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1543.001 +| Launch Agent +| Persistence, Privilege Escalation +|} + + +====Kill Chain Phase==== + +* Actions on Objectives + + +====Known False Positives==== +Some legitimate applications may use PlistBuddy to create or modify property lists and possibly generate false positives. Review the property list being modified or created to confirm. + +====Reference==== + +* https://redcanary.com/blog/clipping-silver-sparrows-wings/ + +* https://marcosantadev.com/manage-plist-files-plistbuddy/ + + +====Test Dataset==== + + +''version'': 1 +
+
+ +---- + +===Suspicious plistbuddy usage via osquery=== +The following analytic identifies the use of a native MacOS utility, PlistBuddy, creating or modifying a properly list (.plist) file. In the instance of Silver Sparrow, the following commands were executed:\ +- PlistBuddy -c "Add :Label string init_verx" ~/Library/Launchagents/init_verx.plist \ +- PlistBuddy -c "Add :RunAtLoad bool true" ~/Library/Launchagents/init_verx.plist \ +- PlistBuddy -c "Add :StartInterval integer 3600" ~/Library/Launchagents/init_verx.plist \ +- PlistBuddy -c "Add :ProgramArguments array" ~/Library/Launchagents/init_verx.plist \ +- PlistBuddy -c "Add :ProgramArguments:0 string /bin/sh" ~/Library/Launchagents/init_verx.plist \ +- PlistBuddy -c "Add :ProgramArguments:1 string -c" ~/Library/Launchagents/init_verx.plist \ +Upon triage, capture the property list file being written to disk and review for further indicators. Contain the endpoint and triage further. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1543.001/ T1543.001] +* '''Last Updated''': 2021-02-22 + +
+
+ +====Search==== +`osquery_process` "columns.cmdline"="*LaunchAgents*" OR "columns.cmdline"="*RunAtLoad*" OR "columns.cmdline"="*true*" +| `suspicious_plistbuddy_usage_via_osquery_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Silver_Sparrow|Silver Sparrow]] + + +====How To Implement==== +OSQuery must be installed and configured to pick up process events (info at https://osquery.io) as well as using the Splunk OSQuery Add-on https://splunkbase.splunk.com/app/4402. Modify the macro and validate fields are correct. + +====Required field==== + +* _time + +* columns.cmdline + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1543.001 +| Launch Agent +| Persistence, Privilege Escalation +|} + + +====Kill Chain Phase==== + +* Actions on Objectives + + +====Known False Positives==== +Some legitimate applications may use PlistBuddy to create or modify property lists and possibly generate false positives. Review the property list being modified or created to confirm. + +====Reference==== + +* https://redcanary.com/blog/clipping-silver-sparrows-wings/ + +* https://marcosantadev.com/manage-plist-files-plistbuddy/ + + +====Test Dataset==== + + ''version'': 1
@@ -20584,7 +26095,7 @@ Although unlikely, some legitimate applications may exhibit this behavior, trigg This search looks for reg.exe being launched from a command prompt not started by the user. When a user launches cmd.exe, the parent process is usually explorer.exe. This search filters out those instances. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1112/ T1112] * '''Last Updated''': 2020-07-22 @@ -20593,18 +26104,18 @@ This search looks for reg.exe being launched from a command prompt not started b ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes where Processes.parent_process_name != explorer.exe Processes.process_name =cmd.exe by Processes.user Processes.process_name Processes.parent_process_name Processes.dest Processes.process_id Processes.parent_process_id -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes where Processes.parent_process_name != explorer.exe Processes.process_name =cmd.exe by Processes.user Processes.process_name Processes.parent_process_name Processes.dest Processes.process_id Processes.parent_process_id +| `drop_dm_object_name("Processes")` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | search [ -| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.parent_process_name=cmd.exe Processes.process_name= reg.exe by Processes.parent_process_id Processes.dest Processes.process_name -| `drop_dm_object_name("Processes")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| rename parent_process_id as process_id +| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.parent_process_name=cmd.exe Processes.process_name= reg.exe by Processes.parent_process_id Processes.dest Processes.process_name +| `drop_dm_object_name("Processes")` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| rename parent_process_id as process_id |dedup process_id -| table process_id dest] +| table process_id dest] | `suspicious_reg_exe_process_filter` ====Associated Analytic Story==== @@ -20621,6 +26132,22 @@ You must be ingesting data that records process activity from your hosts to popu ====Required field==== +* _time + +* Processes.parent_process_name + +* Processes.process_name + +* Processes.user + +* Processes.parent_process_name + +* Processes.dest + +* Processes.process_id + +* Processes.parent_process_id + ====ATT&CK==== @@ -20672,10 +26199,10 @@ Adversaries may abuse Regsvr32.exe to proxy execution of malicious code by using ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=regsvr32.exe (Processes.process=*appdata* OR Processes.process=*programdata* OR Processes.process=*windows\temp*) (Processes.process!=*.dll Processes.process!=*.ax Processes.process!=*.ocx) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=regsvr32.exe (Processes.process=*appdata* OR Processes.process=*programdata* OR Processes.process=*windows\temp*) (Processes.process!=*.dll Processes.process!=*.ax Processes.process!=*.ocx) by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | `suspicious_regsvr32_register_suspicious_path_filter` ====Associated Analytic Story==== @@ -20688,6 +26215,24 @@ You must be ingesting endpoint data that tracks process activity, including pare ====Required field==== +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process + +* Processes.process_id + +* Processes.parent_process_id + ====ATT&CK==== @@ -20738,7 +26283,7 @@ Limited false positives with the query restricted to specified paths. Add more w The following analytic identifies renamed instances of rundll32.exe executing. rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. During investigation, validate it is the legitimate rundll32.exe executing and what script content it is loading. This query relies on the OriginalFileName from Sysmon, or internal name from the PE meta data. Expand the query as needed by looking for specific command line arguments outlined in other analytics. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1218.011/ T1218.011], [https://attack.mitre.org/techniques/T1036.003/ T1036.003] * '''Last Updated''': 2021-02-04 @@ -20746,9 +26291,9 @@ The following analytic identifies renamed instances of rundll32.exe executing. r
====Search==== -`sysmon` EventID=1 OriginalFileName=RUNDLL32.EXE NOT process_name=rundll32.exe -| stats count min(_time) as firstTime max(_time) as lastTime by Computer, User, parent_process_name, process_name, OriginalFileName, process_path, CommandLine -| rename Computer as dest +`sysmon` EventID=1 OriginalFileName=RUNDLL32.EXE NOT process_name=rundll32.exe +| stats count min(_time) as firstTime max(_time) as lastTime by Computer, User, parent_process_name, process_name, OriginalFileName, process_path, CommandLine +| rename Computer as dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `suspicious_rundll32_rename_filter` @@ -20763,6 +26308,24 @@ To successfully implement this search, you need to be ingesting logs with the pr ====Required field==== +* _time + +* EventID + +* OriginalFileName + +* process_name + +* Computer + +* User + +* parent_process_name + +* process_path + +* CommandLine + ====ATT&CK==== @@ -20822,10 +26385,10 @@ The following analytic identifies rundll32.exe executing a DLL function name, St ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=rundll32.exe Processes.process=*start* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=rundll32.exe Processes.process=*start* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `suspicious_rundll32_startw_filter` ====Associated Analytic Story==== @@ -20840,6 +26403,22 @@ To successfully implement this search you need to be ingesting information on pr ====Required field==== +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_id + +* Processes.parent_process_id + ====ATT&CK==== @@ -20899,10 +26478,10 @@ The following analytic identifies rundll32.exe using dllregisterserver on the co ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=rundll32.exe Processes.process=*dllregisterserver* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=rundll32.exe Processes.process=*dllregisterserver* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `suspicious_rundll32_dllregisterserver_filter` ====Associated Analytic Story==== @@ -20915,6 +26494,22 @@ To successfully implement this search you need to be ingesting information on pr ====Required field==== +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_id + +* Processes.parent_process_id + ====ATT&CK==== @@ -20965,11 +26560,11 @@ This is likely to produce false positives and will require some filtering. Tune ---- -===Suspicious rundll32 no commandline arguments=== +===Suspicious rundll32 no command line arguments=== The following analytic identifies rundll32.exe with no command line arguments. It is unusual for rundll32.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, identify any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. Rundll32.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1218.011/ T1218.011] * '''Last Updated''': 2021-02-09 @@ -20977,13 +26572,13 @@ The following analytic identifies rundll32.exe with no command line arguments. I
====Search==== -`sysmon` EventID=1 (process_name=rundll32.exe OR OriginalFileName=RUNDLL32.EXE) -| regex CommandLine="(rundll32\.exe.{0,4}$)" -| stats count min(_time) as firstTime max(_time) as lastTime by dest, User, ParentImage,ParentCommandLine, process_name, OriginalFileName, process_path, CommandLine -| rename Computer as dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `suspicious_rundll32_no_commandline_arguments_filter` +`sysmon` EventID=1 (process_name=rundll32.exe OR OriginalFileName=RUNDLL32.EXE) +| regex CommandLine="(rundll32\.exe.{0,4}$)" +| stats count min(_time) as firstTime max(_time) as lastTime by dest, User, ParentImage,ParentCommandLine, process_name, OriginalFileName, process_path, CommandLine +| rename Computer as dest +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `suspicious_rundll32_no_command_line_arguments_filter` ====Associated Analytic Story==== @@ -20997,6 +26592,26 @@ To successfully implement this search, you need to be ingesting logs with the pr ====Required field==== +* _time + +* EventID + +* process_name + +* OriginalFileName + +* CommandLine + +* dest + +* User + +* ParentImage + +* ParentCommandLine + +* process_path + ====ATT&CK==== @@ -21035,6 +26650,268 @@ Although unlikely, some legitimate applications may use a moved copy of rundll32 * https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1218.011/atomic_red_team/windows-sysmon.log +''version'': 1 +
+
+ +---- + +===Suspicious sqlite3 lsquarantine behavior=== +The following analytic identifies the use of a SQLite3 querying the MacOS preferences to identify the original URL the pkg was downloaded from. This particular behavior is common with MacOS adware-malicious software. Upon triage, review other processes in parallel for suspicious activity. Identify any recent package installations. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1074/ T1074] +* '''Last Updated''': 2021-02-22 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=sqlite3 Processes.process=*LSQuarantine* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `suspicious_sqlite3_lsquarantine_behavior_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Silver_Sparrow|Silver Sparrow]] + + +====How To Implement==== +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. + +====Required field==== + +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_id + +* Processes.parent_process_id + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1074 +| Data Staged +| Collection +|} + + +====Kill Chain Phase==== + +* Actions on Objectives + + +====Known False Positives==== +Unknown. + +====Reference==== + +* https://redcanary.com/blog/clipping-silver-sparrows-wings/ + +* https://marcosantadev.com/manage-plist-files-plistbuddy/ + + +====Test Dataset==== + + +''version'': 1 +
+
+ +---- + +===Suspicious scheduled task from public directory=== +The following detection identifies Scheduled Tasks registering (creating a new task) a binary or script to run from a public directory which includes users\public, \programdata\ and \windows\temp. Upon triage, review the binary or script in the command line for legitimacy, whether an approved binary/script or not. In addition, capture the binary or script in question and analyze for further behaviors. Identify the source and contain the endpoint. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1053.005/ T1053.005] +* '''Last Updated''': 2021-03-01 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=schtasks.exe (Processes.process=*\\users\\public\\* OR Processes.process=*\\programdata\\* OR Processes.process=*windows\\temp*) Processes.process=*/create* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `suspicious_scheduled_task_from_public_directory_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] + +* [[Documentation:ESSOC:stories:UseCase#Ryuk_Ransomware|Ryuk Ransomware]] + +* [[Documentation:ESSOC:stories:UseCase#Windows_Persistence_Techniques|Windows Persistence Techniques]] + + +====How To Implement==== +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. + +====Required field==== + +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_name + +* Processes.process_id + +* Processes.parent_process_id + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1053.005 +| Scheduled Task +| Execution, Persistence, Privilege Escalation +|} + + +====Kill Chain Phase==== + +* Exploitation + +* Privilege Escalation + + +====Known False Positives==== +Limited false positives may be present. Filter as needed by parent process or command line argument. + +====Reference==== + +* https://attack.mitre.org/techniques/T1053/005/ + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1053.005/schtasks/windows-sysmon.log + + +''version'': 1 +
+
+ +---- + +===Suspicious searchprotocolhost no command line arguments=== +The following analytic identifies searchprotocolhost.exe with no command line arguments. It is unusual for searchprotocolhost.exe to execute with no command line arguments present. This particular behavior is common with malicious software, including Cobalt Strike. During investigation, identify any network connections and parallel processes. Identify any suspicious module loads related to credential dumping or file writes. searchprotocolhost.exe is natively found in C:\Windows\system32 and C:\Windows\syswow64. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1055/ T1055] +* '''Last Updated''': 2021-02-23 + +
+
+ +====Search==== +`sysmon` EventID=1 (process_name=searchprotocolhost.exe OR OriginalFileName=SearchProtocolHost.exe) +| regex CommandLine="(searchprotocolhost\.exe.{0,4}$)" +| stats count min(_time) as firstTime max(_time) as lastTime by dest, User, ParentImage,ParentCommandLine, process_name, OriginalFileName, process_path, CommandLine +| rename Computer as dest +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `suspicious_searchprotocolhost_no_command_line_arguments_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Cobalt_Strike|Cobalt Strike]] + + +====How To Implement==== +To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. + +====Required field==== + +* _time + +* EventID + +* process_name + +* OriginalFileName + +* CommandLine + +* dest + +* User + +* ParentImage + +* ParentCommandLine + +* process_path + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1055 +| Process Injection +| Defense Evasion, Privilege Escalation +|} + + +====Kill Chain Phase==== + +* Exploitation + + +====Known False Positives==== +Limited false positives may be present in small environments. Tuning may be required based on parent process. + +====Reference==== + +* https://github.com/fireeye/red_team_tool_countermeasures/blob/master/rules/PGF/supplemental/hxioc/SUSPICIOUS%20EXECUTION%20OF%20SEARCHPROTOCOLHOST%20(METHODOLOGY).ioc + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1055/cobalt_strike/windows-sysmon.log + + ''version'': 1
@@ -21045,7 +26922,7 @@ Although unlikely, some legitimate applications may use a moved copy of rundll32 The following analytic identifies a renamed instance of microsoft.workflow.compiler.exe. Microsoft.workflow.compiler.exe is natively found in C:\Windows\Microsoft.NET\Framework64\v4.0.30319 and is rarely utilized. When investigating, identify the executed code on disk and review. A spawned child process from microsoft.workflow.compiler.exe is uncommon. In any instance, microsoft.workflow.compiler.exe spawning from an Office product or any living off the land binary is highly suspect. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1127/ T1127], [https://attack.mitre.org/techniques/T1036.003/ T1036.003] * '''Last Updated''': 2021-01-12 @@ -21053,9 +26930,9 @@ The following analytic identifies a renamed instance of microsoft.workflow.compi
====Search==== -`sysmon` EventID=1 (OriginalFileName=microsoft.workflow.compiler.exe OR process_name=microsoft.workflow.compiler.exe) -| stats count min(_time) as firstTime max(_time) as lastTime by Computer, User, parent_process_name, process_name, OriginalFileName, process_path, CommandLine -| rename Computer as dest +`sysmon` EventID=1 (OriginalFileName=microsoft.workflow.compiler.exe OR process_name=microsoft.workflow.compiler.exe) +| stats count min(_time) as firstTime max(_time) as lastTime by Computer, User, parent_process_name, process_name, OriginalFileName, process_path, CommandLine +| rename Computer as dest | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `suspicious_microsoft_workflow_compiler_rename_filter` @@ -21064,12 +26941,32 @@ The following analytic identifies a renamed instance of microsoft.workflow.compi * [[Documentation:ESSOC:stories:UseCase#Trusted_Developer_Utilities_Proxy_Execution|Trusted Developer Utilities Proxy Execution]] +* [[Documentation:ESSOC:stories:UseCase#Cobalt_Strike|Cobalt Strike]] + ====How To Implement==== To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. ====Required field==== +* _time + +* EventID + +* OriginalFileName + +* process_name + +* Computer + +* User + +* parent_process_name + +* process_path + +* CommandLine + ====ATT&CK==== @@ -21127,10 +27024,10 @@ The following analytic identifies microsoft.workflow.compiler.exe usage. microso ====Search==== -| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=microsoft.workflow.compiler.exe by Processes.dest Processes.parent_process Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=microsoft.workflow.compiler.exe by Processes.dest Processes.parent_process Processes.user +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `suspicious_microsoft_workflow_compiler_usage_filter` ====Associated Analytic Story==== @@ -21143,6 +27040,18 @@ To successfully implement this search you need to be ingesting information on pr ====Required field==== +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.parent_process + +* Processes.user + ====ATT&CK==== @@ -21196,9 +27105,9 @@ The following analytic identifies msbuild.exe executing from a non-standard path ====Search==== -| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=msbuild.exe AND (Processes.process_path!=c:\\windows\\microsoft.net\\framework*\\v*\\*) by Processes.dest Processes.parent_process Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` +| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=msbuild.exe AND (Processes.process_path!=c:\\windows\\microsoft.net\\framework*\\v*\\*) by Processes.dest Processes.parent_process Processes.user +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `suspicious_msbuild_path_filter` @@ -21206,12 +27115,28 @@ The following analytic identifies msbuild.exe executing from a non-standard path * [[Documentation:ESSOC:stories:UseCase#Trusted_Developer_Utilities_Proxy_Execution_MSBuild|Trusted Developer Utilities Proxy Execution MSBuild]] +* [[Documentation:ESSOC:stories:UseCase#Cobalt_Strike|Cobalt Strike]] + ====How To Implement==== To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. ====Required field==== +* _time + +* Processes.process_name + +* Processes.process + +* Processes.process_path + +* Processes.dest + +* Processes.parent_process + +* Processes.user + ====ATT&CK==== @@ -21269,10 +27194,10 @@ The following analytic identifies child processes spawning from "mshta.exe". Th ====Search==== -| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=mshta.exe AND (Processes.process_name=powershell.exe OR Processes.process_name=colorcpl.exe OR Processes.process_name=msbuild.exe OR Processes.process_name=microsoft.workflow.compiler.exe OR Processes.process_name=searchprotocolhost.exe OR Processes.process_name=scrcons.exe OR Processes.process_name=cscript.exe OR Processes.process_name=wscript.exe OR Processes.process_name=powershell.exe OR Processes.process_name=cmd.exe) by Processes.dest Processes.parent_process Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=mshta.exe AND (Processes.process_name=powershell.exe OR Processes.process_name=colorcpl.exe OR Processes.process_name=msbuild.exe OR Processes.process_name=microsoft.workflow.compiler.exe OR Processes.process_name=searchprotocolhost.exe OR Processes.process_name=scrcons.exe OR Processes.process_name=cscript.exe OR Processes.process_name=wscript.exe OR Processes.process_name=powershell.exe OR Processes.process_name=cmd.exe) by Processes.dest Processes.parent_process Processes.user +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `suspicious_mshta_child_process_filter` ====Associated Analytic Story==== @@ -21285,6 +27210,20 @@ To successfully implement this search, you need to be ingesting logs with the pr ====Required field==== +* _time + +* Processes.process_name + +* Processes.process + +* Processes.parent_process_name + +* Processes.dest + +* Processes.parent_process + +* Processes.user + ====ATT&CK==== @@ -21338,10 +27277,10 @@ The following analytic identifies wmiprvse.exe spawning mshta.exe. This behavior ====Search==== -| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name=svchost.exe OR Processes.parent_process_name=wmiprvse.exe) AND Processes.process_name=mshta.exe by Processes.dest Processes.parent_process Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.parent_process_name=svchost.exe OR Processes.parent_process_name=wmiprvse.exe) AND Processes.process_name=mshta.exe by Processes.dest Processes.parent_process Processes.user +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `suspicious_mshta_spawn_filter` ====Associated Analytic Story==== @@ -21354,6 +27293,20 @@ To successfully implement this search you need to be ingesting information on pr ====Required field==== +* _time + +* Processes.process_name + +* Processes.process + +* Processes.parent_process_name + +* Processes.dest + +* Processes.parent_process + +* Processes.user + ====ATT&CK==== @@ -21410,9 +27363,9 @@ The wevtutil.exe application is the windows event log utility. This searches for ====Search==== | tstats `security_content_summariesonly` values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name = wevtutil.exe Processes.process="*cl*" (Processes.process="*System*" OR Processes.process="*Security*" OR Processes.process="*Setup*" OR Processes.process="*Application*") by Processes.process_name Processes.parent_process_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +|`security_content_ctime(lastTime)` | `suspicious_wevtutil_usage_filter` ====Associated Analytic Story==== @@ -21421,12 +27374,26 @@ The wevtutil.exe application is the windows event log utility. This searches for * [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] +* [[Documentation:ESSOC:stories:UseCase#Clop_Ransomware|Clop Ransomware]] + ====How To Implement==== You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. ====Required field==== +* _time + +* Processes.process + +* Processes.process_name + +* Processes.parent_process_name + +* Processes.dest + +* Processes.user + ====ATT&CK==== @@ -21467,7 +27434,7 @@ The wevtutil.exe application is a legitimate Windows event log utility. Administ This search detects writes to the recycle bin by a process other than explorer.exe. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1036/ T1036] * '''Last Updated''': 2020-07-22 @@ -21476,12 +27443,12 @@ This search detects writes to the recycle bin by a process other than explorer.e ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Filesystem.file_path) as file_path values(Filesystem.file_name) as file_name FROM datamodel=Endpoint.Filesystem where Filesystem.file_path = "*$Recycle.Bin*" by Filesystem.process_id Filesystem.dest +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Filesystem.file_path) as file_path values(Filesystem.file_name) as file_name FROM datamodel=Endpoint.Filesystem where Filesystem.file_path = "*$Recycle.Bin*" by Filesystem.process_id Filesystem.dest | `drop_dm_object_name("Filesystem")` | search [ | tstats `security_content_summariesonly` values(Processes.user) as user values(Processes.process_name) as process_name values(Processes.parent_process_name) as parent_process_name FROM datamodel=Endpoint.Processes where Processes.process_name != "explorer.exe" by Processes.process_id Processes.dest -| `drop_dm_object_name("Processes")` -| table process_id dest] +| `drop_dm_object_name("Processes")` +| table process_id dest] | `suspicious_writes_to_windows_recycle_bin_filter` ====Associated Analytic Story==== @@ -21494,6 +27461,26 @@ To successfully implement this search you need to be ingesting information on fi ====Required field==== +* _time + +* Filesystem.file_path + +* Filesystem.file_name + +* Filesystem.process_id + +* Filesystem.dest + +* Processes.user + +* Processes.process_name + +* Processes.parent_process_name + +* Processes.process_id + +* Processes.dest + ====ATT&CK==== @@ -21541,13 +27528,13 @@ Detect system information discovery techniques used by attackers to understand c ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process="*wmic* qfe*" OR Processes.process=*systeminfo* OR Processes.process=*hostname*) by Processes.user Processes.process_name Processes.process Processes.dest -| `drop_dm_object_name(Processes)` -| eventstats dc(process) as dc_processes_by_dest by dest -| where dc_processes_by_dest > 2 -| stats values(process) min(firstTime) as firstTime max(lastTime) as lastTime by user, dest +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process="*wmic* qfe*" OR Processes.process=*systeminfo* OR Processes.process=*hostname*) by Processes.user Processes.process_name Processes.process Processes.dest +| `drop_dm_object_name(Processes)` +| eventstats dc(process) as dc_processes_by_dest by dest +| where dc_processes_by_dest > 2 +| stats values(process) min(firstTime) as firstTime max(lastTime) as lastTime by user, dest | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | `system_information_discovery_detection_filter` ====Associated Analytic Story==== @@ -21560,6 +27547,16 @@ To successfully implement this search you need to be ingesting information on pr ====Required field==== +* _time + +* Processes.process + +* Processes.user + +* Processes.process_name + +* Processes.dest + ====ATT&CK==== @@ -21602,7 +27599,7 @@ Administrators debugging servers An attacker tries might try to use different version of a system command without overriding original, or they might try to avoid some detection running the process from a different folder. This detection checks that a list of system processes run inside C:\\Windows\System32 or C:\\Windows\SysWOW64 The list of system processes has been extracted from https://github.com/splunk/security_content/blob/develop/lookups/is_windows_system_file.csv and the original detection https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml * '''Product''': UEBA for Security Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1036/ T1036] * '''Last Updated''': 2020-08-25 @@ -21610,40 +27607,42 @@ An attacker tries might try to use different version of a system command without
====Search==== - $ssa_input = -| from read_ssa_enriched_events() + $ssa_input = +| from read_ssa_enriched_events() | eval device=ucast(map_get(input_event, "dest_device_id"), "string", null), user=ucast(map_get(input_event, "dest_user_id"), "string", null), timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)), process_name=lower(ucast(map_get(input_event, "process_name"), "string", null)), process_path=lower(ucast(map_get(input_event, "process_path"), "string", null)); -$cond_1 = -| from $ssa_input +$cond_1 = +| from $ssa_input | where process_name="arp.exe" OR process_name="adaptertroubleshooter.exe" OR process_name="applicationframehost.exe" OR process_name="atbroker.exe" OR process_name="authhost.exe" OR process_name="autoworkplace.exe" OR process_name="axinstui.exe" OR process_name="backgroundtransferhost.exe" OR process_name="bdehdcfg.exe" OR process_name="bdeuisrv.exe" OR process_name="bdeunlockwizard.exe" OR process_name="bitlockerdeviceencryption.exe" OR process_name="bitlockerwizard.exe" OR process_name="bitlockerwizardelev.exe" OR process_name="bytecodegenerator.exe" OR process_name="camerasettingsuihost.exe" OR process_name="castsrv.exe" OR process_name="certenrollctrl.exe" OR process_name="checknetisolation.exe" OR process_name="clipup.exe" OR process_name="cloudexperiencehostbroker.exe" OR process_name="cloudnotifications.exe" OR process_name="cloudstoragewizard.exe" OR process_name="compmgmtlauncher.exe" OR process_name="compattelrunner.exe" OR process_name="computerdefaults.exe" OR process_name="credentialuibroker.exe" OR process_name="dfdwiz.exe" OR process_name="dwwin.exe" OR process_name="dataexchangehost.exe" OR process_name="defrag.exe" OR process_name="devicedisplayobjectprovider.exe" OR process_name="deviceeject.exe" OR process_name="deviceenroller.exe" OR process_name="devicepairingwizard.exe" OR process_name="deviceproperties.exe" OR process_name="disksnapshot.exe" OR process_name="dism.exe" OR process_name="displayswitch.exe" OR process_name="dmnotificationbroker.exe" OR process_name="dmomacpmo.exe" OR process_name="dpiscaling.exe" OR process_name="dsmusertask.exe" OR process_name="dxpserver.exe" OR process_name="edpcleanup.exe" OR process_name="eosnotify.exe" OR process_name="eap3host.exe" OR process_name="easpoliciesbrokerhost.exe" OR process_name="easeofaccessdialog.exe" OR process_name="ehstorauthn.exe" OR process_name="fxscover.exe" OR process_name="fxssvc.exe" OR process_name="fxsunatd.exe" OR process_name="filehistory.exe" OR process_name="fondue.exe" OR process_name="gamepanel.exe" OR process_name="genvalobj.exe" OR process_name="gettingstarted.exe" OR process_name="hostname.exe" OR process_name="icsentitlementhost.exe" OR process_name="infdefaultinstall.exe" OR process_name="installagent.exe" OR process_name="languagecomponentsinstallercomhandler.exe" OR process_name="launchtm.exe" OR process_name="launchwinapp.exe" OR process_name="legacynetuxhost.exe" OR process_name="licensemanagershellext.exe" OR process_name="licensingui.exe" OR process_name="locationnotificationwindows.exe" OR process_name="locationnotifications.exe" OR process_name="locator.exe" OR process_name="lockapphost.exe" OR process_name="lockscreencontentserver.exe" OR process_name="logonui.exe" OR process_name="lsaiso.exe" OR process_name="mdeserver.exe" OR process_name="mdmagent.exe" OR process_name="mdmappinstaller.exe" OR process_name="mrinfo.exe" OR process_name="mrt.exe" OR process_name="mschedexe.exe" OR process_name="magnify.exe" OR process_name="mbaeparsertask.exe" OR process_name="mdres.exe" OR process_name="mdsched.exe" OR process_name="migautoplay.exe" OR process_name="mpsigstub.exe" OR process_name="msspellcheckinghost.exe" OR process_name="muiunattend.exe" OR process_name="multidigimon.exe" OR process_name="musnotification.exe" OR process_name="musnotificationux.exe" OR process_name="napstat.exe" OR process_name="netstat.exe" OR process_name="narrator.exe" OR process_name="netcfgnotifyobjecthost.exe" OR process_name="netevtfwdr.exe" OR process_name="netproj.exe" OR process_name="netplwiz.exe" OR process_name="networkuxbroker.exe"; -$cond_2 = -| from $ssa_input +$cond_2 = +| from $ssa_input | where process_name="openwith.exe" OR process_name="optionalfeatures.exe" OR process_name="pathping.exe" OR process_name="ping.exe" OR process_name="passwordonwakesettingflyout.exe" OR process_name="pickerhost.exe" OR process_name="pkgmgr.exe" OR process_name="pnpunattend.exe" OR process_name="pnputil.exe" OR process_name="presentationhost.exe" OR process_name="presentationsettings.exe" OR process_name="printbrmui.exe" OR process_name="printdialoghost.exe" OR process_name="printdialoghost3d.exe" OR process_name="printisolationhost.exe" OR process_name="proximityuxhost.exe" OR process_name="rdspnf.exe" OR process_name="rmactivate.exe" OR process_name="rmactivate_isv.exe" OR process_name="rmactivate_ssp.exe" OR process_name="rmactivate_ssp_isv.exe" OR process_name="route.exe" OR process_name="rdpsa.exe" OR process_name="rdpsaproxy.exe" OR process_name="rdpsauachelper.exe" OR process_name="reagentc.exe" OR process_name="recoverydrive.exe" OR process_name="register-cimprovider.exe" OR process_name="registeriepkeys.exe" OR process_name="relpost.exe" OR process_name="remoteposworker.exe" OR process_name="rmclient.exe" OR process_name="robocopy.exe" OR process_name="rpcping.exe" OR process_name="runlegacycplelevated.exe" OR process_name="runtimebroker.exe" OR process_name="sihclient.exe" OR process_name="searchfilterhost.exe" OR process_name="searchindexer.exe" OR process_name="searchprotocolhost.exe" OR process_name="secedit.exe" OR process_name="sensordataservice.exe" OR process_name="setieinstalleddate.exe" OR process_name="settingsynchost.exe" OR process_name="slidetoshutdown.exe" OR process_name="smartscreensettings.exe" OR process_name="sndvol.exe" OR process_name="snippingtool.exe" OR process_name="soundrecorder.exe" OR process_name="spaceagent.exe" OR process_name="sppextcomobj.exe" OR process_name="srtasks.exe" OR process_name="stikynot.exe" OR process_name="synchost.exe" OR process_name="sysreseterr.exe" OR process_name="systempropertiesadvanced.exe" OR process_name="systempropertiescomputername.exe" OR process_name="systempropertiesdataexecutionprevention.exe" OR process_name="systempropertieshardware.exe" OR process_name="systempropertiesperformance.exe" OR process_name="systempropertiesprotection.exe" OR process_name="systempropertiesremote.exe" OR process_name="systemsettingsadminflows.exe" OR process_name="systemsettingsbroker.exe" OR process_name="systemsettingsremovedevice.exe" OR process_name="tcpsvcs.exe" OR process_name="tracert.exe" OR process_name="tstheme.exe" OR process_name="tswbprxy.exe" OR process_name="tapiunattend.exe" OR process_name="taskmgr.exe" OR process_name="thumbnailextractionhost.exe" OR process_name="tokenbrokercookies.exe" OR process_name="tpminit.exe" OR process_name="tswpfwrp.exe" OR process_name="ui0detect.exe" OR process_name="upgraderesultsui.exe" OR process_name="useraccountbroker.exe" OR process_name="useraccountcontrolsettings.exe" OR process_name="usoclient.exe" OR process_name="utilman.exe" OR process_name="vssvc.exe" OR process_name="vaultcmd.exe" OR process_name="vaultsysui.exe" OR process_name="wfs.exe" OR process_name="wmpdmc.exe" OR process_name="wpdshextautoplay.exe" OR process_name="wscollect.exe" OR process_name="wsmanhttpconfig.exe" OR process_name="wsreset.exe" OR process_name="wudfhost.exe" OR process_name="wwahost.exe" OR process_name="wallpaperhost.exe" OR process_name="webcache.exe" OR process_name="werfault.exe" OR process_name="werfaultsecure.exe" OR process_name="winsat.exe" OR process_name="windows.media.backgroundplayback.exe" OR process_name="windowsactiondialog.exe" OR process_name="windowsanytimeupgrade.exe" OR process_name="windowsanytimeupgraderesults.exe"; -$cond_3 = -| from $ssa_input +$cond_3 = +| from $ssa_input | where process_name="windowsanytimeupgradeui.exe" OR process_name="windowsupdateelevatedinstaller.exe" OR process_name="workfolders.exe" OR process_name="wpcmon.exe" OR process_name="acu.exe" OR process_name="aitagent.exe" OR process_name="aitstatic.exe" OR process_name="alg.exe" OR process_name="appidcertstorecheck.exe" OR process_name="appidpolicyconverter.exe" OR process_name="at.exe" OR process_name="attrib.exe" OR process_name="audiodg.exe" OR process_name="auditpol.exe" OR process_name="autochk.exe" OR process_name="autoconv.exe" OR process_name="autofmt.exe" OR process_name="baaupdate.exe" OR process_name="backgroundtaskhost.exe" OR process_name="bcastdvr.exe" OR process_name="bcdboot.exe" OR process_name="bcdedit.exe" OR process_name="bdechangepin.exe" OR process_name="bdeunlock.exe" OR process_name="bitsadmin.exe" OR process_name="bootcfg.exe" OR process_name="bootim.exe" OR process_name="bootsect.exe" OR process_name="bridgeunattend.exe" OR process_name="browser_broker.exe" OR process_name="bthudtask.exe" OR process_name="cacls.exe" OR process_name="calc.exe" OR process_name="cdpreference.exe" OR process_name="certreq.exe" OR process_name="certutil.exe" OR process_name="change.exe" OR process_name="changepk.exe" OR process_name="charmap.exe" OR process_name="chglogon.exe" OR process_name="chgport.exe" OR process_name="chgusr.exe" OR process_name="chkdsk.exe" OR process_name="chkntfs.exe" OR process_name="choice.exe" OR process_name="cipher.exe" OR process_name="cleanmgr.exe" OR process_name="cliconfg.exe" OR process_name="clip.exe" OR process_name="cmd.exe" OR process_name="cmdkey.exe" OR process_name="cmdl32.exe" OR process_name="cmmon32.exe" OR process_name="cmstp.exe" OR process_name="cofire.exe" OR process_name="colorcpl.exe" OR process_name="comp.exe" OR process_name="compact.exe" OR process_name="conhost.exe" OR process_name="consent.exe" OR process_name="control.exe" OR process_name="convert.exe" OR process_name="credwiz.exe" OR process_name="cscript.exe" OR process_name="csrss.exe" OR process_name="ctfmon.exe" OR process_name="cttune.exe" OR process_name="cttunesvr.exe" OR process_name="dashost.exe" OR process_name="dccw.exe" OR process_name="dcomcnfg.exe" OR process_name="ddodiag.exe" OR process_name="dfrgui.exe" OR process_name="dialer.exe" OR process_name="diantz.exe" OR process_name="dinotify.exe" OR process_name="diskpart.exe" OR process_name="diskperf.exe" OR process_name="diskraid.exe" OR process_name="dispdiag.exe" OR process_name="djoin.exe" OR process_name="dllhost.exe" OR process_name="dllhst3g.exe" OR process_name="dmcertinst.exe" OR process_name="dmcfghost.exe" OR process_name="dmclient.exe" OR process_name="dnscacheugc.exe" OR process_name="doskey.exe" OR process_name="dpapimig.exe" OR process_name="dpnsvr.exe" OR process_name="driverquery.exe" OR process_name="drvcfg.exe" OR process_name="drvinst.exe" OR process_name="dsregcmd.exe" OR process_name="dstokenclean.exe" OR process_name="dvdplay.exe" OR process_name="dvdupgrd.exe" OR process_name="dwm.exe" OR process_name="dxdiag.exe" OR process_name="easinvoker.exe" OR process_name="efsui.exe"; -$cond_4 = -| from $ssa_input +$cond_4 = +| from $ssa_input | where process_name="embeddedapplauncher.exe" OR process_name="esentutl.exe" OR process_name="eudcedit.exe" OR process_name="eventcreate.exe" OR process_name="eventvwr.exe" OR process_name="expand.exe" OR process_name="extrac32.exe" OR process_name="fc.exe" OR process_name="fhmanagew.exe" OR process_name="find.exe" OR process_name="findstr.exe" OR process_name="finger.exe" OR process_name="fixmapi.exe" OR process_name="fltmc.exe" OR process_name="fodhelper.exe" OR process_name="fontdrvhost.exe" OR process_name="fontview.exe" OR process_name="forfiles.exe" OR process_name="fsavailux.exe" OR process_name="fsquirt.exe" OR process_name="fsutil.exe" OR process_name="ftp.exe" OR process_name="fvenotify.exe" OR process_name="fveprompt.exe" OR process_name="getmac.exe" OR process_name="gpresult.exe" OR process_name="gpscript.exe" OR process_name="gpupdate.exe" OR process_name="grpconv.exe" OR process_name="hdwwiz.exe" OR process_name="help.exe" OR process_name="hwrcomp.exe" OR process_name="hwrreg.exe" OR process_name="icacls.exe" OR process_name="icardagt.exe" OR process_name="icsunattend.exe" OR process_name="ie4uinit.exe" OR process_name="ieunatt.exe" OR process_name="ieetwcollector.exe" OR process_name="iexpress.exe" OR process_name="immersivetpmvscmgrsvr.exe" OR process_name="ipconfig.exe" OR process_name="irftp.exe" OR process_name="iscsicli.exe" OR process_name="iscsicpl.exe" OR process_name="isoburn.exe" OR process_name="klist.exe" OR process_name="ksetup.exe" OR process_name="ktmutil.exe" OR process_name="label.exe" OR process_name="licensingdiag.exe" OR process_name="lodctr.exe" OR process_name="logagent.exe" OR process_name="logman.exe" OR process_name="logoff.exe" OR process_name="lpkinstall.exe" OR process_name="lpksetup.exe" OR process_name="lpremove.exe" OR process_name="lsass.exe" OR process_name="lsm.exe" OR process_name="makecab.exe" OR process_name="manage-bde.exe" OR process_name="mblctr.exe" OR process_name="mcbuilder.exe" OR process_name="mctadmin.exe" OR process_name="mfpmp.exe" OR process_name="mmc.exe" OR process_name="mobsync.exe" OR process_name="mountvol.exe" OR process_name="mpnotify.exe" OR process_name="msconfig.exe" OR process_name="msdt.exe" OR process_name="msdtc.exe" OR process_name="msfeedssync.exe" OR process_name="msg.exe" OR process_name="mshta.exe" OR process_name="msiexec.exe" OR process_name="msinfo32.exe" OR process_name="mspaint.exe" OR process_name="msra.exe" OR process_name="mstsc.exe" OR process_name="mtstocom.exe" OR process_name="nbtstat.exe" OR process_name="ndadmin.exe" OR process_name="net.exe" OR process_name="net1.exe" OR process_name="netbtugc.exe" OR process_name="netcfg.exe" OR process_name="netiougc.exe" OR process_name="netsh.exe" OR process_name="newdev.exe" OR process_name="nltest.exe" OR process_name="notepad.exe" OR process_name="nslookup.exe" OR process_name="ntoskrnl.exe" OR process_name="ntprint.exe" OR process_name="ocsetup.exe" OR process_name="odbcad32.exe" OR process_name="odbcconf.exe" OR process_name="omadmclient.exe" OR process_name="omadmprc.exe"; -$cond_5 = -| from $ssa_input +$cond_5 = +| from $ssa_input | where process_name="openfiles.exe" OR process_name="osk.exe" OR process_name="p2phost.exe" OR process_name="pcalua.exe" OR process_name="pcaui.exe" OR process_name="pcawrk.exe" OR process_name="pcwrun.exe" OR process_name="perfmon.exe" OR process_name="phoneactivate.exe" OR process_name="plasrv.exe" OR process_name="poqexec.exe" OR process_name="powercfg.exe" OR process_name="prevhost.exe" OR process_name="print.exe" OR process_name="printfilterpipelinesvc.exe" OR process_name="printui.exe" OR process_name="proquota.exe" OR process_name="provtool.exe" OR process_name="psr.exe" OR process_name="pwlauncher.exe" OR process_name="qappsrv.exe" OR process_name="qprocess.exe" OR process_name="query.exe" OR process_name="quser.exe" OR process_name="qwinsta.exe" OR process_name="rasautou.exe" OR process_name="rasdial.exe" OR process_name="raserver.exe" OR process_name="rasphone.exe" OR process_name="rdpclip.exe" OR process_name="rdpinput.exe" OR process_name="rdrleakdiag.exe" OR process_name="recdisc.exe" OR process_name="recover.exe" OR process_name="reg.exe" OR process_name="regedt32.exe" OR process_name="regini.exe" OR process_name="regsvr32.exe" OR process_name="rekeywiz.exe" OR process_name="relog.exe" OR process_name="repair-bde.exe" OR process_name="replace.exe" OR process_name="reset.exe" OR process_name="resmon.exe" OR process_name="rmttpmvscmgrsvr.exe" OR process_name="rrinstaller.exe" OR process_name="rstrui.exe" OR process_name="runas.exe" OR process_name="rundll32.exe" OR process_name="runonce.exe" OR process_name="rwinsta.exe" OR process_name="sbunattend.exe" OR process_name="sc.exe" OR process_name="schtasks.exe" OR process_name="sdbinst.exe" OR process_name="sdchange.exe" OR process_name="sdclt.exe" OR process_name="sdiagnhost.exe" OR process_name="secinit.exe" OR process_name="services.exe" OR process_name="sessionmsg.exe" OR process_name="sethc.exe" OR process_name="setspn.exe" OR process_name="setupcl.exe" OR process_name="setupugc.exe" OR process_name="setx.exe" OR process_name="sfc.exe" OR process_name="shadow.exe" OR process_name="shrpubw.exe" OR process_name="shutdown.exe" OR process_name="sigverif.exe" OR process_name="sihost.exe" OR process_name="slui.exe" OR process_name="smss.exe" OR process_name="snmptrap.exe" OR process_name="sort.exe" OR process_name="spinstall.exe" OR process_name="spoolsv.exe" OR process_name="sppsvc.exe" OR process_name="spreview.exe" OR process_name="srdelayed.exe" OR process_name="subst.exe" OR process_name="svchost.exe" OR process_name="sxstrace.exe" OR process_name="syskey.exe" OR process_name="systeminfo.exe" OR process_name="systemreset.exe" OR process_name="systray.exe" OR process_name="tabcal.exe" OR process_name="takeown.exe" OR process_name="taskeng.exe" OR process_name="taskhost.exe" OR process_name="taskhostw.exe" OR process_name="taskkill.exe" OR process_name="tasklist.exe" OR process_name="taskmgr.exe" OR process_name="tcmsetup.exe" OR process_name="timeout.exe" OR process_name="tpmvscmgr.exe" OR process_name="tpmvscmgrsvr.exe"; -$cond_6 = -| from $ssa_input +$cond_6 = +| from $ssa_input | where process_name="tracerpt.exe" OR process_name="tscon.exe" OR process_name="tsdiscon.exe" OR process_name="tskill.exe" OR process_name="typeperf.exe" OR process_name="tzsync.exe" OR process_name="tzutil.exe" OR process_name="ucsvc.exe" OR process_name="unlodctr.exe" OR process_name="unregmp2.exe" OR process_name="upnpcont.exe" OR process_name="userinit.exe" OR process_name="vds.exe" OR process_name="vdsldr.exe" OR process_name="verclsid.exe" OR process_name="verifier.exe" OR process_name="verifiergui.exe" OR process_name="vmicsvc.exe" OR process_name="vssadmin.exe" OR process_name="w32tm.exe" OR process_name="waitfor.exe" OR process_name="wbadmin.exe" OR process_name="wbengine.exe" OR process_name="wecutil.exe" OR process_name="wermgr.exe" OR process_name="wevtutil.exe" OR process_name="wextract.exe" OR process_name="where.exe" OR process_name="whoami.exe" OR process_name="wiaacmgr.exe" OR process_name="wiawow64.exe" OR process_name="wifitask.exe" OR process_name="wimserv.exe" OR process_name="wininit.exe" OR process_name="winload.exe" OR process_name="winlogon.exe" OR process_name="winresume.exe" OR process_name="winrs.exe" OR process_name="winrshost.exe" OR process_name="winver.exe" OR process_name="wisptis.exe" OR process_name="wkspbroker.exe" OR process_name="wksprt.exe" OR process_name="wlanext.exe" OR process_name="wlrmdr.exe" OR process_name="wowreg32.exe" OR process_name="wpnpinst.exe" OR process_name="wpr.exe" OR process_name="write.exe" OR process_name="wscript.exe" OR process_name="wsmprovhost.exe" OR process_name="wsqmcons.exe" OR process_name="wuapihost.exe" OR process_name="wuapp.exe" OR process_name="wuauclt.exe" OR process_name="wusa.exe" OR process_name="xcopy.exe" OR process_name="xpsrchvw.exe" OR process_name="xwizard.exe"; -| from $cond_1 -| union $cond_2 -| union $cond_3 -| union $cond_4 -| union $cond_5 -| union $cond_6 -| where process_path!="c:\\windows\\system32" AND process_path!="c:\\windows\\syswow64" -| eval start_time = timestamp, end_time = timestamp, entities = mvappend(device, user), body = "TBD" +| from $cond_1 +| union $cond_2 +| union $cond_3 +| union $cond_4 +| union $cond_5 +| union $cond_6 +| where process_path!="c:\\windows\\system32" AND process_path!="c:\\windows\\syswow64" +| eval start_time = timestamp, end_time = timestamp, entities = mvappend(device, user), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Windows_Defense_Evasion_Tactics|Windows Defense Evasion Tactics]] + ====How To Implement==== Collect endpoint data such as sysmon or 4688 events. @@ -21698,7 +27697,7 @@ None This search looks for system processes that normally run out of C:\Windows\System32\ or C:\Windows\SysWOW64 that are not run from that location. This can indicate a malicious process that is trying to hide as a legitimate process. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1036.003/ T1036.003] * '''Last Updated''': 2020-12-08 @@ -21708,10 +27707,10 @@ This search looks for system processes that normally run out of C:\Windows\Syste ====Search==== | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes where Processes.process_path !="C:\\Windows\\System32*" Processes.process_path !="C:\\Windows\\SysWOW64*" by Processes.user Processes.dest Processes.process_name Processes.process_id Processes.process_path Processes.parent_process_name Processes.process_hash -| `drop_dm_object_name("Processes")` +| `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` -| `is_windows_system_file` +| `is_windows_system_file` | `system_processes_run_from_unexpected_locations_filter` ====Associated Analytic Story==== @@ -21728,6 +27727,22 @@ To successfully implement this search you need to ingest details about process e ====Required field==== +* _time + +* Processes.process_path + +* Processes.user + +* Processes.dest + +* Processes.process_name + +* Processes.process_id + +* Processes.parent_process_name + +* Processes.process_hash + ====ATT&CK==== @@ -21777,11 +27792,11 @@ The fsutil.exe application is a legitimate Windows utility used to perform tasks ====Search==== -| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=fsutil.exe by Processes.user Processes.process_name Processes.parent_process_name Processes.dest -| `drop_dm_object_name(Processes)` +| tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=fsutil.exe by Processes.user Processes.process_name Processes.parent_process_name Processes.dest +| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| search process="*deletejournal*" AND process="*usn*" +| `security_content_ctime(lastTime)` +| search process="*deletejournal*" AND process="*usn*" | `usn_journal_deletion_filter` ====Associated Analytic Story==== @@ -21796,6 +27811,20 @@ You must be ingesting data that records process activity from your hosts to popu ====Required field==== +* _time + +* Processes.process + +* Processes.parent_process + +* Processes.process_name + +* Processes.user + +* Processes.parent_process_name + +* Processes.dest + ====ATT&CK==== @@ -21832,6 +27861,93 @@ None identified ---- +===Unified messaging service spawning a process=== +This detection identifies Microsoft Exchange Server's Unified Messaging services, umworkerprocess.exe and umservice.exe, spawning a child process, indicating possible exploitation of CVE-2021-26857 vulnerability. The query filters out werfault.exe and wermgr.exe mostly due to potential false positives, however, if there is an excessive amount of "wermgr.exe" or "WerFault.exe" failures, it may be due to the active exploitation. During triage, identify any additional suspicious parallel processes. Identify any recent out of place file modifications. Review Exchange logs following Microsofts guide. To contain, perform egress filtering or restrict public access to Exchange. In final, patch the vulnerablity and monitor. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1190/ T1190] +* '''Last Updated''': 2021-03-02 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name="umworkerprocess.exe" OR Processes.parent_process_name="UMService.exe" (Processes.process_name!="wermgr.exe" OR Processes.process_name!="werfault.exe") by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `unified_messaging_service_spawning_a_process_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#HAFNIUM_Group|HAFNIUM Group]] + + +====How To Implement==== +To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. + +====Required field==== + +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + +* Processes.process_id + +* Processes.parent_process_id + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1190 +| Exploit Public-Facing Application +| Initial Access +|} + + +====Kill Chain Phase==== + +* Exploitation + + +====Known False Positives==== +Unknown. Tune out child processes as needed to limit volume of false positives. + +====Reference==== + +* https://www.volexity.com/blog/2021/03/02/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities/ + +* https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/ + +* https://blog.rapid7.com/2021/03/03/rapid7s-insightidr-enables-detection-and-response-to-microsoft-exchange-0-day/ + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1505.003/windows-sysmon_umservices.log + + +''version'': 1 +
+
+ +---- + ===Unload sysmon filter driver=== Attackers often disable security tools to avoid detection. This search looks for the usage of process `fltMC.exe` to unload a Sysmon Driver that will stop sysmon from collecting the data. @@ -21845,10 +27961,10 @@ Attackers often disable security tools to avoid detection. This search looks for ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime values(Processes.process) as process max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=fltMC.exe AND Processes.process=*unload* AND Processes.process=*SysmonDrv* by Processes.process_name Processes.process_id Processes.parent_process_name Processes.process Processes.dest Processes.user -| `drop_dm_object_name("Processes")` +| tstats `security_content_summariesonly` count min(_time) as firstTime values(Processes.process) as process max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=fltMC.exe AND Processes.process=*unload* AND Processes.process=*SysmonDrv* by Processes.process_name Processes.process_id Processes.parent_process_name Processes.process Processes.dest Processes.user +| `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` +|`security_content_ctime(lastTime)` |`unload_sysmon_filter_driver_filter` | table firstTime lastTime dest user count process_name process_id parent_process_name process @@ -21862,6 +27978,20 @@ You must be ingesting data that records process activity from your hosts to popu ====Required field==== +* _time + +* Processes.process_name + +* Processes.process + +* Processes.process_id + +* Processes.parent_process_name + +* Processes.dest + +* Processes.user + ====ATT&CK==== @@ -21902,31 +28032,33 @@ You must be ingesting data that records process activity from your hosts to popu Command lines that are extremely long may be indicative of malicious activity on your hosts. This search leverages the Splunk Streaming ML DSP plugin to help identify command lines with lengths that are unusual for a given user. This detection is inspired on Unusually Long Command Line authored by Rico Valdez. * '''Product''': UEBA for Security Cloud -* '''Datamodel''': -* '''ATT&CK''': +* '''Datamodel''': +* '''ATT&CK''': * '''Last Updated''': 2020-10-06
====Search==== - -| from read_ssa_enriched_events() -| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) -| eval cmd_line=ucast(map_get(input_event, "process"), "string", null), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null) -| where cmd_line!=null and dest_user_id!=null + +| from read_ssa_enriched_events() +| eval timestamp=parse_long(ucast(map_get(input_event, "_time"), "string", null)) +| eval cmd_line=ucast(map_get(input_event, "process"), "string", null), dest_user_id=ucast(map_get(input_event, "dest_user_id"), "string", null), dest_device_id=ucast(map_get(input_event, "dest_device_id"), "string", null), process_name=ucast(map_get(input_event, "process_name"), "string", null) +| where cmd_line!=null and dest_user_id!=null | eval cmd_line_norm=replace(cast(cmd_line, "string"), /\s(--?\w+) -|(\/\w+)/, " ARG"), cmd_line_norm=replace(cmd_line_norm, /\w:\\[^\s]+/, "PATH"), cmd_line_norm=replace(cmd_line_norm, /\d+/, "N"), input=parse_double(len(coalesce(cmd_line_norm, ""))) -| select timestamp, process_name, dest_device_id, dest_user_id, cmd_line, input -| adaptive_threshold algorithm="quantile" entity="process_name" window=60480000 -| where label AND quantile>0.99 -| first_time_event input_columns=["dest_device_id", "cmd_line"] -| where first_time_dest_device_id_cmd_line -| eval start_time = timestamp, end_time = timestamp, entities = mvappend(dest_device_id, dest_user_id), body = "TBD" +|(\/\w+)/, " ARG"), cmd_line_norm=replace(cmd_line_norm, /\w:\\[^\s]+/, "PATH"), cmd_line_norm=replace(cmd_line_norm, /\d+/, "N"), input=parse_double(len(coalesce(cmd_line_norm, ""))) +| select timestamp, process_name, dest_device_id, dest_user_id, cmd_line, input +| adaptive_threshold algorithm="quantile" entity="process_name" window=60480000 +| where label AND quantile>0.99 +| first_time_event input_columns=["dest_device_id", "cmd_line"] +| where first_time_dest_device_id_cmd_line +| eval start_time = timestamp, end_time = timestamp, entities = mvappend(dest_device_id, dest_user_id), body = "TBD" | into write_ssa_detected_events(); ====Associated Analytic Story==== +* [[Documentation:ESSOC:stories:UseCase#Unusual_Processes|Unusual Processes]] + ====How To Implement==== You must be ingesting sysmon endpoint data that monitors command lines. @@ -21970,8 +28102,8 @@ This detection may flag suspiciously long command lines when there is not suffic Command lines that are extremely long may be indicative of malicious activity on your hosts. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': +* '''Datamodel''': +* '''ATT&CK''': * '''Last Updated''': 2020-12-08
@@ -21979,15 +28111,15 @@ Command lines that are extremely long may be indicative of malicious activity on ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes by Processes.user Processes.dest Processes.process_name Processes.process -| `drop_dm_object_name("Processes")` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes by Processes.user Processes.dest Processes.process_name Processes.process +| `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` -| eval processlen=len(process) -| eventstats stdev(processlen) as stdev, avg(processlen) as avg by dest -| stats max(processlen) as maxlen, values(stdev) as stdevperhost, values(avg) as avgperhost by dest, user, process_name, process -| `unusually_long_command_line_filter` -|eval threshold = 3 +| eval processlen=len(process) +| eventstats stdev(processlen) as stdev, avg(processlen) as avg by dest +| stats max(processlen) as maxlen, values(stdev) as stdevperhost, values(avg) as avgperhost by dest, user, process_name, process +| `unusually_long_command_line_filter` +|eval threshold = 3 | where maxlen > ((threshold*stdevperhost) + avgperhost) ====Associated Analytic Story==== @@ -22006,6 +28138,16 @@ You must be ingesting endpoint data that tracks process activity, including pare ====Required field==== +* _time + +* Processes.user + +* Processes.dest + +* Processes.process_name + +* Processes.process + @@ -22035,8 +28177,8 @@ Some legitimate applications start with long command lines. Command lines that are extremely long may be indicative of malicious activity on your hosts. This search leverages the Machine Learning Toolkit (MLTK) to help identify command lines with lengths that are unusual for a given user. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': +* '''Datamodel''': +* '''ATT&CK''': * '''Last Updated''': 2019-05-08
@@ -22044,16 +28186,16 @@ Command lines that are extremely long may be indicative of malicious activity on ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes by Processes.user Processes.dest Processes.process_name Processes.process -| `drop_dm_object_name(Processes)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes by Processes.user Processes.dest Processes.process_name Processes.process +| `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` -| eval processlen=len(process) -| search user!=unknown -| apply cmdline_pdfmodel threshold=0.01 -| rename "IsOutlier(processlen)" as isOutlier -| search isOutlier > 0 -| table firstTime lastTime user dest process_name process processlen count +| eval processlen=len(process) +| search user!=unknown +| apply cmdline_pdfmodel threshold=0.01 +| rename "IsOutlier(processlen)" as isOutlier +| search isOutlier > 0 +| table firstTime lastTime user dest process_name process processlen count | `unusually_long_command_line___mltk_filter` ====Associated Analytic Story==== @@ -22072,6 +28214,16 @@ You must be ingesting endpoint data that monitors command lines and populates th ====Required field==== +* _time + +* Processes.user + +* Processes.dest + +* Processes.process_name + +* Processes.process + @@ -22089,6 +28241,85 @@ Some legitimate applications use long command lines for installs or updates. You ====Test Dataset==== +''version'': 1 +
+
+ +---- + +===W3wp spawning shell=== +This query identifies a shell, PowerShell.exe or Cmd.exe, spawning from W3WP.exe, or IIS. In addition to IIS logs, this behavior with an EDR product will capture potential webshell activity, similar to the HAFNIUM Group abusing CVEs, on publicly available Exchange mail servers. During triage, review the parent process and child process of the shell being spawned. Review the command-line arguments and any file modifications that may occur. Identify additional parallel process, child processes, that may highlight further commands executed. After triaging, work to contain the threat and patch the system that is vulnerable. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1505.003/ T1505.003] +* '''Last Updated''': 2021-03-03 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` count values(Processes.process_name) as process_name values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name=w3wp.exe AND Processes.process_name=cmd.exe OR Processes.process_name=powershell.exe by Processes.dest Processes.parent_process Processes.user +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `w3wp_spawning_shell_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#HAFNIUM_Group|HAFNIUM Group]] + + +====How To Implement==== +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. + +====Required field==== + +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.parent_process + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1505.003 +| Web Shell +| Persistence +|} + + +====Kill Chain Phase==== + +* Exploitation + + +====Known False Positives==== +Baseline your environment before production. It is possible build systems using IIS will spawn cmd.exe to perform a software build. Filter as needed. + +====Reference==== + +* https://www.microsoft.com/security/blog/2020/02/04/ghost-in-the-shell-investigating-web-shell-attacks/ + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1505.003/windows-sysmon.log + + ''version'': 1
@@ -22108,9 +28339,9 @@ This search looks for flags passed to wbadmin.exe (Windows Backup Administrator ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=wbadmin.exe Processes.process="*delete*" AND (Processes.process="*catalog*" OR Processes.process="*systemstatebackup*") by Processes.process_name Processes.process Processes.parent_process_name Processes.dest Processes.user -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=wbadmin.exe Processes.process="*delete*" AND (Processes.process="*catalog*" OR Processes.process="*systemstatebackup*") by Processes.process_name Processes.process Processes.parent_process_name Processes.dest Processes.user +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `wbadmin_delete_system_backups_filter` @@ -22126,6 +28357,18 @@ You must be ingesting endpoint data that tracks process activity, including pare ====Required field==== +* _time + +* Processes.process_name + +* Processes.process + +* Processes.parent_process_name + +* Processes.dest + +* Processes.user + ====ATT&CK==== @@ -22174,7 +28417,7 @@ Administrators may modify the boot configuration. This search looks for the creation of WMI permanent event subscriptions. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1047/ T1047] * '''Last Updated''': 2018-10-23 @@ -22182,14 +28425,14 @@ This search looks for the creation of WMI permanent event subscriptions.
====Search==== -`wmi` EventCode=5861 Binding +`wmi` EventCode=5861 Binding | rex field=Message "Consumer =\s+(?[^; -|^$]+)" -| search consumer!="NTEventLogEventConsumer=\"SCM Event Log Consumer\"" -| stats count min(_time) as firstTime max(_time) as lastTime by ComputerName, consumer, Message +|^$]+)" +| search consumer!="NTEventLogEventConsumer=\"SCM Event Log Consumer\"" +| stats count min(_time) as firstTime max(_time) as lastTime by ComputerName, consumer, Message | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| rename ComputerName as dest +| `security_content_ctime(lastTime)` +| rename ComputerName as dest | `wmi_permanent_event_subscription_filter` ====Associated Analytic Story==== @@ -22202,6 +28445,16 @@ To successfully implement this search, you must be ingesting the Windows WMI act ====Required field==== +* _time + +* EventCode + +* Message + +* consumer + +* ComputerName + ====ATT&CK==== @@ -22240,7 +28493,7 @@ Although unlikely, administrators may use event subscriptions for legitimate pur This search looks for the creation of WMI permanent event subscriptions. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1546.003/ T1546.003] * '''Last Updated''': 2020-12-08 @@ -22248,9 +28501,9 @@ This search looks for the creation of WMI permanent event subscriptions.
====Search==== -`sysmon` EventCode=21 -| rename host as dest -| table _time, dest, user, Operation, EventType, Query, Consumer, Filter +`sysmon` EventCode=21 +| rename host as dest +| table _time, dest, user, Operation, EventType, Query, Consumer, Filter | `wmi_permanent_event_subscription___sysmon_filter` ====Associated Analytic Story==== @@ -22263,6 +28516,24 @@ To successfully implement this search, you must be collecting Sysmon data using ====Required field==== +* _time + +* EventCode + +* host + +* user + +* Operation + +* EventType + +* Query + +* Consumer + +* Filter + ====ATT&CK==== @@ -22303,7 +28574,7 @@ Although unlikely, administrators may use event subscriptions for legitimate pur This search looks for the creation of WMI temporary event subscriptions. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1047/ T1047] * '''Last Updated''': 2018-10-23 @@ -22311,13 +28582,13 @@ This search looks for the creation of WMI temporary event subscriptions.
====Search==== -`wmi` EventCode=5860 Temporary +`wmi` EventCode=5860 Temporary | rex field=Message "NotificationQuery =\s+(?[^; -|^$]+)" -| search query!="SELECT * FROM Win32_ProcessStartTrace WHERE ProcessName = 'wsmprovhost.exe'" AND query!="SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'AntiVirusProduct' OR TargetInstance ISA 'FirewallProduct' OR TargetInstance ISA 'AntiSpywareProduct'" -| stats count min(_time) as firstTime max(_time) as lastTime by ComputerName, query +|^$]+)" +| search query!="SELECT * FROM Win32_ProcessStartTrace WHERE ProcessName = 'wsmprovhost.exe'" AND query!="SELECT * FROM __InstanceOperationEvent WHERE TargetInstance ISA 'AntiVirusProduct' OR TargetInstance ISA 'FirewallProduct' OR TargetInstance ISA 'AntiSpywareProduct'" +| stats count min(_time) as firstTime max(_time) as lastTime by ComputerName, query | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | `wmi_temporary_event_subscription_filter` ====Associated Analytic Story==== @@ -22330,6 +28601,14 @@ To successfully implement this search, you must be ingesting the Windows WMI act ====Required field==== +* _time + +* EventCode + +* Message + +* query + ====ATT&CK==== @@ -22376,16 +28655,16 @@ This search looks for the execution of `adfind.exe` with command-line arguments
====Search==== - -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process=*-f* OR Processes.process=*-b*) AND (Processes.process=*objectcategory* OR Processes.process=*-gcb* OR Processes.process=*-sc*) by Processes.dest Processes.user Processes.process_name Processes.process Processes.parent_process Processes.process_id Processes.parent_process_id -| `drop_dm_object_name(Processes)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where (Processes.process=*-f* OR Processes.process=*-b*) AND (Processes.process=*objectcategory* OR Processes.process=*-gcb* OR Processes.process=*-sc*) by Processes.dest Processes.user Processes.process_name Processes.process Processes.parent_process Processes.process_id Processes.parent_process_id +| `drop_dm_object_name(Processes)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `windows_adfind_exe_filter` ====Associated Analytic Story==== -* [[Documentation:ESSOC:stories:UseCase#Sunburst_Malware|Sunburst Malware]] +* [[Documentation:ESSOC:stories:UseCase#NOBELIUM_Group|NOBELIUM Group]] ====How To Implement==== @@ -22393,6 +28672,22 @@ To successfully implement this search, you need to be ingesting logs with the pr ====Required field==== +* _time + +* Processes.process + +* Processes.dest + +* Processes.user + +* Processes.process_name + +* Processes.parent_process + +* Processes.process_id + +* Processes.parent_process_id + ====ATT&CK==== @@ -22433,11 +28728,92 @@ administrators rarely use adfind, usually not used for legitimate reasons ---- +===Windows disableantispyware registry=== +The search looks for the Registry Key DisableAntiSpyware set to disable. This is consistent with Ryuk infections across a fleet of endpoints. This particular behavior is typically executed when an ransomware actor gains access to an endpoint and beings to perform execution. Usually, a batch (.bat) will be executed and multiple registry and scheduled task modifications will occur. During triage, review parallel processes and identify any further file modifications. Endpoint should be isolated. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1562.001/ T1562.001] +* '''Last Updated''': 2021-03-02 + +
+
+ +====Search==== + +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Registry where Registry.registry_key_name="DisableAntiSpyware" AND Registry.registry_value_name="DWORD (0x00000001)" by Registry.dest Registry.user Registry.registry_path Registry.registry_value_name +| `drop_dm_object_name(Registry)` +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` +| `windows_disableantispyware_registry_filter` + +====Associated Analytic Story==== + +* [[Documentation:ESSOC:stories:UseCase#Ryuk_Ransomware|Ryuk Ransomware]] + +* [[Documentation:ESSOC:stories:UseCase#Windows_Defense_Evasion_Tactics|Windows Defense Evasion Tactics]] + + +====How To Implement==== +To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Registry` node. + +====Required field==== + +* _time + +* Registry.registry_key_name + +* Registry.registry_value_name + +* Registry.dest + +* Registry.user + +* Registry.registry_path + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1562.001 +| Disable or Modify Tools +| Defense Evasion +|} + + +====Kill Chain Phase==== + +* Delivery + + +====Known False Positives==== +It is unusual to turn this feature off a Windows system since it is a default security control, although it is not rare for some policies to disable it. Although no false positives have been identified, use the provided filter macro to tune the search. + +====Reference==== + +* https://blog.malwarebytes.com/malwarebytes-news/2021/02/lazyscripter-from-empire-to-double-rat/ + + +====Test Dataset==== + +* https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1562.001/atomic_red_team/windows-sysmon.log + + +''version'': 2 +
+
+ +---- + ===Windows event log cleared=== This search looks for Windows events that indicate one of the Windows event logs has been purged. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1070.001/ T1070.001] * '''Last Updated''': 2020-07-06 @@ -22445,10 +28821,10 @@ This search looks for Windows events that indicate one of the Windows event logs
====Search==== -(`wineventlog_security` (EventCode=1102 OR EventCode=1100)) OR (`wineventlog_system` EventCode=104) -| stats count min(_time) as firstTime max(_time) as lastTime by EventCode dest -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +(`wineventlog_security` (EventCode=1102 OR EventCode=1100)) OR (`wineventlog_system` EventCode=104) +| stats count min(_time) as firstTime max(_time) as lastTime by EventCode dest +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `windows_event_log_cleared_filter` ====Associated Analytic Story==== @@ -22457,12 +28833,20 @@ This search looks for Windows events that indicate one of the Windows event logs * [[Documentation:ESSOC:stories:UseCase#Ransomware|Ransomware]] +* [[Documentation:ESSOC:stories:UseCase#Clop_Ransomware|Clop Ransomware]] + ====How To Implement==== To successfully implement this search, you need to be ingesting Windows event logs from your hosts. ====Required field==== +* _time + +* EventCode + +* dest + ====ATT&CK==== @@ -22505,7 +28889,7 @@ It is possible that these logs may be legitimately cleared by Administrators. The search looks for a Windows Security Account Manager (SAM) was stopped via command-line. This is consistent with Ryuk infections across a fleet of endpoints. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1489/ T1489] * '''Last Updated''': 2020-11-06 @@ -22514,10 +28898,10 @@ The search looks for a Windows Security Account Manager (SAM) was stopped via co ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes WHERE ("Processes.process_name"="net*.exe" "Processes.process"="*stop \"samss\"*") BY "Processes.dest", "Processes.user", "Processes.process" -| `drop_dm_object_name(Processes)` -| `security_content_ctime(lastTime)` -| `security_content_ctime(firstTime)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes WHERE ("Processes.process_name"="net*.exe" "Processes.process"="*stop \"samss\"*") BY "Processes.dest", "Processes.user", "Processes.process" +| `drop_dm_object_name(Processes)` +| `security_content_ctime(lastTime)` +| `security_content_ctime(firstTime)` | `windows_security_account_manager_stopped_filter` ====Associated Analytic Story==== @@ -22530,6 +28914,16 @@ You must be ingesting data that records the process-system activity from your ho ====Required field==== +* _time + +* Processes.process_name + +* Processes.process + +* Processes.dest + +* Processes.user + ====ATT&CK==== @@ -22584,17 +28978,17 @@ This search allows you to identify DNS requests that are unusually large for the ====Search==== -| tstats `security_content_summariesonly` count min(_time) as start_time max(_time) as end_time values(DNS.src) as src values(DNS.dest) as dest from datamodel=Network_Resolution by DNS.query DNS.record_type -| search DNS.record_type=* -| `drop_dm_object_name(DNS)` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| eval query_length = len(query) -| apply dns_query_pdfmodel threshold=0.01 -| rename "IsOutlier(query_length)" as isOutlier -| search isOutlier > 0 -| sort -query_length -| table start_time end_time query record_type count src dest query_length +| tstats `security_content_summariesonly` count min(_time) as start_time max(_time) as end_time values(DNS.src) as src values(DNS.dest) as dest from datamodel=Network_Resolution by DNS.query DNS.record_type +| search DNS.record_type=* +| `drop_dm_object_name(DNS)` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| eval query_length = len(query) +| apply dns_query_pdfmodel threshold=0.01 +| rename "IsOutlier(query_length)" as isOutlier +| search isOutlier > 0 +| sort -query_length +| table start_time end_time query record_type count src dest query_length | `dns_query_length_outliers___mltk_filter` ====Associated Analytic Story==== @@ -22617,6 +29011,16 @@ Detailed documentation on how to create a new field within Incident Review may b ====Required field==== +* _time + +* DNS.src + +* DNS.dest + +* DNS.query + +* DNS.record_type + ====ATT&CK==== @@ -22664,13 +29068,13 @@ This search allows you to identify DNS requests and compute the standard deviati ====Search==== -| tstats `security_content_summariesonly` count from datamodel=Network_Resolution by DNS.query -| `drop_dm_object_name("DNS")` -| eval query_length = len(query) -| table query query_length record_type count +| tstats `security_content_summariesonly` count from datamodel=Network_Resolution by DNS.query +| `drop_dm_object_name("DNS")` +| eval query_length = len(query) +| table query query_length record_type count | eventstats stdev(query_length) AS stdev avg(query_length) AS avg p50(query_length) AS p50 -| where query_length>(avg+stdev*2) -| eval z_score=(query_length-avg)/stdev +| where query_length>(avg+stdev*2) +| eval z_score=(query_length-avg)/stdev | `dns_query_length_with_high_standard_deviation_filter` ====Associated Analytic Story==== @@ -22687,6 +29091,10 @@ To successfully implement this search, you will need to ensure that DNS data is ====Required field==== +* _time + +* DNS.query + ====ATT&CK==== @@ -22717,86 +29125,6 @@ It's possible there can be long domain names that are legitimate. * https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1048.003/long_dns_queries/windows-sysmon.log -''version'': 3 -
-
- ----- - -===Dns record changed=== -The search takes the DNS records and their answers results of the discovered_dns_records lookup and finds if any records have changed by searching DNS response from the Network_Resolution datamodel across the last day. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Network_Resolution -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1071.004/ T1071.004] -* '''Last Updated''': 2020-07-21 - -
-
- -====Search==== - -| inputlookup discovered_dns_records -| rename answer as discovered_answer -| join domain[ -|tstats `security_content_summariesonly` count values(DNS.record_type) as type, values(DNS.answer) as current_answer values(DNS.src) as src from datamodel=Network_Resolution where DNS.message_type=RESPONSE DNS.answer!="unknown" DNS.answer!="" by DNS.query -| rename DNS.query as query -| where query!="unknown" -| rex field=query "(?\w+\.\w+?)(?:$ -|/)"] -| makemv delim=" " answer -| makemv delim=" " type -| sort -count -| table count,src,domain,type,query,current_answer,discovered_answer -| makemv current_answer -| mvexpand current_answer -| makemv discovered_answer -| eval n=mvfind(discovered_answer, current_answer) -| where isnull(n) -| `dns_record_changed_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#DNS_Hijacking|DNS Hijacking]] - - -====How To Implement==== -To successfully implement this search you will need to ensure that DNS data is populating the `Network_Resolution` data model. It also requires that the `discover_dns_record` lookup table be populated by the included support search "Discover DNS record". \ - **Splunk>Phantom Playbook Integration**\ -If Splunk>Phantom is also configured in your environment, a Playbook called "DNS Hijack Enrichment" can be configured to run when any results are found by this detection search. The playbook takes in the DNS record changed and uses Geoip, whois, Censys and PassiveTotal to detect if DNS issuers changed. To use this integration, install the Phantom App for Splunk `https://splunkbase.splunk.com/app/3411/`, add the correct hostname to the "Phantom Instance" field in the Adaptive Response Actions when configuring this detection search, and set the corresponding Playbook to active. \ -(Playbook Link:`https://my.phantom.us/4.2/playbook/dns-hijack-enrichment/`).\ - - -====Required field==== - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1071.004 -| DNS -| Command and Control -|} - - -====Kill Chain Phase==== - -* Command and Control - - -====Known False Positives==== -Legitimate DNS changes can be detected in this search. Investigate, verify and update the list of provided current answers for the domains in question as appropriate. - -====Reference==== - - -====Test Dataset==== - - ''version'': 3
@@ -22807,7 +29135,7 @@ Legitimate DNS changes can be detected in this search. Investigate, verify and u By enabling Dynamic ARP Inspection as a Layer 2 Security measure on the organization's network devices, we will be able to detect ARP Poisoning attacks in the Infrastructure. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1200/ T1200], [https://attack.mitre.org/techniques/T1498/ T1498], [https://attack.mitre.org/techniques/T1557.002/ T1557.002] * '''Last Updated''': 2020-08-11 @@ -22815,9 +29143,9 @@ By enabling Dynamic ARP Inspection as a Layer 2 Security measure on the organiza
====Search==== -`cisco_networks` facility="PM" mnemonic="ERR_DISABLE" disable_cause="arp-inspection" -| eval src_interface=src_int_prefix_long+src_int_suffix -| stats min(_time) AS firstTime max(_time) AS lastTime count BY host src_interface +`cisco_networks` facility="PM" mnemonic="ERR_DISABLE" disable_cause="arp-inspection" +| eval src_interface=src_int_prefix_long+src_int_suffix +| stats min(_time) AS firstTime max(_time) AS lastTime count BY host src_interface | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `detect_arp_poisoning_filter` @@ -22832,6 +29160,22 @@ This search uses a standard SPL query on logs from Cisco Network devices. The ne ====Required field==== +* _time + +* facility + +* mnemonic + +* disable_cause + +* src_int_prefix_long + +* src_int_suffix + +* host + +* src_interface + ====ATT&CK==== @@ -22882,7 +29226,7 @@ This search might be prone to high false positives if DHCP Snooping or ARP inspe By enabling IPv6 First Hop Security as a Layer 2 Security measure on the organization's network devices, we will be able to detect various attacks such as packet forging in the Infrastructure. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1200/ T1200], [https://attack.mitre.org/techniques/T1498/ T1498], [https://attack.mitre.org/techniques/T1557.002/ T1557.002] * '''Last Updated''': 2020-10-28 @@ -22890,13 +29234,13 @@ By enabling IPv6 First Hop Security as a Layer 2 Security measure on the organiz
====Search==== -`cisco_networks` facility="SISF" mnemonic IN ("IP_THEFT","MAC_THEFT","MAC_AND_IP_THEFT","PAK_DROP") -| eval src_interface=src_int_prefix_long+src_int_suffix -| eval dest_interface=dest_int_prefix_long+dest_int_suffix -| stats min(_time) AS firstTime max(_time) AS lastTime values(src_mac) AS src_mac values(src_vlan) AS src_vlan values(mnemonic) AS mnemonic values(vendor_explanation) AS vendor_explanation values(src_ip) AS src_ip values(dest_ip) AS dest_ip values(dest_interface) AS dest_interface values(action) AS action count BY host src_interface -| table host src_interface dest_interface src_mac src_ip dest_ip src_vlan mnemonic vendor_explanation action count -| `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` +`cisco_networks` facility="SISF" mnemonic IN ("IP_THEFT","MAC_THEFT","MAC_AND_IP_THEFT","PAK_DROP") +| eval src_interface=src_int_prefix_long+src_int_suffix +| eval dest_interface=dest_int_prefix_long+dest_int_suffix +| stats min(_time) AS firstTime max(_time) AS lastTime values(src_mac) AS src_mac values(src_vlan) AS src_vlan values(mnemonic) AS mnemonic values(vendor_explanation) AS vendor_explanation values(src_ip) AS src_ip values(dest_ip) AS dest_ip values(dest_interface) AS dest_interface values(action) AS action count BY host src_interface +| table host src_interface dest_interface src_mac src_ip dest_ip src_vlan mnemonic vendor_explanation action count +| `security_content_ctime(firstTime)` +|`security_content_ctime(lastTime)` | `detect_ipv6_network_infrastructure_threats_filter` ====Associated Analytic Story==== @@ -22909,6 +29253,28 @@ This search uses a standard SPL query on logs from Cisco Network devices. The ne ====Required field==== +* _time + +* facility + +* mnemonic + +* src_int_prefix_long + +* src_int_suffix + +* dest_int_prefix_long + +* dest_int_suffix + +* src_mac + +* src_vlan + +* vendor_explanation + +* action + ====ATT&CK==== @@ -22984,11 +29350,11 @@ This search looks for outbound ICMP packets with a packet size larger than 1,000 ====Search==== -| tstats `security_content_summariesonly` count earliest(_time) as firstTime latest(_time) as lastTime values(All_Traffic.action) values(All_Traffic.bytes) from datamodel=Network_Traffic where All_Traffic.action !=blocked All_Traffic.dest_category !=internal (All_Traffic.protocol=icmp OR All_Traffic.transport=icmp) All_Traffic.bytes > 1000 by All_Traffic.src_ip All_Traffic.dest_ip -| `drop_dm_object_name("All_Traffic")` -| search ( dest_ip!=10.0.0.0/8 AND dest_ip!=172.16.0.0/12 AND dest_ip!=192.168.0.0/16) +| tstats `security_content_summariesonly` count earliest(_time) as firstTime latest(_time) as lastTime values(All_Traffic.action) values(All_Traffic.bytes) from datamodel=Network_Traffic where All_Traffic.action !=blocked All_Traffic.dest_category !=internal (All_Traffic.protocol=icmp OR All_Traffic.transport=icmp) All_Traffic.bytes > 1000 by All_Traffic.src_ip All_Traffic.dest_ip +| `drop_dm_object_name("All_Traffic")` +| search ( dest_ip!=10.0.0.0/8 AND dest_ip!=172.16.0.0/12 AND dest_ip!=192.168.0.0/16) | `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` +|`security_content_ctime(lastTime)` | `detect_large_outbound_icmp_packets_filter` ====Associated Analytic Story==== @@ -23001,6 +29367,22 @@ In order to run this search effectively, we highly recommend that you leverage t ====Required field==== +* _time + +* All_Traffic.action + +* All_Traffic.bytes + +* All_Traffic.dest_category + +* All_Traffic.protocol + +* All_Traffic.transport + +* All_Traffic.src_ip + +* All_Traffic.dest_ip + ====ATT&CK==== @@ -23048,10 +29430,10 @@ This search looks for outbound SMB connections made by hosts within your network ====Search==== -| tstats `security_content_summariesonly` earliest(_time) as start_time latest(_time) as end_time values(All_Traffic.action) as action values(All_Traffic.app) as app values(All_Traffic.dest_ip) as dest_ip values(All_Traffic.dest_port) as dest_port values(sourcetype) as sourcetype count from datamodel=Network_Traffic where ((All_Traffic.dest_port=139 OR All_Traffic.dest_port=445 OR All_Traffic.app="smb") AND NOT (All_Traffic.action="blocked" OR All_Traffic.dest_category="internal" OR All_Traffic.dest_ip=10.0.0.0/8 OR All_Traffic.dest_ip=172.16.0.0/12 OR All_Traffic.dest_ip=192.168.0.0/16 OR All_Traffic.dest_ip=100.64.0.0/10)) by All_Traffic.src_ip -| `drop_dm_object_name("All_Traffic")` -| `security_content_ctime(start_time)` -| `security_content_ctime(end_time)` +| tstats `security_content_summariesonly` earliest(_time) as start_time latest(_time) as end_time values(All_Traffic.action) as action values(All_Traffic.app) as app values(All_Traffic.dest_ip) as dest_ip values(All_Traffic.dest_port) as dest_port values(sourcetype) as sourcetype count from datamodel=Network_Traffic where ((All_Traffic.dest_port=139 OR All_Traffic.dest_port=445 OR All_Traffic.app="smb") AND NOT (All_Traffic.action="blocked" OR All_Traffic.dest_category="internal" OR All_Traffic.dest_ip=10.0.0.0/8 OR All_Traffic.dest_ip=172.16.0.0/12 OR All_Traffic.dest_ip=192.168.0.0/16 OR All_Traffic.dest_ip=100.64.0.0/10)) by All_Traffic.src_ip +| `drop_dm_object_name("All_Traffic")` +| `security_content_ctime(start_time)` +| `security_content_ctime(end_time)` | `detect_outbound_smb_traffic_filter` ====Associated Analytic Story==== @@ -23060,7 +29442,7 @@ This search looks for outbound SMB connections made by hosts within your network * [[Documentation:ESSOC:stories:UseCase#DHS_Report_TA18-074A|DHS Report TA18-074A]] -* [[Documentation:ESSOC:stories:UseCase#Sunburst_Malware|Sunburst Malware]] +* [[Documentation:ESSOC:stories:UseCase#NOBELIUM_Group|NOBELIUM Group]] ====How To Implement==== @@ -23068,6 +29450,22 @@ In order to run this search effectively, we highly recommend that you leverage t ====Required field==== +* _time + +* All_Traffic.action + +* All_Traffic.app + +* All_Traffic.dest_ip + +* All_Traffic.dest_port + +* sourcetype + +* All_Traffic.dest_category + +* All_Traffic.src_ip + ====ATT&CK==== @@ -23108,7 +29506,7 @@ It is likely that the outbound Server Message Block (SMB) traffic is legitimate, By enabling Port Security on a Cisco switch you can restrict input to an interface by limiting and identifying MAC addresses of the workstations that are allowed to access the port. When you assign secure MAC addresses to a secure port, the port does not forward packets with source addresses outside the group of defined addresses. If you limit the number of secure MAC addresses to one and assign a single secure MAC address, the workstation attached to that port is assured the full bandwidth of the port. If a port is configured as a secure port and the maximum number of secure MAC addresses is reached, when the MAC address of a workstation attempting to access the port is different from any of the identified secure MAC addresses, a security violation occurs. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1200/ T1200], [https://attack.mitre.org/techniques/T1498/ T1498], [https://attack.mitre.org/techniques/T1557.002/ T1557.002] * '''Last Updated''': 2020-10-28 @@ -23116,11 +29514,11 @@ By enabling Port Security on a Cisco switch you can restrict input to an interfa
====Search==== -`cisco_networks` (facility="PM" mnemonic="ERR_DISABLE" disable_cause="psecure-violation") OR (facility="PORT_SECURITY" mnemonic="PSECURE_VIOLATION" OR mnemonic="PSECURE_VIOLATION_VLAN") -| eval src_interface=src_int_prefix_long+src_int_suffix -| stats min(_time) AS firstTime max(_time) AS lastTime values(disable_cause) AS disable_cause values(src_mac) AS src_mac values(src_vlan) AS src_vlan values(action) AS action count by host src_interface -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +`cisco_networks` (facility="PM" mnemonic="ERR_DISABLE" disable_cause="psecure-violation") OR (facility="PORT_SECURITY" mnemonic="PSECURE_VIOLATION" OR mnemonic="PSECURE_VIOLATION_VLAN") +| eval src_interface=src_int_prefix_long+src_int_suffix +| stats min(_time) AS firstTime max(_time) AS lastTime values(disable_cause) AS disable_cause values(src_mac) AS src_mac values(src_vlan) AS src_vlan values(action) AS action count by host src_interface +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `detect_port_security_violation_filter` ====Associated Analytic Story==== @@ -23133,6 +29531,28 @@ This search uses a standard SPL query on logs from Cisco Network devices. The ne ====Required field==== +* _time + +* facility + +* mnemonic + +* disable_cause + +* src_int_prefix_long + +* src_int_suffix + +* src_mac + +* src_vlan + +* action + +* host + +* src_interface + ====ATT&CK==== @@ -23185,7 +29605,7 @@ This search might be prone to high false positives if you have malfunctioning de By enabling DHCP Snooping as a Layer 2 Security measure on the organization's network devices, we will be able to detect unauthorized DHCP servers handing out DHCP leases to devices on the network (Man in the Middle attack). * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1200/ T1200], [https://attack.mitre.org/techniques/T1498/ T1498], [https://attack.mitre.org/techniques/T1557/ T1557] * '''Last Updated''': 2020-08-11 @@ -23193,8 +29613,8 @@ By enabling DHCP Snooping as a Layer 2 Security measure on the organization's ne
====Search==== -`cisco_networks` facility="DHCP_SNOOPING" mnemonic="DHCP_SNOOPING_UNTRUSTED_PORT" -| stats min(_time) AS firstTime max(_time) AS lastTime count values(message_type) AS message_type values(src_mac) AS src_mac BY host +`cisco_networks` facility="DHCP_SNOOPING" mnemonic="DHCP_SNOOPING_UNTRUSTED_PORT" +| stats min(_time) AS firstTime max(_time) AS lastTime count values(message_type) AS message_type values(src_mac) AS src_mac BY host | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `detect_rogue_dhcp_server_filter` @@ -23209,6 +29629,18 @@ This search uses a standard SPL query on logs from Cisco Network devices. The ne ====Required field==== +* _time + +* facility + +* mnemonic + +* message_type + +* src_mac + +* host + ====ATT&CK==== @@ -23259,7 +29691,7 @@ This search might be prone to high false positives if DHCP Snooping has been inc This search looks for commands that the SNICat tool uses in the TLS SNI field. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1041/ T1041] * '''Last Updated''': 2020-10-21 @@ -23267,7 +29699,7 @@ This search looks for commands that the SNICat tool uses in the TLS SNI field.
====Search==== -`zeek_ssl` +`zeek_ssl` | rex field=server_name "(?(LIST |LS |SIZE @@ -23278,10 +29710,10 @@ This search looks for commands that the SNICat tool uses in the TLS SNI field. |ALIVE |EXIT |WHERE -|finito)-[A-Za-z0-9]{16}\.)" -| stats count by src_ip dest_ip server_name snicat -| where count>0 -| table src_ip dest_ip server_name snicat +|finito)-[A-Za-z0-9]{16}\.)" +| stats count by src_ip dest_ip server_name snicat +| where count>0 +| table src_ip dest_ip server_name snicat | `detect_snicat_sni_exfiltration_filter` ====Associated Analytic Story==== @@ -23294,6 +29726,14 @@ You must be ingesting Zeek SSL data into Splunk. Zeek data should also be gettin ====Required field==== +* _time + +* server_name + +* src_ip + +* dest_ip + ====ATT&CK==== @@ -23347,10 +29787,10 @@ Adversaries may abuse netbooting to load an unauthorized network device operatin ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Network_Traffic where (All_Traffic.transport=udp AND All_Traffic.dest_port=69) OR (All_Traffic.transport=tcp AND All_Traffic.dest_port=21) OR (All_Traffic.transport=tcp AND All_Traffic.dest_port=22) AND All_Traffic.dest_category!=common_software_repo_destination AND All_Traffic.src_category=network OR All_Traffic.src_category=router OR All_Traffic.src_category=switch by All_Traffic.src All_Traffic.dest All_Traffic.dest_port -| `drop_dm_object_name("All_Traffic")` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Network_Traffic where (All_Traffic.transport=udp AND All_Traffic.dest_port=69) OR (All_Traffic.transport=tcp AND All_Traffic.dest_port=21) OR (All_Traffic.transport=tcp AND All_Traffic.dest_port=22) AND All_Traffic.dest_category!=common_software_repo_destination AND All_Traffic.src_category=network OR All_Traffic.src_category=router OR All_Traffic.src_category=switch by All_Traffic.src All_Traffic.dest All_Traffic.dest_port +| `drop_dm_object_name("All_Traffic")` | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | `detect_software_download_to_network_device_filter` ====Associated Analytic Story==== @@ -23363,6 +29803,20 @@ This search looks for Network Traffic events to TFTP, FTP or SSH/SCP ports from ====Required field==== +* _time + +* All_Traffic.transport + +* All_Traffic.dest_port + +* All_Traffic.dest_category + +* All_Traffic.src_category + +* All_Traffic.src + +* All_Traffic.dest + ====ATT&CK==== @@ -23401,7 +29855,7 @@ This search will also report any legitimate attempts of software downloads to ne Adversaries may leverage traffic mirroring in order to automate data exfiltration over compromised network infrastructure. Traffic mirroring is a native feature for some network devices and used for network analysis and may be configured to duplicate traffic and forward to one or more destinations for analysis by a network analyzer or other monitoring device. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1200/ T1200], [https://attack.mitre.org/techniques/T1498/ T1498], [https://attack.mitre.org/techniques/T1020.001/ T1020.001] * '''Last Updated''': 2020-10-28 @@ -23409,10 +29863,10 @@ Adversaries may leverage traffic mirroring in order to automate data exfiltratio
====Search==== -`cisco_networks` (facility="MIRROR" mnemonic="ETH_SPAN_SESSION_UP") OR (facility="SPAN" mnemonic="SESSION_UP") OR (facility="SPAN" mnemonic="PKTCAP_START") OR (mnemonic="CFGLOG_LOGGEDCMD" command="monitor session*") -| stats min(_time) AS firstTime max(_time) AS lastTime count BY host facility mnemonic +`cisco_networks` (facility="MIRROR" mnemonic="ETH_SPAN_SESSION_UP") OR (facility="SPAN" mnemonic="SESSION_UP") OR (facility="SPAN" mnemonic="PKTCAP_START") OR (mnemonic="CFGLOG_LOGGEDCMD" command="monitor session*") +| stats min(_time) AS firstTime max(_time) AS lastTime count BY host facility mnemonic | `security_content_ctime(firstTime)` -|`security_content_ctime(lastTime)` +|`security_content_ctime(lastTime)` | `detect_traffic_mirroring_filter` ====Associated Analytic Story==== @@ -23425,6 +29879,14 @@ This search uses a standard SPL query on logs from Cisco Network devices. The ne ====Required field==== +* _time + +* facility + +* mnemonic + +* host + ====ATT&CK==== @@ -23474,7 +29936,7 @@ By populating the organization's assets within the assets_by_str.csv, we will be * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Network_Sessions -* '''ATT&CK''': +* '''ATT&CK''': * '''Last Updated''': 2017-09-13
@@ -23482,14 +29944,14 @@ By populating the organization's assets within the assets_by_str.csv, we will be ====Search==== -| tstats `security_content_summariesonly` count from datamodel=Network_Sessions where nodename=All_Sessions.DHCP All_Sessions.signature=DHCPREQUEST by All_Sessions.src_ip All_Sessions.dest_mac +| tstats `security_content_summariesonly` count from datamodel=Network_Sessions where nodename=All_Sessions.DHCP All_Sessions.signature=DHCPREQUEST by All_Sessions.src_ip All_Sessions.dest_mac | dedup All_Sessions.dest_mac | `drop_dm_object_name("Network_Sessions")` -|`drop_dm_object_name("All_Sessions")` +|`drop_dm_object_name("All_Sessions")` | search NOT [ -| inputlookup asset_lookup_by_str -|rename mac as dest_mac -| fields + dest_mac] +| inputlookup asset_lookup_by_str +|rename mac as dest_mac +| fields + dest_mac] | `detect_unauthorized_assets_by_mac_address_filter` ====Associated Analytic Story==== @@ -23502,6 +29964,14 @@ This search uses the Network_Sessions data model shipped with Enterprise Securit ====Required field==== +* _time + +* All_Sessions.signature + +* All_Sessions.src_ip + +* All_Sessions.dest_mac + @@ -23533,7 +30003,7 @@ This search might be prone to high false positives. Please consider this when co This search detects SIGRed via Splunk Stream. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1203/ T1203] * '''Last Updated''': 2020-07-28 @@ -23541,15 +30011,15 @@ This search detects SIGRed via Splunk Stream.
====Search==== -`stream_dns` -| spath "query_type{}" -| search "query_type{}" IN (SIG,KEY) -| spath protocol_stack -| search protocol_stack="ip:tcp:dns" -| append [search `stream_tcp` bytes_out>65000] -| `detect_windows_dns_sigred_via_splunk_stream_filter` -| stats count by flow_id -| where count>1 +`stream_dns` +| spath "query_type{}" +| search "query_type{}" IN (SIG,KEY) +| spath protocol_stack +| search protocol_stack="ip:tcp:dns" +| append [search `stream_tcp` bytes_out>65000] +| `detect_windows_dns_sigred_via_splunk_stream_filter` +| stats count by flow_id +| where count>1 | fields - count ====Associated Analytic Story==== @@ -23562,6 +30032,8 @@ You must be ingesting Splunk Stream DNS and Splunk Stream TCP. We are detecting ====Required field==== +* _time + ====ATT&CK==== @@ -23611,14 +30083,14 @@ This search detects SIGRed via Zeek DNS and Zeek Conn data. ====Search==== -| tstats `security_content_summariesonly` count from datamodel=Network_Resolution where DNS.query_type IN (SIG,KEY) by DNS.flow_id -| rename DNS.flow_id as flow_id +| tstats `security_content_summariesonly` count from datamodel=Network_Resolution where DNS.query_type IN (SIG,KEY) by DNS.flow_id +| rename DNS.flow_id as flow_id | append [ -| tstats `security_content_summariesonly` count from datamodel=Network_Traffic where All_Traffic.bytes_in>65000 by All_Traffic.flow_id -| rename All_Traffic.flow_id as flow_id] -| `detect_windows_dns_sigred_via_zeek_filter` -| stats count by flow_id -| where count>1 +| tstats `security_content_summariesonly` count from datamodel=Network_Traffic where All_Traffic.bytes_in>65000 by All_Traffic.flow_id +| rename All_Traffic.flow_id as flow_id] +| `detect_windows_dns_sigred_via_zeek_filter` +| stats count by flow_id +| where count>1 | fields - count ====Associated Analytic Story==== @@ -23631,6 +30103,16 @@ You must be ingesting Zeek DNS and Zeek Conn data into Splunk. Zeek data should ====Required field==== +* _time + +* DNS.query_type + +* DNS.flow_id + +* All_Traffic.bytes_in + +* All_Traffic.flow_id + ====ATT&CK==== @@ -23671,7 +30153,7 @@ unknown This search detects attempts to run exploits for the Zerologon CVE-2020-1472 vulnerability via Zeek RPC * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1190/ T1190] * '''Last Updated''': 2020-09-15 @@ -23679,10 +30161,10 @@ This search detects attempts to run exploits for the Zerologon CVE-2020-1472 vul
====Search==== -`zeek_rpc` operation IN (NetrServerPasswordSet2,NetrServerReqChallenge,NetrServerAuthenticate3) -| bin span=5m _time -| stats values(operation) dc(operation) as opscount count(eval(operation=="NetrServerReqChallenge")) as challenge count(eval(operation=="NetrServerAuthenticate3")) as authcount count(eval(operation=="NetrServerPasswordSet2")) as passcount count as totalcount by _time,src_ip,dest_ip -| search opscount=3 authcount>4 passcount>0 +`zeek_rpc` operation IN (NetrServerPasswordSet2,NetrServerReqChallenge,NetrServerAuthenticate3) +| bin span=5m _time +| stats values(operation) dc(operation) as opscount count(eval(operation=="NetrServerReqChallenge")) as challenge count(eval(operation=="NetrServerAuthenticate3")) as authcount count(eval(operation=="NetrServerPasswordSet2")) as passcount count as totalcount by _time,src_ip,dest_ip +| search opscount=3 authcount>4 passcount>0 | search `detect_zerologon_via_zeek_filter` ====Associated Analytic Story==== @@ -23695,6 +30177,10 @@ You must be ingesting Zeek DCE-RPC data into Splunk. Zeek data should also be ge ====Required field==== +* _time + +* operation + ====ATT&CK==== @@ -23748,10 +30234,10 @@ Malicious actors often abuse legitimate Dynamic DNS services to host malicious p ====Search==== -| tstats `security_content_summariesonly` count values(DNS.answer) as answer min(_time) as firstTime from datamodel=Network_Resolution by DNS.query host -| `drop_dm_object_name("DNS")` -| `security_content_ctime(firstTime)` -| `dynamic_dns_providers` +| tstats `security_content_summariesonly` count values(DNS.answer) as answer min(_time) as firstTime from datamodel=Network_Resolution by DNS.query host +| `drop_dm_object_name("DNS")` +| `security_content_ctime(firstTime)` +| `dynamic_dns_providers` | `detect_hosts_connecting_to_dynamic_domain_providers_filter` ====Associated Analytic Story==== @@ -23780,6 +30266,14 @@ Detailed documentation on how to create a new field within Incident Review may b ====Required field==== +* _time + +* DNS.answer + +* DNS.query + +* host + ====ATT&CK==== @@ -23839,7 +30333,7 @@ This search identifies DNS query failures by counting the number of DNS response | where isnull(rank) | stats sum(count) as count mode(queries) as queries by src | `get_asset(src)` -| where count>50 +| where count>50 | `excessive_dns_failures_filter` ====Associated Analytic Story==== @@ -23854,6 +30348,14 @@ To successfully implement this search you must ensure that DNS data is populatin ====Required field==== +* _time + +* DNS.query + +* DNS.reply_code + +* DNS.src + ====ATT&CK==== @@ -23901,14 +30403,14 @@ This search looks for an increase of data transfers from your email server to yo ====Search==== -| tstats `security_content_summariesonly` sum(All_Traffic.bytes_in) as bytes_in from datamodel=Network_Traffic where All_Traffic.dest_category=email_server by All_Traffic.src_ip _time span=1d -| `drop_dm_object_name("All_Traffic")` -| eventstats avg(bytes_in) as avg_bytes_in stdev(bytes_in) as stdev_bytes_in -| eventstats count as num_data_samples avg(eval(if(_time < relative_time(now(), "@d"), bytes_in, null))) as per_source_avg_bytes_in stdev(eval(if(_time < relative_time(now(), "@d"), bytes_in, null))) as per_source_stdev_bytes_in by src_ip -| eval minimum_data_samples = 4, deviation_threshold = 3 -| where num_data_samples >= minimum_data_samples AND bytes_in > (avg_bytes_in + (deviation_threshold * stdev_bytes_in)) AND bytes_in > (per_source_avg_bytes_in + (deviation_threshold * per_source_stdev_bytes_in)) AND _time >= relative_time(now(), "@d") -| eval num_standard_deviations_away_from_server_average = round(abs(bytes_in - avg_bytes_in) / stdev_bytes_in, 2), num_standard_deviations_away_from_client_average = round(abs(bytes_in - per_source_avg_bytes_in) / per_source_stdev_bytes_in, 2) -| table src_ip, _time, bytes_in, avg_bytes_in, per_source_avg_bytes_in, num_standard_deviations_away_from_server_average, num_standard_deviations_away_from_client_average +| tstats `security_content_summariesonly` sum(All_Traffic.bytes_in) as bytes_in from datamodel=Network_Traffic where All_Traffic.dest_category=email_server by All_Traffic.src_ip _time span=1d +| `drop_dm_object_name("All_Traffic")` +| eventstats avg(bytes_in) as avg_bytes_in stdev(bytes_in) as stdev_bytes_in +| eventstats count as num_data_samples avg(eval(if(_time < relative_time(now(), "@d"), bytes_in, null))) as per_source_avg_bytes_in stdev(eval(if(_time < relative_time(now(), "@d"), bytes_in, null))) as per_source_stdev_bytes_in by src_ip +| eval minimum_data_samples = 4, deviation_threshold = 3 +| where num_data_samples >= minimum_data_samples AND bytes_in > (avg_bytes_in + (deviation_threshold * stdev_bytes_in)) AND bytes_in > (per_source_avg_bytes_in + (deviation_threshold * per_source_stdev_bytes_in)) AND _time >= relative_time(now(), "@d") +| eval num_standard_deviations_away_from_server_average = round(abs(bytes_in - avg_bytes_in) / stdev_bytes_in, 2), num_standard_deviations_away_from_client_average = round(abs(bytes_in - per_source_avg_bytes_in) / per_source_stdev_bytes_in, 2) +| table src_ip, _time, bytes_in, avg_bytes_in, per_source_avg_bytes_in, num_standard_deviations_away_from_server_average, num_standard_deviations_away_from_client_average | `hosts_receiving_high_volume_of_network_traffic_from_email_server_filter` ====Associated Analytic Story==== @@ -23921,6 +30423,14 @@ This search requires you to be ingesting your network traffic and populating the ====Required field==== +* _time + +* All_Traffic.bytes_in + +* All_Traffic.dest_category + +* All_Traffic.src_ip + ====ATT&CK==== @@ -23968,9 +30478,9 @@ The search is used to identify attempts to use your DNS Infrastructure for DDoS ====Search==== -| tstats `security_content_summariesonly` count from datamodel=Network_Resolution where nodename=DNS "DNS.message_type"="QUERY" "DNS.record_type"="ANY" by "DNS.dest" -| `drop_dm_object_name("DNS")` -| where count>200 +| tstats `security_content_summariesonly` count from datamodel=Network_Resolution where nodename=DNS "DNS.message_type"="QUERY" "DNS.record_type"="ANY" by "DNS.dest" +| `drop_dm_object_name("DNS")` +| where count>200 | `large_volume_of_dns_any_queries_filter` ====Associated Analytic Story==== @@ -23983,6 +30493,14 @@ To successfully implement this search you must ensure that DNS data is populatin ====Required field==== +* _time + +* DNS.message_type + +* DNS.record_type + +* DNS.dest + ====ATT&CK==== @@ -24030,12 +30548,12 @@ This search looks for network traffic defined by port and transport layer protoc ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Network_Traffic where All_Traffic.action = allowed by All_Traffic.src_ip All_Traffic.dest_ip All_Traffic.dest_port All_Traffic.action -| lookup update=true interesting_ports_lookup dest_port as All_Traffic.dest_port OUTPUT app is_prohibited note transport -| search is_prohibited=true -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `drop_dm_object_name("All_Traffic")` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Network_Traffic where All_Traffic.action = allowed by All_Traffic.src_ip All_Traffic.dest_ip All_Traffic.dest_port All_Traffic.action +| lookup update=true interesting_ports_lookup dest_port as All_Traffic.dest_port OUTPUT app is_prohibited note transport +| search is_prohibited=true +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `drop_dm_object_name("All_Traffic")` | `prohibited_network_traffic_allowed_filter` ====Associated Analytic Story==== @@ -24052,6 +30570,16 @@ In order to properly run this search, Splunk needs to ingest data from firewalls ====Required field==== +* _time + +* All_Traffic.action + +* All_Traffic.src_ip + +* All_Traffic.dest_ip + +* All_Traffic.dest_port + ====ATT&CK==== @@ -24101,10 +30629,10 @@ This search looks for network traffic on common ports where a higher layer proto ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Network_Traffic where (All_Traffic.app=dns NOT All_Traffic.dest_port=53) OR ((All_Traffic.app=web-browsing OR All_Traffic.app=http) NOT (All_Traffic.dest_port=80 OR All_Traffic.dest_port=8080 OR All_Traffic.dest_port=8000)) OR (All_Traffic.app=ssl NOT (All_Traffic.dest_port=443 OR All_Traffic.dest_port=8443)) OR (All_Traffic.app=smtp NOT All_Traffic.dest_port=25) by All_Traffic.src_ip, All_Traffic.dest_ip, All_Traffic.app, All_Traffic.dest_port -|`security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `drop_dm_object_name("All_Traffic")` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Network_Traffic where (All_Traffic.app=dns NOT All_Traffic.dest_port=53) OR ((All_Traffic.app=web-browsing OR All_Traffic.app=http) NOT (All_Traffic.dest_port=80 OR All_Traffic.dest_port=8080 OR All_Traffic.dest_port=8000)) OR (All_Traffic.app=ssl NOT (All_Traffic.dest_port=443 OR All_Traffic.dest_port=8443)) OR (All_Traffic.app=smtp NOT All_Traffic.dest_port=25) by All_Traffic.src_ip, All_Traffic.dest_ip, All_Traffic.app, All_Traffic.dest_port +|`security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `drop_dm_object_name("All_Traffic")` | `protocol_or_port_mismatch_filter` ====Associated Analytic Story==== @@ -24119,6 +30647,16 @@ Running this search properly requires a technology that can inspect network traf ====Required field==== +* _time + +* All_Traffic.app + +* All_Traffic.dest_port + +* All_Traffic.src_ip + +* All_Traffic.dest_ip + ====ATT&CK==== @@ -24158,7 +30696,7 @@ This search looks for cleartext protocols at risk of leaking credentials. Curren * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Network_Traffic -* '''ATT&CK''': +* '''ATT&CK''': * '''Last Updated''': 2020-11-04
@@ -24166,10 +30704,10 @@ This search looks for cleartext protocols at risk of leaking credentials. Curren ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Network_Traffic where All_Traffic.transport="tcp" AND (All_Traffic.dest_port="23" OR All_Traffic.dest_port="143" OR All_Traffic.dest_port="110" OR (All_Traffic.dest_port="21" AND All_Traffic.user != "anonymous")) by All_Traffic.user All_Traffic.src All_Traffic.dest All_Traffic.dest_port -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `drop_dm_object_name("All_Traffic")` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Network_Traffic where All_Traffic.transport="tcp" AND (All_Traffic.dest_port="23" OR All_Traffic.dest_port="143" OR All_Traffic.dest_port="110" OR (All_Traffic.dest_port="21" AND All_Traffic.user != "anonymous")) by All_Traffic.user All_Traffic.src All_Traffic.dest All_Traffic.dest_port +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `drop_dm_object_name("All_Traffic")` | `protocols_passing_authentication_in_cleartext_filter` ====Associated Analytic Story==== @@ -24182,6 +30720,18 @@ This search requires you to be ingesting your network traffic, and populating th ====Required field==== +* _time + +* All_Traffic.transport + +* All_Traffic.dest_port + +* All_Traffic.user + +* All_Traffic.src + +* All_Traffic.dest + @@ -24220,11 +30770,11 @@ This search looks for RDP application network traffic and filters any source/des ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Network_Traffic where All_Traffic.app=rdp by All_Traffic.src All_Traffic.dest All_Traffic.dest_port -| eventstats stdev(count) AS stdev avg(count) AS avg p50(count) AS p50 -| where count>(avg + stdev*2) -| rename All_Traffic.src AS src All_Traffic.dest AS dest -| table firstTime lastTime src dest count avg p50 stdev +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Network_Traffic where All_Traffic.app=rdp by All_Traffic.src All_Traffic.dest All_Traffic.dest_port +| eventstats stdev(count) AS stdev avg(count) AS avg p50(count) AS p50 +| where count>(avg + stdev*2) +| rename All_Traffic.src AS src All_Traffic.dest AS dest +| table firstTime lastTime src dest count avg p50 stdev | `remote_desktop_network_bruteforce_filter` ====Associated Analytic Story==== @@ -24239,6 +30789,16 @@ You must ensure that your network traffic data is populating the Network_Traffic ====Required field==== +* _time + +* All_Traffic.app + +* All_Traffic.src + +* All_Traffic.dest + +* All_Traffic.dest_port + ====ATT&CK==== @@ -24288,10 +30848,10 @@ This search looks for network traffic on TCP/3389, the default port used by remo ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Network_Traffic where All_Traffic.dest_port=3389 AND All_Traffic.dest_category!=common_rdp_destination AND All_Traffic.src_category!=common_rdp_source by All_Traffic.src All_Traffic.dest All_Traffic.dest_port -| `drop_dm_object_name("All_Traffic")` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Network_Traffic where All_Traffic.dest_port=3389 AND All_Traffic.dest_category!=common_rdp_destination AND All_Traffic.src_category!=common_rdp_source by All_Traffic.src All_Traffic.dest All_Traffic.dest_port +| `drop_dm_object_name("All_Traffic")` | `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| `security_content_ctime(lastTime)` | `remote_desktop_network_traffic_filter` ====Associated Analytic Story==== @@ -24310,6 +30870,20 @@ To successfully implement this search you need to identify systems that commonly ====Required field==== +* _time + +* All_Traffic.dest_port + +* All_Traffic.dest_category + +* All_Traffic.src_category + +* All_Traffic.src + +* All_Traffic.dest + +* All_Traffic.dest_port + ====ATT&CK==== @@ -24357,13 +30931,13 @@ This search looks for spikes in the number of Server Message Block (SMB) traffic ====Search==== -| tstats `security_content_summariesonly` count from datamodel=Network_Traffic where All_Traffic.dest_port=139 OR All_Traffic.dest_port=445 OR All_Traffic.app=smb by _time span=1h, All_Traffic.src -| `drop_dm_object_name("All_Traffic")` -| eventstats max(_time) as maxtime -| stats count as num_data_samples max(eval(if(_time >= relative_time(maxtime, "-70m@m"), count, null))) as count avg(eval(if(_time upperBound AND num_data_samples >=50, 1, 0) -| where isOutlier=1 -| table src count +| tstats `security_content_summariesonly` count from datamodel=Network_Traffic where All_Traffic.dest_port=139 OR All_Traffic.dest_port=445 OR All_Traffic.app=smb by _time span=1h, All_Traffic.src +| `drop_dm_object_name("All_Traffic")` +| eventstats max(_time) as maxtime +| stats count as num_data_samples max(eval(if(_time >= relative_time(maxtime, "-70m@m"), count, null))) as count avg(eval(if(_time upperBound AND num_data_samples >=50, 1, 0) +| where isOutlier=1 +| table src count | `smb_traffic_spike_filter` ====Associated Analytic Story==== @@ -24382,6 +30956,14 @@ This search requires you to be ingesting your network traffic logs and populatin ====Required field==== +* _time + +* All_Traffic.dest_port + +* All_Traffic.app + +* All_Traffic.src + ====ATT&CK==== @@ -24429,15 +31011,15 @@ This search uses the Machine Learning Toolkit (MLTK) to identify spikes in the n ====Search==== -| tstats `security_content_summariesonly` count values(All_Traffic.dest_ip) as dest values(All_Traffic.dest_port) as port from datamodel=Network_Traffic where All_Traffic.dest_port=139 OR All_Traffic.dest_port=445 OR All_Traffic.app=smb by _time span=1h, All_Traffic.src -| eval HourOfDay=strftime(_time, "%H") -| eval DayOfWeek=strftime(_time, "%A") -| `drop_dm_object_name(All_Traffic)` -| apply smb_pdfmodel threshold=0.001 -| rename "IsOutlier(count)" as isOutlier -| search isOutlier > 0 -| sort -count -| table _time src dest port count +| tstats `security_content_summariesonly` count values(All_Traffic.dest_ip) as dest values(All_Traffic.dest_port) as port from datamodel=Network_Traffic where All_Traffic.dest_port=139 OR All_Traffic.dest_port=445 OR All_Traffic.app=smb by _time span=1h, All_Traffic.src +| eval HourOfDay=strftime(_time, "%H") +| eval DayOfWeek=strftime(_time, "%A") +| `drop_dm_object_name(All_Traffic)` +| apply smb_pdfmodel threshold=0.001 +| rename "IsOutlier(count)" as isOutlier +| search isOutlier > 0 +| sort -count +| table _time src dest port count | `smb_traffic_spike___mltk_filter` ====Associated Analytic Story==== @@ -24459,6 +31041,16 @@ Detailed documentation on how to create a new field within Incident Review is fo ====Required field==== +* _time + +* All_Traffic.dest_ip + +* All_Traffic.dest_port + +* All_Traffic.app + +* All_Traffic.src + ====ATT&CK==== @@ -24506,10 +31098,10 @@ This search looks for network traffic identified as The Onion Router (TOR), a be ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Network_Traffic where All_Traffic.app=tor AND All_Traffic.action=allowed by All_Traffic.src_ip All_Traffic.dest_ip All_Traffic.dest_port All_Traffic.action -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| `drop_dm_object_name("All_Traffic")` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Network_Traffic where All_Traffic.app=tor AND All_Traffic.action=allowed by All_Traffic.src_ip All_Traffic.dest_ip All_Traffic.dest_port All_Traffic.action +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| `drop_dm_object_name("All_Traffic")` | `tor_traffic_filter` ====Associated Analytic Story==== @@ -24520,7 +31112,7 @@ This search looks for network traffic identified as The Onion Router (TOR), a be * [[Documentation:ESSOC:stories:UseCase#Command_and_Control|Command and Control]] -* [[Documentation:ESSOC:stories:UseCase#Sunburst_Malware|Sunburst Malware]] +* [[Documentation:ESSOC:stories:UseCase#NOBELIUM_Group|NOBELIUM Group]] ====How To Implement==== @@ -24528,6 +31120,18 @@ In order to properly run this search, Splunk needs to ingest data from firewalls ====Required field==== +* _time + +* All_Traffic.app + +* All_Traffic.action + +* All_Traffic.src_ip + +* All_Traffic.dest_ip + +* All_Traffic.dest_port + ====ATT&CK==== @@ -24566,18 +31170,18 @@ None at this time This search looks for unusually long strings in the Content-Type http header that the client sends the server. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': +* '''Datamodel''': +* '''ATT&CK''': * '''Last Updated''': 2017-10-13
====Search==== -`stream_http` -| eval cs_content_type_length = len(cs_content_type) -| where cs_content_type_length > 100 -| table endtime src_ip dest_ip cs_content_type_length cs_content_type url +`stream_http` +| eval cs_content_type_length = len(cs_content_type) +| where cs_content_type_length > 100 +| table endtime src_ip dest_ip cs_content_type_length cs_content_type url | `unusually_long_content_type_length_filter` ====Associated Analytic Story==== @@ -24590,6 +31194,18 @@ This particular search leverages data extracted from Stream:HTTP. You must confi ====Required field==== +* _time + +* cs_content_type + +* endtime + +* src_ip + +* dest_ip + +* url + @@ -24622,7 +31238,7 @@ Very few legitimate Content-Type fields will have a length greater than 100 char This search detects remote code exploit attempts on F5 BIG-IP, BIG-IQ, and Traffix SDC devices * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': +* '''Datamodel''': * '''ATT&CK''': [https://attack.mitre.org/techniques/T1190/ T1190] * '''Last Updated''': 2020-08-02 @@ -24630,9 +31246,9 @@ This search detects remote code exploit attempts on F5 BIG-IP, BIG-IQ, and Traff
====Search==== -`f5_bigip_rogue` +`f5_bigip_rogue` | regex _raw="(hsqldb; -|.*\\.\\.;.*)" +|.*\\.\\.;.*)" | search `detect_f5_tmui_rce_cve_2020_5902_filter` ====Associated Analytic Story==== @@ -24645,6 +31261,8 @@ To consistently detect exploit attempts on F5 devices using the vulnerabilities ====Required field==== +* _time + ====ATT&CK==== @@ -24698,10 +31316,10 @@ This search looks for specific GET or HEAD requests to web servers that are indi ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Web where (Web.http_method="GET" OR Web.http_method="HEAD") AND (Web.url="*/web-console/ServerInfo.jsp*" OR Web.url="*web-console*" OR Web.url="*jmx-console*" OR Web.url = "*invoker*") by Web.http_method, Web.url, Web.src, Web.dest -| `drop_dm_object_name("Web")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Web where (Web.http_method="GET" OR Web.http_method="HEAD") AND (Web.url="*/web-console/ServerInfo.jsp*" OR Web.url="*web-console*" OR Web.url="*jmx-console*" OR Web.url = "*invoker*") by Web.http_method, Web.url, Web.src, Web.dest +| `drop_dm_object_name("Web")` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` | `detect_attackers_scanning_for_vulnerable_jboss_servers_filter` ====Associated Analytic Story==== @@ -24716,6 +31334,16 @@ You must be ingesting data from the web server or network traffic that contains ====Required field==== +* _time + +* Web.http_method + +* Web.url + +* Web.src + +* Web.dest + ====ATT&CK==== @@ -24755,7 +31383,7 @@ This search is used to detect malicious HTTP requests crafted to exploit jmx-con * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Web -* '''ATT&CK''': +* '''ATT&CK''': * '''Last Updated''': 2017-09-23
@@ -24763,12 +31391,12 @@ This search is used to detect malicious HTTP requests crafted to exploit jmx-con ====Search==== -| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Web where (Web.http_method="GET" OR Web.http_method="HEAD") by Web.http_method, Web.url,Web.url_length Web.src, Web.dest -| search Web.url="*jmx-console/HtmlAdaptor?action=invokeOpByName&name=jboss.admin*import*" AND Web.url_length > 200 -| `drop_dm_object_name("Web")` -| `security_content_ctime(firstTime)` -| `security_content_ctime(lastTime)` -| table src, dest_ip, http_method, url, firstTime, lastTime +| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Web where (Web.http_method="GET" OR Web.http_method="HEAD") by Web.http_method, Web.url,Web.url_length Web.src, Web.dest +| search Web.url="*jmx-console/HtmlAdaptor?action=invokeOpByName&name=jboss.admin*import*" AND Web.url_length > 200 +| `drop_dm_object_name("Web")` +| `security_content_ctime(firstTime)` +| `security_content_ctime(lastTime)` +| table src, dest_ip, http_method, url, firstTime, lastTime | `detect_malicious_requests_to_exploit_jboss_servers_filter` ====Associated Analytic Story==== @@ -24783,6 +31411,18 @@ You must ingest data from the web server or capture network data that contains w ====Required field==== +* _time + +* Web.http_method + +* Web.url + +* Web.url_length + +* Web.src + +* Web.dest + @@ -24811,7 +31451,7 @@ This search looks for Web requests to faux domains similar to the one that you w * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Web -* '''ATT&CK''': +* '''ATT&CK''': * '''Last Updated''': 2017-09-23
@@ -24819,10 +31459,10 @@ This search looks for Web requests to faux domains similar to the one that you w ====Search==== -| tstats `security_content_summariesonly` values(Web.url) as urls min(_time) as firstTime from datamodel=Web by Web.src -| `drop_dm_object_name("Web")` -| `security_content_ctime(firstTime)` -| `brand_abuse_web` +| tstats `security_content_summariesonly` values(Web.url) as urls min(_time) as firstTime from datamodel=Web by Web.src +| `drop_dm_object_name("Web")` +| `security_content_ctime(firstTime)` +| `brand_abuse_web` | `monitor_web_traffic_for_brand_abuse_filter` ====Associated Analytic Story==== @@ -24835,6 +31475,12 @@ You need to ingest data from your web traffic. This can be accomplished by index ====Required field==== +* _time + +* Web.url + +* Web.src + @@ -24871,10 +31517,10 @@ This search looks for long URLs that have several SQL commands visible within th ====Search==== -| tstats `security_content_summariesonly` count from datamodel=Web where Web.dest_category=web_server AND (Web.url_length > 1024 OR Web.http_user_agent_length > 200) by Web.src Web.dest Web.url Web.url_length Web.http_user_agent -| `drop_dm_object_name("Web")` -| eval num_sql_cmds=mvcount(split(url, "alter%20table")) + mvcount(split(url, "between")) + mvcount(split(url, "create%20table")) + mvcount(split(url, "create%20database")) + mvcount(split(url, "create%20index")) + mvcount(split(url, "create%20view")) + mvcount(split(url, "delete")) + mvcount(split(url, "drop%20database")) + mvcount(split(url, "drop%20index")) + mvcount(split(url, "drop%20table")) + mvcount(split(url, "exists")) + mvcount(split(url, "exec")) + mvcount(split(url, "group%20by")) + mvcount(split(url, "having")) + mvcount(split(url, "insert%20into")) + mvcount(split(url, "inner%20join")) + mvcount(split(url, "left%20join")) + mvcount(split(url, "right%20join")) + mvcount(split(url, "full%20join")) + mvcount(split(url, "select")) + mvcount(split(url, "distinct")) + mvcount(split(url, "select%20top")) + mvcount(split(url, "union")) + mvcount(split(url, "xp_cmdshell")) - 24 -| where num_sql_cmds > 3 +| tstats `security_content_summariesonly` count from datamodel=Web where Web.dest_category=web_server AND (Web.url_length > 1024 OR Web.http_user_agent_length > 200) by Web.src Web.dest Web.url Web.url_length Web.http_user_agent +| `drop_dm_object_name("Web")` +| eval num_sql_cmds=mvcount(split(url, "alter%20table")) + mvcount(split(url, "between")) + mvcount(split(url, "create%20table")) + mvcount(split(url, "create%20database")) + mvcount(split(url, "create%20index")) + mvcount(split(url, "create%20view")) + mvcount(split(url, "delete")) + mvcount(split(url, "drop%20database")) + mvcount(split(url, "drop%20index")) + mvcount(split(url, "drop%20table")) + mvcount(split(url, "exists")) + mvcount(split(url, "exec")) + mvcount(split(url, "group%20by")) + mvcount(split(url, "having")) + mvcount(split(url, "insert%20into")) + mvcount(split(url, "inner%20join")) + mvcount(split(url, "left%20join")) + mvcount(split(url, "right%20join")) + mvcount(split(url, "full%20join")) + mvcount(split(url, "select")) + mvcount(split(url, "distinct")) + mvcount(split(url, "select%20top")) + mvcount(split(url, "union")) + mvcount(split(url, "xp_cmdshell")) - 24 +| where num_sql_cmds > 3 | `sql_injection_with_long_urls_filter` ====Associated Analytic Story==== @@ -24887,6 +31533,22 @@ To successfully implement this search, you need to be monitoring network communi ====Required field==== +* _time + +* Web.dest_category + +* Web.url_length + +* Web.http_user_agent_length + +* Web.src + +* Web.dest + +* Web.url + +* Web.http_user_agent + ====ATT&CK==== @@ -24934,12 +31596,12 @@ This search aims to detect the Supernova webshell used in the SUNBURST attack. ====Search==== -| tstats `security_content_summariesonly` count from datamodel=Web.Web where web.url=*logoimagehandler.ashx*codes* OR Web.url=*logoimagehandler.ashx*clazz* OR Web.url=*logoimagehandler.ashx*method* OR Web.url=*logoimagehandler.ashx*args* by Web.src Web.dest Web.url Web.vendor_product Web.user Web.http_user_agent _time span=1s +| tstats `security_content_summariesonly` count from datamodel=Web.Web where web.url=*logoimagehandler.ashx*codes* OR Web.url=*logoimagehandler.ashx*clazz* OR Web.url=*logoimagehandler.ashx*method* OR Web.url=*logoimagehandler.ashx*args* by Web.src Web.dest Web.url Web.vendor_product Web.user Web.http_user_agent _time span=1s | `supernova_webshell_filter` ====Associated Analytic Story==== -* [[Documentation:ESSOC:stories:UseCase#Sunburst_Malware|Sunburst Malware]] +* [[Documentation:ESSOC:stories:UseCase#NOBELIUM_Group|NOBELIUM Group]] ====How To Implement==== @@ -24947,6 +31609,20 @@ To successfully implement this search, you need to be monitoring web traffic to ====Required field==== +* _time + +* Web.url + +* Web.src + +* Web.dest + +* Web.vendor_product + +* Web.user + +* Web.http_user_agent + ====ATT&CK==== @@ -24985,216 +31661,12 @@ There might be false positives associted with this detection since items like ar ---- -===Web fraud - account harvesting=== -This search is used to identify the creation of multiple user accounts using the same email domain name. -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1136/ T1136] -* '''Last Updated''': 2018-10-08 -
-
-====Search==== -`stream_http` http_content_type=text* uri="/magento2/customer/account/loginPost/" -| rex field=cookie "form_key=(?\w+)" -| rex field=form_data "login\[username\]=(?[^& -|^$]+)" -| search Username=* -| rex field=Username "@(?.*)" -| stats dc(Username) as UniqueUsernames list(Username) as src_user by email_domain -| where UniqueUsernames> 25 -| `web_fraud___account_harvesting_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Web_Fraud_Detection|Web Fraud Detection]] - - -====How To Implement==== -We start with a dataset that provides visibility into the email address used for the account creation. In this example, we are narrowing our search down to the single web page that hosts the Magento2 e-commerce platform (via URI) used for account creation, the single http content-type to grab only the user's clicks, and the http field that provides the username (form_data), for performance reasons. After we have the username and email domain, we look for numerous account creations per email domain. Common data sources used for this detection are customized Apache logs or Splunk Stream. - -====Required field==== - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1136 -| Create Account -| Persistence -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -As is common with many fraud-related searches, we are usually looking to attribute risk or synthesize relevant context with loosely written detections that simply detect anamolous behavior. This search will need to be customized to fit your environment—improving its fidelity by counting based on something much more specific, such as a device ID that may be present in your dataset. Consideration for whether the large number of registrations are occuring from a first-time seen domain may also be important. Extending the search window to look further back in time, or even calculating the average per hour/day for each email domain to look for an anomalous spikes, will improve this search. You can also use Shannon entropy or Levenshtein Distance (both courtesy of URL Toolbox) to consider the randomness or similarity of the email name or email domain, as the names are often machine-generated. - -====Reference==== - -* https://splunkbase.splunk.com/app/2734/ - -* https://splunkbase.splunk.com/app/1809/ - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Web fraud - anomalous user clickspeed=== -This search is used to examine web sessions to identify those where the clicks are occurring too quickly for a human or are occurring with a near-perfect cadence (high periodicity or low standard deviation), resembling a script driven session. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078] -* '''Last Updated''': 2018-10-08 - -
-
- -====Search==== -`stream_http` http_content_type=text* -| rex field=cookie "form_key=(?\w+)" -| streamstats window=2 current=1 range(_time) as TimeDelta by session_id -| where TimeDelta>0 -|stats count stdev(TimeDelta) as ClickSpeedStdDev avg(TimeDelta) as ClickSpeedAvg by session_id -| where count>5 AND (ClickSpeedStdDev<.5 OR ClickSpeedAvg<.5) -| `web_fraud___anomalous_user_clickspeed_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Web_Fraud_Detection|Web Fraud Detection]] - - -====How To Implement==== -Start with a dataset that allows you to see clickstream data for each user click on the website. That data must have a time stamp and must contain a reference to the session identifier being used by the website. This ties the clicks together into clickstreams. This value is usually found in the http cookie. With a bit of tuning, a version of this search could be used in high-volume scenarios, such as scraping, crawling, application DDOS, credit-card testing, account takeover, etc. Common data sources used for this detection are customized Apache logs, customized IIS, and Splunk Stream. - -====Required field==== - - - -====ATT&CK==== -{| -! style="text-align:left;"| ID -! Technique -! Tactic -|- -| T1078 -| Valid Accounts -| Defense Evasion, Initial Access, Persistence, Privilege Escalation -|} - - -====Kill Chain Phase==== - -* Actions on Objectives - - -====Known False Positives==== -As is common with many fraud-related searches, we are usually looking to attribute risk or synthesize relevant context with loosly written detections that simply detect anamoluous behavior. - -====Reference==== - -* https://en.wikipedia.org/wiki/Session_ID - -* https://en.wikipedia.org/wiki/Session_(computer_science) - -* https://en.wikipedia.org/wiki/HTTP_cookie - -* https://splunkbase.splunk.com/app/1809/ - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - -===Web fraud - password sharing across accounts=== -This search is used to identify user accounts that share a common password. - -* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': -* '''ATT&CK''': -* '''Last Updated''': 2018-10-08 - -
-
- -====Search==== -`stream_http` http_content_type=text* uri=/magento2/customer/account/loginPost* -| rex field=form_data "login\[username\]=(?[^& -|^$]+)" -| rex field=form_data "login\[password\]=(?[^& -|^$]+)" -| stats dc(Username) as UniqueUsernames values(Username) as user list(src_ip) as src_ip by Password -|where UniqueUsernames>5 -| `web_fraud___password_sharing_across_accounts_filter` - -====Associated Analytic Story==== - -* [[Documentation:ESSOC:stories:UseCase#Web_Fraud_Detection|Web Fraud Detection]] - - -====How To Implement==== -We need to start with a dataset that allows us to see the values of usernames and passwords that users are submitting to the website hosting the Magento2 e-commerce platform (commonly found in the HTTP form_data field). A tokenized or hashed value of a password is acceptable and certainly preferable to a clear-text password. Common data sources used for this detection are customized Apache logs, customized IIS, and Splunk Stream. - -====Required field==== - - - - -====Kill Chain Phase==== - - -====Known False Positives==== -As is common with many fraud-related searches, we are usually looking to attribute risk or synthesize relevant context with loosely written detections that simply detect anamoluous behavior. - -====Reference==== - -* https://en.wikipedia.org/wiki/Session_ID - -* https://en.wikipedia.org/wiki/Session_(computer_science) - -* https://en.wikipedia.org/wiki/HTTP_cookie - -* https://splunkbase.splunk.com/app/1809/ - - -====Test Dataset==== - - -''version'': 1 -
-
- ----- - - - - -'' -############# -# Automatically generated by doc_gen.py in https://github.com/splunk/security_content -# On Date: 2021-03-24 17:37:00.842958 UTC -# Author: Splunk Security Research -# Contact: research@splunk.com -############# -'' +''#############'' +''# Automatically generated by doc_gen.py in https://github.com/splunk/security_content'' +''# On Date: 2021-03-25 19:28:45.949791 UTC'' +''# Author: Splunk Security Research'' +''# Contact: research@splunk.com'' +''#############'' diff --git a/docs/mitre-map/coverage.csv b/docs/mitre-map/coverage.csv index a11b970ceb..b18176359e 100644 --- a/docs/mitre-map/coverage.csv +++ b/docs/mitre-map/coverage.csv @@ -43,17 +43,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -74,10 +74,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -92,7 +93,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -227,7 +229,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -244,9 +246,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -333,7 +335,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -486,7 +489,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -539,9 +542,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -593,30 +599,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -644,10 +650,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -668,12 +676,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -755,9 +764,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -783,7 +793,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -801,7 +811,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -834,21 +845,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -867,9 +880,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -892,7 +906,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -940,17 +955,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -971,10 +986,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -989,7 +1005,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -1124,7 +1141,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -1141,9 +1158,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -1230,7 +1247,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -1383,7 +1401,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -1436,9 +1454,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -1490,30 +1511,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -1541,10 +1562,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -1565,12 +1588,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -1652,9 +1676,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -1680,7 +1705,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -1698,7 +1723,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -1731,21 +1757,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -1764,9 +1792,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -1789,7 +1818,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -1837,17 +1867,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -1868,10 +1898,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -1886,7 +1917,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -2021,7 +2053,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -2038,9 +2070,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -2127,7 +2159,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -2280,7 +2313,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -2333,9 +2366,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -2387,30 +2423,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -2438,10 +2474,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -2462,12 +2500,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -2549,9 +2588,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -2577,7 +2617,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -2595,7 +2635,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -2628,21 +2669,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -2661,9 +2704,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -2686,7 +2730,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -2734,17 +2779,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -2765,10 +2810,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -2783,7 +2829,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -2918,7 +2965,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -2935,9 +2982,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -3024,7 +3071,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -3177,7 +3225,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -3230,9 +3278,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -3284,30 +3335,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -3335,10 +3386,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -3359,12 +3412,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -3446,9 +3500,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -3474,7 +3529,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -3492,7 +3547,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -3525,21 +3581,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -3558,9 +3616,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -3583,7 +3642,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -3631,17 +3691,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -3662,10 +3722,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -3680,7 +3741,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -3815,7 +3877,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -3832,9 +3894,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -3921,7 +3983,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -4074,7 +4137,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -4127,9 +4190,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -4181,30 +4247,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -4232,10 +4298,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -4256,12 +4324,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -4343,9 +4412,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -4371,7 +4441,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -4389,7 +4459,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -4422,21 +4493,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -4455,9 +4528,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -4480,7 +4554,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -4528,17 +4603,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -4559,10 +4634,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -4577,7 +4653,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -4712,7 +4789,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -4729,9 +4806,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -4818,7 +4895,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -4971,7 +5049,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -5024,9 +5102,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -5078,30 +5159,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -5129,10 +5210,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -5153,12 +5236,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -5240,9 +5324,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -5268,7 +5353,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -5286,7 +5371,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -5319,21 +5405,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -5352,9 +5440,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -5377,7 +5466,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -5425,17 +5515,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -5456,10 +5546,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -5474,7 +5565,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -5609,7 +5701,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -5626,9 +5718,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -5715,7 +5807,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -5868,7 +5961,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -5921,9 +6014,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -5975,30 +6071,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -6026,10 +6122,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -6050,12 +6148,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -6137,9 +6236,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -6165,7 +6265,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -6183,7 +6283,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -6216,21 +6317,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -6249,9 +6352,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -6274,7 +6378,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -6322,17 +6427,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -6353,10 +6458,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -6371,7 +6477,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -6506,7 +6613,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -6523,9 +6630,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -6612,7 +6719,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -6765,7 +6873,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -6818,9 +6926,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -6872,30 +6983,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -6923,10 +7034,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -6947,12 +7060,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -7034,9 +7148,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -7062,7 +7177,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -7080,7 +7195,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -7113,21 +7229,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -7146,9 +7264,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -7171,7 +7290,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -7219,17 +7339,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -7250,10 +7370,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -7268,7 +7389,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -7403,7 +7525,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -7420,9 +7542,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -7509,7 +7631,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -7662,7 +7785,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -7715,9 +7838,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -7769,30 +7895,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -7820,10 +7946,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -7844,12 +7972,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -7931,9 +8060,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -7959,7 +8089,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -7977,7 +8107,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -8010,21 +8141,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -8043,9 +8176,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -8068,7 +8202,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -8116,17 +8251,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -8147,10 +8282,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -8165,7 +8301,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -8300,7 +8437,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -8317,9 +8454,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -8406,7 +8543,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -8559,7 +8697,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -8612,9 +8750,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -8666,30 +8807,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -8717,10 +8858,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -8741,12 +8884,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -8828,9 +8972,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -8856,7 +9001,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -8874,7 +9019,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -8907,21 +9053,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -8940,9 +9088,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -8965,7 +9114,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -9013,17 +9163,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -9044,10 +9194,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -9062,7 +9213,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -9197,7 +9349,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -9214,9 +9366,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -9303,7 +9455,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -9456,7 +9609,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -9509,9 +9662,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -9563,30 +9719,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -9614,10 +9770,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -9638,12 +9796,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -9725,9 +9884,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -9753,7 +9913,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -9771,7 +9931,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -9804,21 +9965,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -9837,9 +10000,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -9862,7 +10026,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -9910,17 +10075,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -9941,10 +10106,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -9959,7 +10125,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -10094,7 +10261,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -10111,9 +10278,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -10200,7 +10367,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -10353,7 +10521,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -10406,9 +10574,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -10460,30 +10631,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -10511,10 +10682,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -10535,12 +10708,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -10622,9 +10796,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -10650,7 +10825,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -10668,7 +10843,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -10701,21 +10877,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -10734,9 +10912,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -10759,7 +10938,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -10807,17 +10987,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -10838,10 +11018,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -10856,7 +11037,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -10991,7 +11173,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -11008,9 +11190,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -11097,7 +11279,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -11250,7 +11433,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -11303,9 +11486,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -11357,30 +11543,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -11408,10 +11594,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -11432,12 +11620,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -11519,9 +11708,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -11547,7 +11737,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -11565,7 +11755,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -11598,21 +11789,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -11631,9 +11824,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -11656,7 +11850,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -11704,17 +11899,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -11735,10 +11930,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -11753,7 +11949,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -11888,7 +12085,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -11905,9 +12102,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -11994,7 +12191,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -12147,7 +12345,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -12200,9 +12398,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -12254,30 +12455,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -12305,10 +12506,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -12329,12 +12532,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -12416,9 +12620,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -12444,7 +12649,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -12462,7 +12667,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -12495,21 +12701,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -12528,9 +12736,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -12553,7 +12762,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -12601,17 +12811,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -12632,10 +12842,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -12650,7 +12861,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -12785,7 +12997,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -12802,9 +13014,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -12891,7 +13103,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -13044,7 +13257,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -13097,9 +13310,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -13151,30 +13367,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -13202,10 +13418,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -13226,12 +13444,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -13313,9 +13532,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -13341,7 +13561,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -13359,7 +13579,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -13392,21 +13613,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -13425,9 +13648,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -13450,7 +13674,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -13498,17 +13723,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -13529,10 +13754,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -13547,7 +13773,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -13682,7 +13909,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -13699,9 +13926,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -13788,7 +14015,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -13941,7 +14169,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -13994,9 +14222,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -14048,30 +14279,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -14099,10 +14330,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -14123,12 +14356,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -14210,9 +14444,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -14238,7 +14473,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -14256,7 +14491,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -14289,21 +14525,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -14322,9 +14560,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -14347,7 +14586,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -14395,17 +14635,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -14426,10 +14666,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -14444,7 +14685,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -14579,7 +14821,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -14596,9 +14838,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -14685,7 +14927,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -14838,7 +15081,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -14891,9 +15134,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -14945,30 +15191,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -14996,10 +15242,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -15020,12 +15268,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -15107,9 +15356,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -15135,7 +15385,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -15153,7 +15403,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -15186,21 +15437,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -15219,9 +15472,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -15244,7 +15498,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -15292,17 +15547,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -15323,10 +15578,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -15341,7 +15597,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -15476,7 +15733,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -15493,9 +15750,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -15582,7 +15839,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -15735,7 +15993,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -15788,9 +16046,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -15842,30 +16103,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -15893,10 +16154,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -15917,12 +16180,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -16004,9 +16268,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -16032,7 +16297,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -16050,7 +16315,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -16083,21 +16349,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -16116,9 +16384,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -16141,7 +16410,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -16189,17 +16459,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -16220,10 +16490,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -16238,7 +16509,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -16373,7 +16645,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -16390,9 +16662,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -16479,7 +16751,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -16632,7 +16905,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -16685,9 +16958,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -16739,30 +17015,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -16790,10 +17066,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -16814,12 +17092,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -16901,9 +17180,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -16929,7 +17209,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -16947,7 +17227,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -16980,21 +17261,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -17013,9 +17296,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -17038,7 +17322,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -17086,17 +17371,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -17117,10 +17402,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -17135,7 +17421,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -17270,7 +17557,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -17287,9 +17574,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -17376,7 +17663,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -17529,7 +17817,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -17582,9 +17870,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -17636,30 +17927,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -17687,10 +17978,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -17711,12 +18004,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -17798,9 +18092,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -17826,7 +18121,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -17844,7 +18139,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -17877,21 +18173,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -17910,9 +18208,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -17935,7 +18234,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -17983,17 +18283,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -18014,10 +18314,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -18032,7 +18333,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -18167,7 +18469,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -18184,9 +18486,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -18273,7 +18575,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -18426,7 +18729,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -18479,9 +18782,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -18533,30 +18839,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -18584,10 +18890,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -18608,12 +18916,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -18695,9 +19004,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -18723,7 +19033,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -18741,7 +19051,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -18774,21 +19085,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -18807,9 +19120,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -18832,7 +19146,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -18880,17 +19195,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -18911,10 +19226,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -18929,7 +19245,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -19064,7 +19381,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -19081,9 +19398,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -19170,7 +19487,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -19323,7 +19641,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -19376,9 +19694,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -19430,30 +19751,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -19481,10 +19802,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -19505,12 +19828,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -19592,9 +19916,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -19620,7 +19945,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -19638,7 +19963,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -19671,21 +19997,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -19704,9 +20032,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -19729,7 +20058,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -19777,17 +20107,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -19808,10 +20138,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -19826,7 +20157,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -19961,7 +20293,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -19978,9 +20310,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -20067,7 +20399,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -20220,7 +20553,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -20273,9 +20606,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -20327,30 +20663,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -20378,10 +20714,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -20402,12 +20740,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -20489,9 +20828,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -20517,7 +20857,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -20535,7 +20875,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -20568,21 +20909,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -20601,9 +20944,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -20626,7 +20970,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -20674,17 +21019,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -20705,10 +21050,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -20723,7 +21069,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -20858,7 +21205,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -20875,9 +21222,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -20964,7 +21311,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -21117,7 +21465,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -21170,9 +21518,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -21224,30 +21575,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -21275,10 +21626,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -21299,12 +21652,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -21386,9 +21740,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -21414,7 +21769,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -21432,7 +21787,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -21465,21 +21821,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -21498,9 +21856,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -21523,7 +21882,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -21571,17 +21931,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -21602,10 +21962,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -21620,7 +21981,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -21755,7 +22117,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -21772,9 +22134,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -21861,7 +22223,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -22014,7 +22377,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -22067,9 +22430,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -22121,30 +22487,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -22172,10 +22538,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -22196,12 +22564,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -22283,9 +22652,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -22311,7 +22681,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -22329,7 +22699,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -22362,21 +22733,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -22395,9 +22768,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -22420,7 +22794,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -22468,17 +22843,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -22499,10 +22874,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -22517,7 +22893,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -22652,7 +23029,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -22669,9 +23046,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -22758,7 +23135,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -22911,7 +23289,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -22964,9 +23342,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -23018,30 +23399,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -23069,10 +23450,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -23093,12 +23476,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -23180,9 +23564,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -23208,7 +23593,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -23226,7 +23611,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -23259,21 +23645,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -23292,9 +23680,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -23317,7 +23706,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -23365,17 +23755,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -23396,10 +23786,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -23414,7 +23805,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -23549,7 +23941,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -23566,9 +23958,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -23655,7 +24047,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -23808,7 +24201,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -23861,9 +24254,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -23915,30 +24311,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -23966,10 +24362,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -23990,12 +24388,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -24077,9 +24476,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -24105,7 +24505,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -24123,7 +24523,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -24156,21 +24557,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -24189,9 +24592,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -24214,7 +24618,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -24262,17 +24667,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -24293,10 +24698,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -24311,7 +24717,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -24446,7 +24853,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -24463,9 +24870,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -24552,7 +24959,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -24705,7 +25113,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -24758,9 +25166,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -24812,30 +25223,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -24863,10 +25274,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -24887,12 +25300,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -24974,9 +25388,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -25002,7 +25417,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -25020,7 +25435,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -25053,21 +25469,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -25086,9 +25504,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -25111,7 +25530,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -25159,17 +25579,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -25190,10 +25610,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -25208,7 +25629,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -25343,7 +25765,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -25360,9 +25782,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -25449,7 +25871,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -25602,7 +26025,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -25655,9 +26078,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -25709,30 +26135,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -25760,10 +26186,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -25784,12 +26212,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -25871,9 +26300,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -25899,7 +26329,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -25917,7 +26347,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -25950,21 +26381,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -25983,9 +26416,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -26008,7 +26442,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -26056,17 +26491,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -26087,10 +26522,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -26105,7 +26541,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -26240,7 +26677,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -26257,9 +26694,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -26346,7 +26783,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -26499,7 +26937,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -26552,9 +26990,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -26606,30 +27047,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -26657,10 +27098,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -26681,12 +27124,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -26768,9 +27212,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -26796,7 +27241,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -26814,7 +27259,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -26847,21 +27293,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -26880,9 +27328,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -26905,7 +27354,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -26953,17 +27403,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -26984,10 +27434,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -27002,7 +27453,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -27137,7 +27589,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -27154,9 +27606,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -27243,7 +27695,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -27396,7 +27849,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -27449,9 +27902,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -27503,30 +27959,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -27554,10 +28010,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -27578,12 +28036,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -27665,9 +28124,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -27693,7 +28153,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -27711,7 +28171,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -27744,21 +28205,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -27777,9 +28240,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -27802,7 +28266,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -27850,17 +28315,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -27881,10 +28346,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -27899,7 +28365,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -28034,7 +28501,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -28051,9 +28518,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -28140,7 +28607,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -28293,7 +28761,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -28346,9 +28814,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -28400,30 +28871,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -28451,10 +28922,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -28475,12 +28948,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -28562,9 +29036,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -28590,7 +29065,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -28608,7 +29083,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -28641,21 +29117,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -28674,9 +29152,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -28699,7 +29178,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -28747,17 +29227,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -28778,10 +29258,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -28796,7 +29277,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -28931,7 +29413,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -28948,9 +29430,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -29037,7 +29519,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -29190,7 +29673,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -29243,9 +29726,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -29297,30 +29783,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -29348,10 +29834,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -29372,12 +29860,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -29459,9 +29948,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -29487,7 +29977,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -29505,7 +29995,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -29538,21 +30029,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -29571,9 +30064,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -29596,7 +30090,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -29644,17 +30139,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -29675,10 +30170,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -29693,7 +30189,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -29828,7 +30325,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -29845,9 +30342,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -29934,7 +30431,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -30087,7 +30585,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -30140,9 +30638,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -30194,30 +30695,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -30245,10 +30746,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -30269,12 +30772,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -30356,9 +30860,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -30384,7 +30889,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -30402,7 +30907,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -30435,21 +30941,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -30468,9 +30976,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -30493,7 +31002,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -30541,17 +31051,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -30572,10 +31082,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -30590,7 +31101,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -30725,7 +31237,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -30742,9 +31254,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -30831,7 +31343,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -30984,7 +31497,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -31037,9 +31550,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -31091,30 +31607,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -31142,10 +31658,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -31166,12 +31684,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -31253,9 +31772,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -31281,7 +31801,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -31299,7 +31819,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -31332,21 +31853,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -31365,9 +31888,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -31390,7 +31914,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -31438,17 +31963,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -31469,10 +31994,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -31487,7 +32013,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -31622,7 +32149,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -31639,9 +32166,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -31728,7 +32255,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -31881,7 +32409,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -31934,9 +32462,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -31988,30 +32519,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -32039,10 +32570,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -32063,12 +32596,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -32150,9 +32684,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -32178,7 +32713,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -32196,7 +32731,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -32229,21 +32765,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -32262,9 +32800,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -32287,7 +32826,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -32335,17 +32875,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -32366,10 +32906,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -32384,7 +32925,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -32519,7 +33061,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -32536,9 +33078,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -32625,7 +33167,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -32778,7 +33321,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -32831,9 +33374,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -32885,30 +33431,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -32936,10 +33482,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -32960,12 +33508,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -33047,9 +33596,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -33075,7 +33625,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -33093,7 +33643,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -33126,21 +33677,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -33159,9 +33712,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -33184,7 +33738,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -33232,17 +33787,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -33263,10 +33818,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -33281,7 +33837,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -33416,7 +33973,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -33433,9 +33990,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -33522,7 +34079,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -33675,7 +34233,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -33728,9 +34286,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -33782,30 +34343,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -33833,10 +34394,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -33857,12 +34420,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -33944,9 +34508,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -33972,7 +34537,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -33990,7 +34555,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -34023,21 +34589,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -34056,9 +34624,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -34081,7 +34650,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -34129,17 +34699,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -34160,10 +34730,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -34178,7 +34749,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -34313,7 +34885,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -34330,9 +34902,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -34419,7 +34991,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -34572,7 +35145,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -34625,9 +35198,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -34679,30 +35255,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -34730,10 +35306,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -34754,12 +35332,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -34841,9 +35420,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -34869,7 +35449,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -34887,7 +35467,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -34920,21 +35501,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -34953,9 +35536,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -34978,7 +35562,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -35026,17 +35611,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -35057,10 +35642,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -35075,7 +35661,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -35210,7 +35797,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -35227,9 +35814,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -35316,7 +35903,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -35469,7 +36057,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -35522,9 +36110,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -35576,30 +36167,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -35627,10 +36218,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -35651,12 +36244,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -35738,9 +36332,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -35766,7 +36361,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -35784,7 +36379,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -35817,21 +36413,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -35850,9 +36448,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -35875,7 +36474,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -35923,17 +36523,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -35954,10 +36554,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -35972,7 +36573,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -36107,7 +36709,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -36124,9 +36726,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -36213,7 +36815,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -36366,7 +36969,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -36419,9 +37022,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -36473,30 +37079,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -36524,10 +37130,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -36548,12 +37156,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -36635,9 +37244,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -36663,7 +37273,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -36681,7 +37291,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -36714,21 +37325,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -36747,9 +37360,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -36772,7 +37386,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -36820,17 +37435,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -36851,10 +37466,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -36869,7 +37485,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -37004,7 +37621,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -37021,9 +37638,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -37110,7 +37727,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -37263,7 +37881,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -37316,9 +37934,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -37370,30 +37991,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -37421,10 +38042,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -37445,12 +38068,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -37532,9 +38156,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -37560,7 +38185,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -37578,7 +38203,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -37611,21 +38237,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -37644,9 +38272,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -37669,7 +38298,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -37717,17 +38347,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -37748,10 +38378,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -37766,7 +38397,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -37901,7 +38533,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -37918,9 +38550,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -38007,7 +38639,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -38160,7 +38793,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -38213,9 +38846,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -38267,30 +38903,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -38318,10 +38954,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -38342,12 +38980,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -38429,9 +39068,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -38457,7 +39097,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -38475,7 +39115,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -38508,21 +39149,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -38541,9 +39184,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -38566,7 +39210,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -38614,17 +39259,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -38645,10 +39290,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -38663,7 +39309,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -38798,7 +39445,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -38815,9 +39462,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -38904,7 +39551,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -39057,7 +39705,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -39110,9 +39758,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -39164,30 +39815,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -39215,10 +39866,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -39239,12 +39892,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -39326,9 +39980,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -39354,7 +40009,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -39372,7 +40027,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -39405,21 +40061,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -39438,9 +40096,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -39463,7 +40122,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -39511,17 +40171,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -39542,10 +40202,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -39560,7 +40221,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -39695,7 +40357,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -39712,9 +40374,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -39801,7 +40463,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -39954,7 +40617,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -40007,9 +40670,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -40061,30 +40727,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -40112,10 +40778,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -40136,12 +40804,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -40223,9 +40892,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -40251,7 +40921,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -40269,7 +40939,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -40302,21 +40973,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -40335,9 +41008,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -40360,7 +41034,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -40408,17 +41083,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -40439,10 +41114,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -40457,7 +41133,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -40592,7 +41269,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -40609,9 +41286,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -40698,7 +41375,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -40851,7 +41529,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -40904,9 +41582,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -40958,30 +41639,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -41009,10 +41690,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -41033,12 +41716,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -41120,9 +41804,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -41148,7 +41833,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -41166,7 +41851,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -41199,21 +41885,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -41232,9 +41920,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -41257,7 +41946,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -41305,17 +41995,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -41336,10 +42026,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -41354,7 +42045,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -41489,7 +42181,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -41506,9 +42198,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -41595,7 +42287,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -41748,7 +42441,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -41801,9 +42494,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -41855,30 +42551,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -41906,10 +42602,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -41930,12 +42628,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -42017,9 +42716,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -42045,7 +42745,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -42063,7 +42763,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -42096,21 +42797,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -42129,9 +42832,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -42154,7 +42858,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -42202,17 +42907,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -42233,10 +42938,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -42251,7 +42957,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -42386,7 +43093,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -42403,9 +43110,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -42492,7 +43199,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -42645,7 +43353,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -42698,9 +43406,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -42752,30 +43463,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -42803,10 +43514,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -42827,12 +43540,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -42914,9 +43628,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -42942,7 +43657,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -42960,7 +43675,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -42993,21 +43709,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -43026,9 +43744,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -43051,7 +43770,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -43099,17 +43819,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -43130,10 +43850,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -43148,7 +43869,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -43283,7 +44005,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -43300,9 +44022,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -43389,7 +44111,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -43542,7 +44265,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -43595,9 +44318,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -43649,30 +44375,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -43700,10 +44426,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -43724,12 +44452,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -43811,9 +44540,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -43839,7 +44569,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -43857,7 +44587,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -43890,21 +44621,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -43923,9 +44656,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -43948,7 +44682,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -43996,17 +44731,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -44027,10 +44762,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -44045,7 +44781,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -44180,7 +44917,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -44197,9 +44934,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -44286,7 +45023,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -44439,7 +45177,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -44492,9 +45230,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -44546,30 +45287,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -44597,10 +45338,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -44621,12 +45364,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -44708,9 +45452,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -44736,7 +45481,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -44754,7 +45499,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -44787,21 +45533,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -44820,9 +45568,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -44845,7 +45594,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -44893,17 +45643,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -44924,10 +45674,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -44942,7 +45693,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -45077,7 +45829,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -45094,9 +45846,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -45183,7 +45935,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -45336,7 +46089,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -45389,9 +46142,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -45443,30 +46199,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -45494,10 +46250,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -45518,12 +46276,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -45605,9 +46364,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -45633,7 +46393,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -45651,7 +46411,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -45684,21 +46445,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -45717,9 +46480,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -45742,7 +46506,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -45790,17 +46555,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -45821,10 +46586,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -45839,7 +46605,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -45974,7 +46741,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -45991,9 +46758,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -46080,7 +46847,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -46233,7 +47001,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -46286,9 +47054,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -46340,30 +47111,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -46391,10 +47162,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -46415,12 +47188,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -46502,9 +47276,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -46530,7 +47305,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -46548,7 +47323,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -46581,21 +47357,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -46614,9 +47392,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -46639,7 +47418,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -46687,17 +47467,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -46718,10 +47498,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -46736,7 +47517,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -46871,7 +47653,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -46888,9 +47670,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -46977,7 +47759,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -47130,7 +47913,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -47183,9 +47966,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -47237,30 +48023,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -47288,10 +48074,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -47312,12 +48100,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -47399,9 +48188,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -47427,7 +48217,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -47445,7 +48235,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -47478,21 +48269,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -47511,9 +48304,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -47536,7 +48330,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -47584,17 +48379,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -47615,10 +48410,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -47633,7 +48429,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -47768,7 +48565,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -47785,9 +48582,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -47874,7 +48671,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -48027,7 +48825,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -48080,9 +48878,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -48134,30 +48935,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -48185,10 +48986,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -48209,12 +49012,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -48296,9 +49100,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -48324,7 +49129,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -48342,7 +49147,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -48375,21 +49181,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -48408,9 +49216,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -48433,7 +49242,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -48481,17 +49291,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -48512,10 +49322,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -48530,7 +49341,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -48665,7 +49477,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -48682,9 +49494,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -48771,7 +49583,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -48924,7 +49737,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -48977,9 +49790,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -49031,30 +49847,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -49082,10 +49898,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -49106,12 +49924,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -49193,9 +50012,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -49221,7 +50041,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -49239,7 +50059,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -49272,21 +50093,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -49305,9 +50128,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -49330,7 +50154,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -49378,17 +50203,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -49409,10 +50234,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -49427,7 +50253,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -49562,7 +50389,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -49579,9 +50406,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -49668,7 +50495,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -49821,7 +50649,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -49874,9 +50702,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -49928,30 +50759,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -49979,10 +50810,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -50003,12 +50836,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -50090,9 +50924,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -50118,7 +50953,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -50136,7 +50971,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -50169,21 +51005,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -50202,9 +51040,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -50227,7 +51066,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -50275,17 +51115,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -50306,10 +51146,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -50324,7 +51165,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -50459,7 +51301,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -50476,9 +51318,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -50565,7 +51407,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -50718,7 +51561,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -50771,9 +51614,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -50825,30 +51671,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -50876,10 +51722,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -50900,12 +51748,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -50987,9 +51836,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -51015,7 +51865,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -51033,7 +51883,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -51066,21 +51917,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -51099,9 +51952,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -51124,7 +51978,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -51172,17 +52027,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -51203,10 +52058,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -51221,7 +52077,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -51356,7 +52213,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -51373,9 +52230,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -51462,7 +52319,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -51615,7 +52473,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -51668,9 +52526,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -51722,30 +52583,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -51773,10 +52634,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -51797,12 +52660,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -51884,9 +52748,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -51912,7 +52777,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -51930,7 +52795,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -51963,21 +52829,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -51996,9 +52864,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -52021,7 +52890,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -52069,17 +52939,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -52100,10 +52970,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -52118,7 +52989,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -52253,7 +53125,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -52270,9 +53142,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -52359,7 +53231,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -52512,7 +53385,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -52565,9 +53438,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -52619,30 +53495,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -52670,10 +53546,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -52694,12 +53572,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -52781,9 +53660,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -52809,7 +53689,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -52827,7 +53707,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -52860,21 +53741,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -52893,9 +53776,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -52918,7 +53802,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -52966,17 +53851,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -52997,10 +53882,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -53015,7 +53901,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -53150,7 +54037,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -53167,9 +54054,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -53256,7 +54143,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -53409,7 +54297,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -53462,9 +54350,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -53516,30 +54407,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -53567,10 +54458,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -53591,12 +54484,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -53678,9 +54572,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -53706,7 +54601,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -53724,7 +54619,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -53757,21 +54653,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -53790,9 +54688,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -53815,7 +54714,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -53863,17 +54763,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -53894,10 +54794,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -53912,7 +54813,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -54047,7 +54949,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -54064,9 +54966,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -54153,7 +55055,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -54306,7 +55209,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -54359,9 +55262,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -54413,30 +55319,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -54464,10 +55370,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -54488,12 +55396,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -54575,9 +55484,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -54603,7 +55513,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -54621,7 +55531,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -54654,21 +55565,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -54687,9 +55600,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -54712,7 +55626,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -54760,17 +55675,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -54791,10 +55706,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -54809,7 +55725,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -54944,7 +55861,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -54961,9 +55878,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -55050,7 +55967,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -55203,7 +56121,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -55256,9 +56174,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -55310,30 +56231,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -55361,10 +56282,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -55385,12 +56308,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -55472,9 +56396,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -55500,7 +56425,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -55518,7 +56443,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -55551,21 +56477,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -55584,9 +56512,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -55609,7 +56538,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -55657,17 +56587,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -55688,10 +56618,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -55706,7 +56637,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -55841,7 +56773,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -55858,9 +56790,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -55947,7 +56879,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -56100,7 +57033,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -56153,9 +57086,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -56207,30 +57143,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -56258,10 +57194,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -56282,12 +57220,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -56369,9 +57308,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -56397,7 +57337,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -56415,7 +57355,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -56448,21 +57389,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -56481,9 +57424,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -56506,7 +57450,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -56554,17 +57499,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -56585,10 +57530,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -56603,7 +57549,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -56738,7 +57685,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -56755,9 +57702,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -56844,7 +57791,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -56997,7 +57945,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -57050,9 +57998,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -57104,30 +58055,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -57155,10 +58106,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -57179,12 +58132,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -57266,9 +58220,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -57294,7 +58249,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -57312,7 +58267,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -57345,21 +58301,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -57378,9 +58336,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -57403,7 +58362,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -57451,17 +58411,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -57482,10 +58442,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -57500,7 +58461,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -57635,7 +58597,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -57652,9 +58614,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -57741,7 +58703,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -57894,7 +58857,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -57947,9 +58910,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -58001,30 +58967,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -58052,10 +59018,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -58076,12 +59044,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -58163,9 +59132,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -58191,7 +59161,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -58209,7 +59179,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -58242,21 +59213,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -58275,9 +59248,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -58300,7 +59274,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -58348,17 +59323,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -58379,10 +59354,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -58397,7 +59373,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -58532,7 +59509,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -58549,9 +59526,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -58638,7 +59615,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -58791,7 +59769,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -58844,9 +59822,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -58898,30 +59879,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -58949,10 +59930,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -58973,12 +59956,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -59060,9 +60044,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -59088,7 +60073,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -59106,7 +60091,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -59139,21 +60125,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -59172,9 +60160,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -59197,7 +60186,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -59245,17 +60235,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -59276,10 +60266,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -59294,7 +60285,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -59429,7 +60421,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -59446,9 +60438,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -59535,7 +60527,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -59688,7 +60681,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -59741,9 +60734,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -59795,30 +60791,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -59846,10 +60842,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -59870,12 +60868,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -59957,9 +60956,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -59985,7 +60985,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -60003,7 +61003,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -60036,21 +61037,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -60069,9 +61072,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -60094,7 +61098,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -60142,17 +61147,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -60173,10 +61178,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -60191,7 +61197,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -60326,7 +61333,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -60343,9 +61350,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -60432,7 +61439,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -60585,7 +61593,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -60638,9 +61646,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -60692,30 +61703,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -60743,10 +61754,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -60767,12 +61780,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -60854,9 +61868,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -60882,7 +61897,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -60900,7 +61915,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -60933,21 +61949,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -60966,9 +61984,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -60991,7 +62010,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -61039,17 +62059,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -61070,10 +62090,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -61088,7 +62109,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -61223,7 +62245,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -61240,9 +62262,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -61329,7 +62351,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -61482,7 +62505,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -61535,9 +62558,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -61589,30 +62615,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -61640,10 +62666,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -61664,12 +62692,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -61751,9 +62780,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -61779,7 +62809,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -61797,7 +62827,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -61830,21 +62861,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -61863,9 +62896,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -61888,7 +62922,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -61936,17 +62971,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -61967,10 +63002,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -61985,7 +63021,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -62120,7 +63157,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -62137,9 +63174,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -62226,7 +63263,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -62379,7 +63417,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -62432,9 +63470,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -62486,30 +63527,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -62537,10 +63578,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -62561,12 +63604,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -62648,9 +63692,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -62676,7 +63721,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -62694,7 +63739,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -62727,21 +63773,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -62760,9 +63808,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -62785,7 +63834,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -62833,17 +63883,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -62864,10 +63914,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -62882,7 +63933,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -63017,7 +64069,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -63034,9 +64086,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -63123,7 +64175,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -63276,7 +64329,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -63329,9 +64382,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -63383,30 +64439,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -63434,10 +64490,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -63458,12 +64516,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -63545,9 +64604,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -63573,7 +64633,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -63591,7 +64651,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -63624,21 +64685,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -63657,9 +64720,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -63682,7 +64746,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -63730,17 +64795,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -63761,10 +64826,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -63779,7 +64845,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -63914,7 +64981,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -63931,9 +64998,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -64020,7 +65087,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -64173,7 +65241,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -64226,9 +65294,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -64280,30 +65351,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -64331,10 +65402,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -64355,12 +65428,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -64442,9 +65516,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -64470,7 +65545,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -64488,7 +65563,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -64521,21 +65597,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -64554,9 +65632,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -64579,7 +65658,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -64627,17 +65707,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -64658,10 +65738,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -64676,7 +65757,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -64811,7 +65893,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -64828,9 +65910,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -64917,7 +65999,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -65070,7 +66153,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -65123,9 +66206,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -65177,30 +66263,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -65228,10 +66314,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -65252,12 +66340,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -65339,9 +66428,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -65367,7 +66457,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -65385,7 +66475,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -65418,21 +66509,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -65451,9 +66544,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -65476,7 +66570,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -65524,17 +66619,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -65555,10 +66650,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -65573,7 +66669,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -65708,7 +66805,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -65725,9 +66822,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -65814,7 +66911,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -65967,7 +67065,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -66020,9 +67118,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -66074,30 +67175,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -66125,10 +67226,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -66149,12 +67252,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -66236,9 +67340,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -66264,7 +67369,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -66282,7 +67387,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -66315,21 +67421,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -66348,9 +67456,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -66373,7 +67482,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -66421,17 +67531,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -66452,10 +67562,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -66470,7 +67581,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -66605,7 +67717,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -66622,9 +67734,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -66711,7 +67823,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -66864,7 +67977,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -66917,9 +68030,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -66971,30 +68087,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -67022,10 +68138,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -67046,12 +68164,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -67133,9 +68252,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -67161,7 +68281,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -67179,7 +68299,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -67212,21 +68333,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -67245,9 +68368,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -67270,7 +68394,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -67318,17 +68443,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -67349,10 +68474,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -67367,7 +68493,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -67502,7 +68629,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -67519,9 +68646,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -67608,7 +68735,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -67761,7 +68889,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -67814,9 +68942,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -67868,30 +68999,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -67919,10 +69050,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -67943,12 +69076,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -68030,9 +69164,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -68058,7 +69193,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -68076,7 +69211,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -68109,21 +69245,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -68142,9 +69280,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -68167,7 +69306,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -68215,17 +69355,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -68246,10 +69386,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -68264,7 +69405,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -68399,7 +69541,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -68416,9 +69558,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -68505,7 +69647,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -68658,7 +69801,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -68711,9 +69854,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -68765,30 +69911,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -68816,10 +69962,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -68840,12 +69988,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -68927,9 +70076,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -68955,7 +70105,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -68973,7 +70123,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -69006,21 +70157,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -69039,9 +70192,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -69064,7 +70218,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -69112,17 +70267,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -69143,10 +70298,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -69161,7 +70317,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -69296,7 +70453,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -69313,9 +70470,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -69402,7 +70559,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -69555,7 +70713,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -69608,9 +70766,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -69662,30 +70823,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -69713,10 +70874,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -69737,12 +70900,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -69824,9 +70988,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -69852,7 +71017,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -69870,7 +71035,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -69903,21 +71069,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -69936,9 +71104,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -69961,7 +71130,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -70009,17 +71179,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -70040,10 +71210,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -70058,7 +71229,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -70193,7 +71365,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -70210,9 +71382,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -70299,7 +71471,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -70452,7 +71625,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -70505,9 +71678,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -70559,30 +71735,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -70610,10 +71786,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -70634,12 +71812,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -70721,9 +71900,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -70749,7 +71929,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -70767,7 +71947,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -70800,21 +71981,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -70833,9 +72016,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -70858,7 +72042,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -70906,17 +72091,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -70937,10 +72122,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -70955,7 +72141,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -71090,7 +72277,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -71107,9 +72294,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -71196,7 +72383,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -71349,7 +72537,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -71402,9 +72590,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -71456,30 +72647,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -71507,10 +72698,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -71531,12 +72724,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -71618,9 +72812,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -71646,7 +72841,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -71664,7 +72859,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -71697,21 +72893,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -71730,9 +72928,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -71755,7 +72954,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -71803,17 +73003,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -71834,10 +73034,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -71852,7 +73053,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -71987,7 +73189,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -72004,9 +73206,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -72093,7 +73295,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -72246,7 +73449,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -72299,9 +73502,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -72353,30 +73559,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -72404,10 +73610,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -72428,12 +73636,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -72515,9 +73724,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -72543,7 +73753,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -72561,7 +73771,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -72594,21 +73805,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -72627,9 +73840,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -72652,7 +73866,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -72700,17 +73915,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -72731,10 +73946,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -72749,7 +73965,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -72884,7 +74101,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -72901,9 +74118,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -72990,7 +74207,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -73143,7 +74361,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -73196,9 +74414,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -73250,30 +74471,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -73301,10 +74522,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -73325,12 +74548,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -73412,9 +74636,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -73440,7 +74665,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -73458,7 +74683,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -73491,21 +74717,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -73524,9 +74752,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -73549,7 +74778,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -73597,17 +74827,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -73628,10 +74858,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -73646,7 +74877,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -73781,7 +75013,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -73798,9 +75030,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -73887,7 +75119,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -74040,7 +75273,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -74093,9 +75326,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -74147,30 +75383,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -74198,10 +75434,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -74222,12 +75460,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -74309,9 +75548,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -74337,7 +75577,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -74355,7 +75595,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -74388,21 +75629,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -74421,9 +75664,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -74446,7 +75690,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -74494,17 +75739,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -74525,10 +75770,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -74543,7 +75789,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -74678,7 +75925,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -74695,9 +75942,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -74784,7 +76031,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -74937,7 +76185,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -74990,9 +76238,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -75044,30 +76295,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -75095,10 +76346,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -75119,12 +76372,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -75206,9 +76460,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -75234,7 +76489,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -75252,7 +76507,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -75285,21 +76541,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -75318,9 +76576,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -75343,7 +76602,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -75391,17 +76651,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -75422,10 +76682,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -75440,7 +76701,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -75575,7 +76837,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -75592,9 +76854,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -75681,7 +76943,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -75834,7 +77097,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -75887,9 +77150,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -75941,30 +77207,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -75992,10 +77258,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -76016,12 +77284,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -76103,9 +77372,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -76131,7 +77401,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -76149,7 +77419,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -76182,21 +77453,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -76215,9 +77488,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -76240,7 +77514,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -76288,17 +77563,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -76319,10 +77594,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -76337,7 +77613,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -76472,7 +77749,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -76489,9 +77766,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -76578,7 +77855,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -76731,7 +78009,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -76784,9 +78062,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -76838,30 +78119,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -76889,10 +78170,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -76913,12 +78196,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -77000,9 +78284,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -77028,7 +78313,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -77046,7 +78331,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -77079,21 +78365,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -77112,9 +78400,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -77137,7 +78426,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -77185,17 +78475,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -77216,10 +78506,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -77234,7 +78525,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -77369,7 +78661,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -77386,9 +78678,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -77475,7 +78767,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -77628,7 +78921,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -77681,9 +78974,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -77735,30 +79031,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -77786,10 +79082,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -77810,12 +79108,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -77897,9 +79196,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -77925,7 +79225,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -77943,7 +79243,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -77976,21 +79277,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -78009,9 +79312,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -78034,7 +79338,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -78082,17 +79387,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -78113,10 +79418,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -78131,7 +79437,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -78266,7 +79573,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -78283,9 +79590,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -78372,7 +79679,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -78525,7 +79833,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -78578,9 +79886,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -78632,30 +79943,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -78683,10 +79994,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -78707,12 +80020,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -78794,9 +80108,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -78822,7 +80137,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -78840,7 +80155,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -78873,21 +80189,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -78906,9 +80224,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -78931,7 +80250,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -78979,17 +80299,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -79010,10 +80330,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -79028,7 +80349,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -79163,7 +80485,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -79180,9 +80502,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -79269,7 +80591,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -79422,7 +80745,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -79475,9 +80798,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -79529,30 +80855,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -79580,10 +80906,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -79604,12 +80932,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -79691,9 +81020,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -79719,7 +81049,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -79737,7 +81067,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -79770,21 +81101,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -79803,9 +81136,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -79828,7 +81162,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -79876,17 +81211,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -79907,10 +81242,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -79925,7 +81261,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -80060,7 +81397,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -80077,9 +81414,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -80166,7 +81503,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -80319,7 +81657,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -80372,9 +81710,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -80426,30 +81767,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -80477,10 +81818,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -80501,12 +81844,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -80588,9 +81932,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -80616,7 +81961,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -80634,7 +81979,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -80667,21 +82013,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -80700,9 +82048,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -80725,7 +82074,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -80773,17 +82123,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -80804,10 +82154,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -80822,7 +82173,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -80957,7 +82309,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -80974,9 +82326,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -81063,7 +82415,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -81216,7 +82569,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -81269,9 +82622,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -81323,30 +82679,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -81374,10 +82730,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -81398,12 +82756,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -81485,9 +82844,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -81513,7 +82873,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -81531,7 +82891,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -81564,21 +82925,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -81597,9 +82960,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -81622,7 +82986,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -81670,17 +83035,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -81701,10 +83066,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -81719,7 +83085,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -81854,7 +83221,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -81871,9 +83238,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -81960,7 +83327,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -82113,7 +83481,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -82166,9 +83534,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -82220,30 +83591,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -82271,10 +83642,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -82295,12 +83668,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -82382,9 +83756,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -82410,7 +83785,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -82428,7 +83803,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -82461,21 +83837,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -82494,9 +83872,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -82519,7 +83898,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -82567,17 +83947,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -82598,10 +83978,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -82616,7 +83997,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -82751,7 +84133,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -82768,9 +84150,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -82857,7 +84239,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -83010,7 +84393,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -83063,9 +84446,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -83117,30 +84503,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -83168,10 +84554,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -83192,12 +84580,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -83279,9 +84668,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -83307,7 +84697,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -83325,7 +84715,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -83358,21 +84749,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -83391,9 +84784,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -83416,7 +84810,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -83464,17 +84859,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -83495,10 +84890,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -83513,7 +84909,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -83648,7 +85045,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -83665,9 +85062,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -83754,7 +85151,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -83907,7 +85305,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -83960,9 +85358,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -84014,30 +85415,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -84065,10 +85466,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -84089,12 +85492,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -84176,9 +85580,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -84204,7 +85609,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -84222,7 +85627,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -84255,21 +85661,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -84288,9 +85696,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -84313,7 +85722,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -84361,17 +85771,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -84392,10 +85802,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -84410,7 +85821,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -84545,7 +85957,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -84562,9 +85974,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -84651,7 +86063,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -84804,7 +86217,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -84857,9 +86270,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -84911,30 +86327,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -84962,10 +86378,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -84986,12 +86404,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -85073,9 +86492,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -85101,7 +86521,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -85119,7 +86539,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -85152,21 +86573,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -85185,9 +86608,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -85210,7 +86634,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -85258,17 +86683,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -85289,10 +86714,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -85307,7 +86733,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -85442,7 +86869,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -85459,9 +86886,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -85548,7 +86975,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -85701,7 +87129,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -85754,9 +87182,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -85808,30 +87239,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -85859,10 +87290,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -85883,12 +87316,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -85970,9 +87404,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -85998,7 +87433,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -86016,7 +87451,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -86049,21 +87485,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -86082,9 +87520,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -86107,7 +87546,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -86155,17 +87595,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -86186,10 +87626,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -86204,7 +87645,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -86339,7 +87781,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -86356,9 +87798,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -86445,7 +87887,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -86598,7 +88041,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -86651,9 +88094,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -86705,30 +88151,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -86756,10 +88202,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -86780,12 +88228,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -86867,9 +88316,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -86895,7 +88345,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -86913,7 +88363,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -86946,21 +88397,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -86979,9 +88432,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -87004,7 +88458,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -87052,17 +88507,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -87083,10 +88538,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -87101,7 +88557,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -87236,7 +88693,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -87253,9 +88710,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -87342,7 +88799,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -87495,7 +88953,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -87548,9 +89006,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -87602,30 +89063,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -87653,10 +89114,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -87677,12 +89140,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -87764,9 +89228,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -87792,7 +89257,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -87810,7 +89275,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -87843,21 +89309,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -87876,9 +89344,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -87901,7 +89370,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -87949,17 +89419,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -87980,10 +89450,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -87998,7 +89469,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -88133,7 +89605,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -88150,9 +89622,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -88239,7 +89711,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -88392,7 +89865,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -88445,9 +89918,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -88499,30 +89975,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -88550,10 +90026,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -88574,12 +90052,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -88661,9 +90140,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -88689,7 +90169,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -88707,7 +90187,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -88740,21 +90221,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -88773,9 +90256,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -88798,7 +90282,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -88846,17 +90331,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -88877,10 +90362,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -88895,7 +90381,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -89030,7 +90517,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -89047,9 +90534,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -89136,7 +90623,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -89289,7 +90777,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -89342,9 +90830,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -89396,30 +90887,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -89447,10 +90938,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -89471,12 +90964,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -89558,9 +91052,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -89586,7 +91081,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -89604,7 +91099,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -89637,21 +91133,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -89670,9 +91168,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -89695,7 +91194,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -89743,17 +91243,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -89774,10 +91274,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -89792,7 +91293,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -89927,7 +91429,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -89944,9 +91446,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -90033,7 +91535,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -90186,7 +91689,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -90239,9 +91742,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -90293,30 +91799,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -90344,10 +91850,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -90368,12 +91876,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -90455,9 +91964,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -90483,7 +91993,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -90501,7 +92011,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -90534,21 +92045,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -90567,9 +92080,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -90592,7 +92106,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -90640,17 +92155,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -90671,10 +92186,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -90689,7 +92205,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -90824,7 +92341,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -90841,9 +92358,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -90930,7 +92447,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -91083,7 +92601,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -91136,9 +92654,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -91190,30 +92711,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -91241,10 +92762,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -91265,12 +92788,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -91352,9 +92876,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -91380,7 +92905,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -91398,7 +92923,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -91431,21 +92957,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -91464,9 +92992,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -91489,7 +93018,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -91537,17 +93067,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -91568,10 +93098,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -91586,7 +93117,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -91721,7 +93253,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -91738,9 +93270,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -91827,7 +93359,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -91980,7 +93513,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -92033,9 +93566,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -92087,30 +93623,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -92138,10 +93674,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -92162,12 +93700,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -92249,9 +93788,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -92277,7 +93817,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -92295,7 +93835,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -92328,21 +93869,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -92361,9 +93904,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -92386,7 +93930,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -92434,17 +93979,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -92465,10 +94010,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -92483,7 +94029,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -92618,7 +94165,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -92635,9 +94182,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -92724,7 +94271,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -92877,7 +94425,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -92930,9 +94478,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -92984,30 +94535,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -93035,10 +94586,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -93059,12 +94612,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -93146,9 +94700,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -93174,7 +94729,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -93192,7 +94747,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -93225,21 +94781,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -93258,9 +94816,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -93283,7 +94842,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -93331,17 +94891,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -93362,10 +94922,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -93380,7 +94941,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -93515,7 +95077,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -93532,9 +95094,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -93621,7 +95183,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -93774,7 +95337,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -93827,9 +95390,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -93881,30 +95447,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -93932,10 +95498,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -93956,12 +95524,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -94043,9 +95612,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -94071,7 +95641,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -94089,7 +95659,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -94122,21 +95693,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -94155,9 +95728,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -94180,7 +95754,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -94228,17 +95803,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -94259,10 +95834,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -94277,7 +95853,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -94412,7 +95989,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -94429,9 +96006,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -94518,7 +96095,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -94671,7 +96249,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -94724,9 +96302,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -94778,30 +96359,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -94829,10 +96410,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -94853,12 +96436,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -94940,9 +96524,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -94968,7 +96553,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -94986,7 +96571,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -95019,21 +96605,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -95052,9 +96640,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -95077,7 +96666,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -95125,17 +96715,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -95156,10 +96746,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -95174,7 +96765,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -95309,7 +96901,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -95326,9 +96918,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -95415,7 +97007,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -95568,7 +97161,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -95621,9 +97214,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -95675,30 +97271,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -95726,10 +97322,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -95750,12 +97348,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -95837,9 +97436,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -95865,7 +97465,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -95883,7 +97483,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -95916,21 +97517,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -95949,9 +97552,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -95974,7 +97578,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -96022,17 +97627,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -96053,10 +97658,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -96071,7 +97677,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -96206,7 +97813,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -96223,9 +97830,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -96312,7 +97919,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -96465,7 +98073,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -96518,9 +98126,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -96572,30 +98183,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -96623,10 +98234,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -96647,12 +98260,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -96734,9 +98348,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -96762,7 +98377,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -96780,7 +98395,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -96813,21 +98429,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -96846,9 +98464,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -96871,7 +98490,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -96919,17 +98539,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -96950,10 +98570,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -96968,7 +98589,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -97103,7 +98725,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -97120,9 +98742,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -97209,7 +98831,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -97362,7 +98985,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -97415,9 +99038,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -97469,30 +99095,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -97520,10 +99146,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -97544,12 +99172,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -97631,9 +99260,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -97659,7 +99289,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -97677,7 +99307,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -97710,21 +99341,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -97743,9 +99376,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -97768,7 +99402,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -97816,17 +99451,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -97847,10 +99482,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -97865,7 +99501,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -98000,7 +99637,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -98017,9 +99654,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -98106,7 +99743,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -98259,7 +99897,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -98312,9 +99950,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -98366,30 +100007,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -98417,10 +100058,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -98441,12 +100084,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -98528,9 +100172,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -98556,7 +100201,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -98574,7 +100219,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -98607,21 +100253,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -98640,9 +100288,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -98665,7 +100314,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -98713,17 +100363,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -98744,10 +100394,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -98762,7 +100413,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -98897,7 +100549,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -98914,9 +100566,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -99003,7 +100655,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -99156,7 +100809,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -99209,9 +100862,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -99263,30 +100919,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -99314,10 +100970,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -99338,12 +100996,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -99425,9 +101084,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -99453,7 +101113,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -99471,7 +101131,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -99504,21 +101165,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -99537,9 +101200,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -99562,7 +101226,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -99610,17 +101275,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -99641,10 +101306,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -99659,7 +101325,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -99794,7 +101461,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -99811,9 +101478,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -99900,7 +101567,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -100053,7 +101721,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -100106,9 +101774,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -100160,30 +101831,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -100211,10 +101882,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -100235,12 +101908,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -100322,9 +101996,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -100350,7 +102025,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -100368,7 +102043,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -100401,21 +102077,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -100434,9 +102112,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -100459,7 +102138,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -100507,17 +102187,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -100538,10 +102218,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -100556,7 +102237,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -100691,7 +102373,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -100708,9 +102390,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -100797,7 +102479,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -100950,7 +102633,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -101003,9 +102686,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -101057,30 +102743,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -101108,10 +102794,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -101132,12 +102820,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -101219,9 +102908,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -101247,7 +102937,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -101265,7 +102955,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -101298,21 +102989,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -101331,9 +103024,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -101356,7 +103050,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -101404,17 +103099,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -101435,10 +103130,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -101453,7 +103149,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -101588,7 +103285,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -101605,9 +103302,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -101694,7 +103391,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -101847,7 +103545,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -101900,9 +103598,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -101954,30 +103655,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -102005,10 +103706,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -102029,12 +103732,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -102116,9 +103820,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -102144,7 +103849,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -102162,7 +103867,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -102195,21 +103901,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -102228,9 +103936,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -102253,7 +103962,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -102301,17 +104011,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -102332,10 +104042,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -102350,7 +104061,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -102485,7 +104197,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -102502,9 +104214,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -102591,7 +104303,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -102744,7 +104457,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -102797,9 +104510,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -102851,30 +104567,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -102902,10 +104618,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -102926,12 +104644,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -103013,9 +104732,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -103041,7 +104761,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -103059,7 +104779,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -103092,21 +104813,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -103125,9 +104848,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -103150,7 +104874,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -103198,17 +104923,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -103229,10 +104954,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -103247,7 +104973,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -103382,7 +105109,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -103399,9 +105126,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -103488,7 +105215,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -103641,7 +105369,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -103694,9 +105422,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -103748,30 +105479,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -103799,10 +105530,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -103823,12 +105556,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -103910,9 +105644,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -103938,7 +105673,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -103956,7 +105691,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -103989,21 +105725,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -104022,9 +105760,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -104047,7 +105786,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -104095,17 +105835,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -104126,10 +105866,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -104144,7 +105885,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -104279,7 +106021,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -104296,9 +106038,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -104385,7 +106127,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -104538,7 +106281,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -104591,9 +106334,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -104645,30 +106391,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -104696,10 +106442,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -104720,12 +106468,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -104807,9 +106556,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -104835,7 +106585,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -104853,7 +106603,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -104886,21 +106637,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -104919,9 +106672,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -104944,7 +106698,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -104992,17 +106747,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -105023,10 +106778,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -105041,7 +106797,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -105176,7 +106933,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -105193,9 +106950,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -105282,7 +107039,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -105435,7 +107193,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -105488,9 +107246,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -105542,30 +107303,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -105593,10 +107354,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -105617,12 +107380,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -105704,9 +107468,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -105732,7 +107497,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -105750,7 +107515,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -105783,21 +107549,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -105816,9 +107584,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -105841,7 +107610,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -105889,17 +107659,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -105920,10 +107690,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -105938,7 +107709,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -106073,7 +107845,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -106090,9 +107862,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -106179,7 +107951,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -106332,7 +108105,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -106385,9 +108158,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -106439,30 +108215,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -106490,10 +108266,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -106514,12 +108292,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -106601,9 +108380,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -106629,7 +108409,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -106647,7 +108427,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -106680,21 +108461,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -106713,9 +108496,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -106738,7 +108522,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -106786,17 +108571,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -106817,10 +108602,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -106835,7 +108621,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -106970,7 +108757,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -106987,9 +108774,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -107076,7 +108863,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -107229,7 +109017,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -107282,9 +109070,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -107336,30 +109127,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -107387,10 +109178,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -107411,12 +109204,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -107498,9 +109292,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -107526,7 +109321,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -107544,7 +109339,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -107577,21 +109373,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -107610,9 +109408,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -107635,7 +109434,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -107683,17 +109483,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -107714,10 +109514,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -107732,7 +109533,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -107867,7 +109669,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -107884,9 +109686,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -107973,7 +109775,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -108126,7 +109929,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -108179,9 +109982,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -108233,30 +110039,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -108284,10 +110090,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -108308,12 +110116,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -108395,9 +110204,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -108423,7 +110233,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -108441,7 +110251,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -108474,21 +110285,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -108507,9 +110320,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -108532,7 +110346,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -108580,17 +110395,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -108611,10 +110426,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -108629,7 +110445,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -108764,7 +110581,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -108781,9 +110598,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -108870,7 +110687,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -109023,7 +110841,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -109076,9 +110894,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -109130,30 +110951,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -109181,10 +111002,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -109205,12 +111028,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -109292,9 +111116,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -109320,7 +111145,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -109338,7 +111163,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -109371,21 +111197,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -109404,9 +111232,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -109429,7 +111258,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -109477,17 +111307,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -109508,10 +111338,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -109526,7 +111357,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -109661,7 +111493,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -109678,9 +111510,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -109767,7 +111599,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -109920,7 +111753,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -109973,9 +111806,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -110027,30 +111863,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -110078,10 +111914,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -110102,12 +111940,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -110189,9 +112028,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -110217,7 +112057,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -110235,7 +112075,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -110268,21 +112109,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -110301,9 +112144,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -110326,7 +112170,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -110374,17 +112219,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -110405,10 +112250,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -110423,7 +112269,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -110558,7 +112405,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -110575,9 +112422,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -110664,7 +112511,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -110817,7 +112665,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -110870,9 +112718,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -110924,30 +112775,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -110975,10 +112826,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -110999,12 +112852,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -111086,9 +112940,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -111114,7 +112969,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -111132,7 +112987,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -111165,21 +113021,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -111198,9 +113056,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -111223,7 +113082,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -111271,17 +113131,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -111302,10 +113162,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -111320,7 +113181,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -111455,7 +113317,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -111472,9 +113334,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -111561,7 +113423,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -111714,7 +113577,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -111767,9 +113630,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -111821,30 +113687,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -111872,10 +113738,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -111896,12 +113764,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -111983,9 +113852,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -112011,7 +113881,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -112029,7 +113899,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -112062,21 +113933,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -112095,9 +113968,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -112120,7 +113994,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -112168,17 +114043,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -112199,10 +114074,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -112217,7 +114093,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -112352,7 +114229,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -112369,9 +114246,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -112458,7 +114335,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -112611,7 +114489,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -112664,9 +114542,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -112718,30 +114599,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -112769,10 +114650,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -112793,12 +114676,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -112880,9 +114764,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -112908,7 +114793,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -112926,7 +114811,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -112959,21 +114845,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -112992,9 +114880,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -113017,7 +114906,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -113065,17 +114955,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -113096,10 +114986,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -113114,7 +115005,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -113249,7 +115141,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -113266,9 +115158,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -113355,7 +115247,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -113508,7 +115401,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -113561,9 +115454,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -113615,30 +115511,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -113666,10 +115562,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -113690,12 +115588,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -113777,9 +115676,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -113805,7 +115705,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -113823,7 +115723,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -113856,21 +115757,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -113889,9 +115792,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -113914,7 +115818,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -113962,17 +115867,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -113993,10 +115898,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -114011,7 +115917,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -114146,7 +116053,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -114163,9 +116070,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -114252,7 +116159,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -114405,7 +116313,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -114458,9 +116366,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -114512,30 +116423,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -114563,10 +116474,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -114587,12 +116500,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -114674,9 +116588,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -114702,7 +116617,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -114720,7 +116635,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -114753,21 +116669,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -114786,9 +116704,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -114811,7 +116730,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -114859,17 +116779,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -114890,10 +116810,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -114908,7 +116829,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -115043,7 +116965,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -115060,9 +116982,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -115149,7 +117071,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -115302,7 +117225,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -115355,9 +117278,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -115409,30 +117335,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -115460,10 +117386,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -115484,12 +117412,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -115571,9 +117500,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -115599,7 +117529,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -115617,7 +117547,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -115650,21 +117581,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -115683,9 +117616,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -115708,7 +117642,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -115756,17 +117691,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -115787,10 +117722,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -115805,7 +117741,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -115940,7 +117877,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -115957,9 +117894,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -116046,7 +117983,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -116199,7 +118137,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -116252,9 +118190,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -116306,30 +118247,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -116357,10 +118298,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -116381,12 +118324,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -116468,9 +118412,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -116496,7 +118441,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -116514,7 +118459,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -116547,21 +118493,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -116580,9 +118528,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -116605,7 +118554,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -116653,17 +118603,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -116684,10 +118634,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -116702,7 +118653,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -116837,7 +118789,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -116854,9 +118806,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -116943,7 +118895,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -117096,7 +119049,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -117149,9 +119102,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -117203,30 +119159,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -117254,10 +119210,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -117278,12 +119236,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -117365,9 +119324,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -117393,7 +119353,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -117411,7 +119371,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -117444,21 +119405,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -117477,9 +119440,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -117502,7 +119466,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -117550,17 +119515,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -117581,10 +119546,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -117599,7 +119565,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -117734,7 +119701,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -117751,9 +119718,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -117840,7 +119807,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -117993,7 +119961,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -118046,9 +120014,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -118100,30 +120071,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -118151,10 +120122,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -118175,12 +120148,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -118262,9 +120236,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -118290,7 +120265,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -118308,7 +120283,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -118341,21 +120317,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -118374,9 +120352,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -118399,7 +120378,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -118447,17 +120427,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -118478,10 +120458,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -118496,7 +120477,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -118631,7 +120613,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -118648,9 +120630,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -118737,7 +120719,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -118890,7 +120873,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -118943,9 +120926,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -118997,30 +120983,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -119048,10 +121034,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -119072,12 +121060,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -119159,9 +121148,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -119187,7 +121177,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -119205,7 +121195,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -119238,21 +121229,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -119271,9 +121264,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -119296,7 +121290,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -119344,17 +121339,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -119375,10 +121370,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -119393,7 +121389,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -119528,7 +121525,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -119545,9 +121542,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -119634,7 +121631,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -119787,7 +121785,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -119840,9 +121838,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -119894,30 +121895,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -119945,10 +121946,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -119969,12 +121972,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -120056,9 +122060,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -120084,7 +122089,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -120102,7 +122107,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -120135,21 +122141,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -120168,9 +122176,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -120193,7 +122202,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -120241,17 +122251,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -120272,10 +122282,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -120290,7 +122301,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -120425,7 +122437,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -120442,9 +122454,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -120531,7 +122543,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -120684,7 +122697,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -120737,9 +122750,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -120791,30 +122807,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -120842,10 +122858,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -120866,12 +122884,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -120953,9 +122972,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -120981,7 +123001,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -120999,7 +123019,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -121032,21 +123053,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -121065,9 +123088,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -121090,7 +123114,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -121138,17 +123163,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -121169,10 +123194,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -121187,7 +123213,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -121322,7 +123349,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -121339,9 +123366,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -121428,7 +123455,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -121581,7 +123609,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -121634,9 +123662,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -121688,30 +123719,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -121739,10 +123770,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -121763,12 +123796,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -121850,9 +123884,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -121878,7 +123913,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -121896,7 +123931,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -121929,21 +123965,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -121962,9 +124000,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -121987,7 +124026,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -122035,17 +124075,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -122066,10 +124106,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -122084,7 +124125,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -122219,7 +124261,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -122236,9 +124278,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -122325,7 +124367,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -122478,7 +124521,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -122531,9 +124574,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -122585,30 +124631,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -122636,10 +124682,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -122660,12 +124708,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -122747,9 +124796,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -122775,7 +124825,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -122793,7 +124843,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -122826,21 +124877,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -122859,9 +124912,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -122884,7 +124938,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -122932,17 +124987,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -122963,10 +125018,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -122981,7 +125037,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -123116,7 +125173,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -123133,9 +125190,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -123222,7 +125279,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -123375,7 +125433,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -123428,9 +125486,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -123482,30 +125543,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -123533,10 +125594,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -123557,12 +125620,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -123644,9 +125708,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -123672,7 +125737,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -123690,7 +125755,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -123723,21 +125789,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -123756,9 +125824,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -123781,7 +125850,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -123829,17 +125899,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -123860,10 +125930,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -123878,7 +125949,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -124013,7 +126085,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -124030,9 +126102,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -124119,7 +126191,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -124272,7 +126345,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -124325,9 +126398,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -124379,30 +126455,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -124430,10 +126506,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -124454,12 +126532,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -124541,9 +126620,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -124569,7 +126649,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -124587,7 +126667,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -124620,21 +126701,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -124653,9 +126736,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -124678,7 +126762,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -124726,17 +126811,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -124757,10 +126842,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -124775,7 +126861,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -124910,7 +126997,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -124927,9 +127014,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -125016,7 +127103,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -125169,7 +127257,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -125222,9 +127310,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -125276,30 +127367,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -125327,10 +127418,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -125351,12 +127444,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -125438,9 +127532,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -125466,7 +127561,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -125484,7 +127579,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -125517,21 +127613,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -125550,9 +127648,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -125575,7 +127674,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -125623,17 +127723,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -125654,10 +127754,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -125672,7 +127773,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -125807,7 +127909,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -125824,9 +127926,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -125913,7 +128015,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -126066,7 +128169,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -126119,9 +128222,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -126173,30 +128279,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -126224,10 +128330,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -126248,12 +128356,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -126335,9 +128444,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -126363,7 +128473,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -126381,7 +128491,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -126414,21 +128525,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -126447,9 +128560,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -126472,7 +128586,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -126520,17 +128635,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -126551,10 +128666,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -126569,7 +128685,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -126704,7 +128821,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -126721,9 +128838,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -126810,7 +128927,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -126963,7 +129081,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -127016,9 +129134,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -127070,30 +129191,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -127121,10 +129242,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -127145,12 +129268,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -127232,9 +129356,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -127260,7 +129385,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -127278,7 +129403,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -127311,21 +129437,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -127344,9 +129472,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -127369,7 +129498,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -127417,17 +129547,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -127448,10 +129578,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -127466,7 +129597,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -127601,7 +129733,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -127618,9 +129750,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -127707,7 +129839,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -127860,7 +129993,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -127913,9 +130046,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -127967,30 +130103,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -128018,10 +130154,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -128042,12 +130180,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -128129,9 +130268,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -128157,7 +130297,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -128175,7 +130315,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -128208,21 +130349,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -128241,9 +130384,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -128266,7 +130410,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -128314,17 +130459,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -128345,10 +130490,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -128363,7 +130509,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -128498,7 +130645,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -128515,9 +130662,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -128604,7 +130751,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -128757,7 +130905,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -128810,9 +130958,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -128864,30 +131015,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -128915,10 +131066,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -128939,12 +131092,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -129026,9 +131180,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -129054,7 +131209,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -129072,7 +131227,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -129105,21 +131261,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -129138,9 +131296,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -129163,7 +131322,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -129211,17 +131371,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -129242,10 +131402,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -129260,7 +131421,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -129395,7 +131557,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -129412,9 +131574,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -129501,7 +131663,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -129654,7 +131817,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -129707,9 +131870,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -129761,30 +131927,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -129812,10 +131978,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -129836,12 +132004,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -129923,9 +132092,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -129951,7 +132121,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -129969,7 +132139,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -130002,21 +132173,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -130035,9 +132208,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -130060,7 +132234,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -130108,17 +132283,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -130139,10 +132314,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -130157,7 +132333,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -130292,7 +132469,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -130309,9 +132486,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -130398,7 +132575,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -130551,7 +132729,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -130604,9 +132782,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -130658,30 +132839,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -130709,10 +132890,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -130733,12 +132916,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -130820,9 +133004,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -130848,7 +133033,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -130866,7 +133051,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -130899,21 +133085,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -130932,9 +133120,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -130957,7 +133146,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -131005,17 +133195,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -131036,10 +133226,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -131054,7 +133245,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -131189,7 +133381,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -131206,9 +133398,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -131295,7 +133487,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -131448,7 +133641,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -131501,9 +133694,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -131555,30 +133751,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -131606,10 +133802,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -131630,12 +133828,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -131717,9 +133916,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -131745,7 +133945,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -131763,7 +133963,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -131796,21 +133997,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -131829,9 +134032,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -131854,7 +134058,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -131902,17 +134107,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -131933,10 +134138,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -131951,7 +134157,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -132086,7 +134293,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -132103,9 +134310,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -132192,7 +134399,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -132345,7 +134553,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -132398,9 +134606,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -132452,30 +134663,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -132503,10 +134714,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -132527,12 +134740,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -132614,9 +134828,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -132642,7 +134857,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -132660,7 +134875,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -132693,21 +134909,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -132726,9 +134944,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -132751,7 +134970,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -132799,17 +135019,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -132830,10 +135050,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -132848,7 +135069,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -132983,7 +135205,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -133000,9 +135222,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -133089,7 +135311,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -133242,7 +135465,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -133295,9 +135518,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -133349,30 +135575,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -133400,10 +135626,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -133424,12 +135652,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -133511,9 +135740,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -133539,7 +135769,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -133557,7 +135787,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -133590,21 +135821,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -133623,9 +135856,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -133648,7 +135882,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -133696,17 +135931,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -133727,10 +135962,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -133745,7 +135981,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -133880,7 +136117,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -133897,9 +136134,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -133986,7 +136223,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -134139,7 +136377,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -134192,9 +136430,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -134246,30 +136487,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -134297,10 +136538,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -134321,12 +136564,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -134408,9 +136652,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -134436,7 +136681,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -134454,7 +136699,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -134487,21 +136733,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -134520,9 +136768,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -134545,7 +136794,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -134593,17 +136843,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -134624,10 +136874,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -134642,7 +136893,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -134777,7 +137029,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -134794,9 +137046,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -134883,7 +137135,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -135036,7 +137289,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -135089,9 +137342,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -135143,30 +137399,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -135194,10 +137450,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -135218,12 +137476,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -135305,9 +137564,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -135333,7 +137593,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -135351,7 +137611,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -135384,21 +137645,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -135417,9 +137680,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -135442,7 +137706,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -135490,17 +137755,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -135521,10 +137786,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -135539,7 +137805,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -135674,7 +137941,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -135691,9 +137958,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -135780,7 +138047,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -135933,7 +138201,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -135986,9 +138254,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -136040,30 +138311,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -136091,10 +138362,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -136115,12 +138388,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -136202,9 +138476,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -136230,7 +138505,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -136248,7 +138523,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -136281,21 +138557,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -136314,9 +138592,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -136339,7 +138618,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -136387,17 +138667,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -136418,10 +138698,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -136436,7 +138717,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -136571,7 +138853,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -136588,9 +138870,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -136677,7 +138959,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -136830,7 +139113,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -136883,9 +139166,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -136937,30 +139223,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -136988,10 +139274,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -137012,12 +139300,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -137099,9 +139388,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -137127,7 +139417,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -137145,7 +139435,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -137178,21 +139469,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -137211,9 +139504,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -137236,7 +139530,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -137284,17 +139579,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -137315,10 +139610,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -137333,7 +139629,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -137468,7 +139765,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -137485,9 +139782,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -137574,7 +139871,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -137727,7 +140025,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -137780,9 +140078,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -137834,30 +140135,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -137885,10 +140186,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -137909,12 +140212,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -137996,9 +140300,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -138024,7 +140329,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -138042,7 +140347,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -138075,21 +140381,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -138108,9 +140416,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -138133,7 +140442,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -138181,17 +140491,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -138212,10 +140522,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -138230,7 +140541,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -138365,7 +140677,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -138382,9 +140694,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -138471,7 +140783,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -138624,7 +140937,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -138677,9 +140990,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -138731,30 +141047,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -138782,10 +141098,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -138806,12 +141124,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -138893,9 +141212,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -138921,7 +141241,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -138939,7 +141259,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -138972,21 +141293,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -139005,9 +141328,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -139030,7 +141354,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -139078,17 +141403,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -139109,10 +141434,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -139127,7 +141453,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -139262,7 +141589,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -139279,9 +141606,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -139368,7 +141695,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -139521,7 +141849,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -139574,9 +141902,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -139628,30 +141959,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -139679,10 +142010,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -139703,12 +142036,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -139790,9 +142124,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -139818,7 +142153,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -139836,7 +142171,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -139869,21 +142205,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -139902,9 +142240,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -139927,7 +142266,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -139975,17 +142315,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -140006,10 +142346,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -140024,7 +142365,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -140159,7 +142501,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -140176,9 +142518,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -140265,7 +142607,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -140418,7 +142761,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -140471,9 +142814,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -140525,30 +142871,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -140576,10 +142922,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -140600,12 +142948,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -140687,9 +143036,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -140715,7 +143065,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -140733,7 +143083,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -140766,21 +143117,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -140799,9 +143152,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -140824,7 +143178,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -140872,17 +143227,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -140903,10 +143258,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -140921,7 +143277,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -141056,7 +143413,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -141073,9 +143430,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -141162,7 +143519,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -141315,7 +143673,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -141368,9 +143726,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -141422,30 +143783,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -141473,10 +143834,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -141497,12 +143860,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -141584,9 +143948,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -141612,7 +143977,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -141630,7 +143995,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -141663,21 +144029,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -141696,9 +144064,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -141721,7 +144090,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -141769,17 +144139,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -141800,10 +144170,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -141818,7 +144189,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -141953,7 +144325,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -141970,9 +144342,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -142059,7 +144431,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -142212,7 +144585,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -142265,9 +144638,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -142319,30 +144695,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -142370,10 +144746,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -142394,12 +144772,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -142481,9 +144860,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -142509,7 +144889,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -142527,7 +144907,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -142560,21 +144941,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -142593,9 +144976,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -142618,7 +145002,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -142666,17 +145051,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -142697,10 +145082,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -142715,7 +145101,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -142850,7 +145237,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -142867,9 +145254,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -142956,7 +145343,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -143109,7 +145497,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -143162,9 +145550,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -143216,30 +145607,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -143267,10 +145658,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -143291,12 +145684,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -143378,9 +145772,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -143406,7 +145801,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -143424,7 +145819,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -143457,21 +145853,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -143490,9 +145888,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -143515,7 +145914,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -143563,17 +145963,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -143594,10 +145994,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -143612,7 +146013,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -143747,7 +146149,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -143764,9 +146166,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -143853,7 +146255,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -144006,7 +146409,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -144059,9 +146462,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -144113,30 +146519,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -144164,10 +146570,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -144188,12 +146596,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -144275,9 +146684,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -144303,7 +146713,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -144321,7 +146731,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -144354,21 +146765,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -144387,9 +146800,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -144412,7 +146826,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -144460,17 +146875,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -144491,10 +146906,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -144509,7 +146925,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -144644,7 +147061,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -144661,9 +147078,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -144750,7 +147167,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -144903,7 +147321,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -144956,9 +147374,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -145010,30 +147431,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -145061,10 +147482,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -145085,12 +147508,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -145172,9 +147596,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -145200,7 +147625,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -145218,7 +147643,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -145251,21 +147677,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -145284,9 +147712,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -145309,7 +147738,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -145357,17 +147787,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -145388,10 +147818,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -145406,7 +147837,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -145541,7 +147973,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -145558,9 +147990,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -145647,7 +148079,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -145800,7 +148233,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -145853,9 +148286,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -145907,30 +148343,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -145958,10 +148394,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -145982,12 +148420,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -146069,9 +148508,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -146097,7 +148537,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -146115,7 +148555,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -146148,21 +148589,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -146181,9 +148624,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -146206,7 +148650,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -146254,17 +148699,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -146285,10 +148730,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -146303,7 +148749,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -146438,7 +148885,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -146455,9 +148902,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -146544,7 +148991,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -146697,7 +149145,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -146750,9 +149198,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -146804,30 +149255,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -146855,10 +149306,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -146879,12 +149332,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -146966,9 +149420,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -146994,7 +149449,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -147012,7 +149467,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -147045,21 +149501,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -147078,9 +149536,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -147103,7 +149562,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -147151,17 +149611,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -147182,10 +149642,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -147200,7 +149661,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -147335,7 +149797,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -147352,9 +149814,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -147441,7 +149903,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -147594,7 +150057,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -147647,9 +150110,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -147701,30 +150167,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -147752,10 +150218,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -147776,12 +150244,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -147863,9 +150332,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -147891,7 +150361,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -147909,7 +150379,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -147942,21 +150413,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -147975,9 +150448,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -148000,7 +150474,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -148048,17 +150523,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -148079,10 +150554,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -148097,7 +150573,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -148232,7 +150709,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -148249,9 +150726,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -148338,7 +150815,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -148491,7 +150969,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -148544,9 +151022,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -148598,30 +151079,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -148649,10 +151130,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -148673,12 +151156,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -148760,9 +151244,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -148788,7 +151273,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -148806,7 +151291,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -148839,21 +151325,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -148872,9 +151360,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -148897,7 +151386,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -148945,17 +151435,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -148976,10 +151466,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -148994,7 +151485,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -149129,7 +151621,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -149146,9 +151638,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -149235,7 +151727,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -149388,7 +151881,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -149441,9 +151934,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -149495,30 +151991,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -149546,10 +152042,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -149570,12 +152068,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -149657,9 +152156,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -149685,7 +152185,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -149703,7 +152203,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -149736,21 +152237,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -149769,9 +152272,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -149794,7 +152298,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -149842,17 +152347,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -149873,10 +152378,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -149891,7 +152397,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -150026,7 +152533,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -150043,9 +152550,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -150132,7 +152639,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -150285,7 +152793,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -150338,9 +152846,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -150392,30 +152903,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -150443,10 +152954,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -150467,12 +152980,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -150554,9 +153068,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -150582,7 +153097,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -150600,7 +153115,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -150633,21 +153149,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -150666,9 +153184,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -150691,7 +153210,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -150739,17 +153259,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -150770,10 +153290,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -150788,7 +153309,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -150923,7 +153445,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -150940,9 +153462,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -151029,7 +153551,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -151182,7 +153705,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -151235,9 +153758,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -151289,30 +153815,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -151340,10 +153866,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -151364,12 +153892,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -151451,9 +153980,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -151479,7 +154009,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -151497,7 +154027,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -151530,21 +154061,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -151563,9 +154096,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -151588,7 +154122,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -151636,17 +154171,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -151667,10 +154202,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -151685,7 +154221,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -151820,7 +154357,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -151837,9 +154374,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -151926,7 +154463,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -152079,7 +154617,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -152132,9 +154670,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -152186,30 +154727,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -152237,10 +154778,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -152261,12 +154804,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -152348,9 +154892,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -152376,7 +154921,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -152394,7 +154939,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -152427,21 +154973,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -152460,9 +155008,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -152485,7 +155034,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -152533,17 +155083,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -152564,10 +155114,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -152582,7 +155133,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -152717,7 +155269,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -152734,9 +155286,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -152823,7 +155375,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -152976,7 +155529,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -153029,9 +155582,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -153083,30 +155639,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -153134,10 +155690,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -153158,12 +155716,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -153245,9 +155804,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -153273,7 +155833,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -153291,7 +155851,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -153324,21 +155885,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -153357,9 +155920,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -153382,7 +155946,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -153430,17 +155995,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -153461,10 +156026,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -153479,7 +156045,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -153614,7 +156181,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -153631,9 +156198,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -153720,7 +156287,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -153873,7 +156441,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -153926,9 +156494,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -153980,30 +156551,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -154031,10 +156602,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -154055,12 +156628,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -154142,9 +156716,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -154170,7 +156745,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -154188,7 +156763,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -154221,21 +156797,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -154254,9 +156832,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -154279,7 +156858,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -154327,17 +156907,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -154358,10 +156938,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -154376,7 +156957,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -154511,7 +157093,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -154528,9 +157110,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -154617,7 +157199,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -154770,7 +157353,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -154823,9 +157406,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -154877,30 +157463,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -154928,10 +157514,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -154952,12 +157540,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -155039,9 +157628,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -155067,7 +157657,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -155085,7 +157675,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -155118,21 +157709,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -155151,9 +157744,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -155176,7 +157770,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -155224,17 +157819,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -155255,10 +157850,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -155273,7 +157869,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -155408,7 +158005,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -155425,9 +158022,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -155514,7 +158111,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -155667,7 +158265,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -155720,9 +158318,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -155774,30 +158375,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -155825,10 +158426,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -155849,12 +158452,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -155936,9 +158540,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -155964,7 +158569,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -155982,7 +158587,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -156015,21 +158621,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -156048,9 +158656,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -156073,7 +158682,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -156121,17 +158731,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -156152,10 +158762,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -156170,7 +158781,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -156305,7 +158917,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -156322,9 +158934,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -156411,7 +159023,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -156564,7 +159177,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -156617,9 +159230,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -156671,30 +159287,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -156722,10 +159338,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -156746,12 +159364,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -156833,9 +159452,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -156861,7 +159481,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -156879,7 +159499,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -156912,21 +159533,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -156945,9 +159568,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -156970,7 +159594,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -157018,17 +159643,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -157049,10 +159674,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -157067,7 +159693,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -157202,7 +159829,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -157219,9 +159846,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -157308,7 +159935,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -157461,7 +160089,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -157514,9 +160142,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -157568,30 +160199,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -157619,10 +160250,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -157643,12 +160276,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -157730,9 +160364,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -157758,7 +160393,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -157776,7 +160411,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -157809,21 +160445,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -157842,9 +160480,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -157867,7 +160506,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -157915,17 +160555,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -157946,10 +160586,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -157964,7 +160605,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -158099,7 +160741,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -158116,9 +160758,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -158205,7 +160847,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -158358,7 +161001,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -158411,9 +161054,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -158465,30 +161111,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -158516,10 +161162,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -158540,12 +161188,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -158627,9 +161276,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -158655,7 +161305,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -158673,7 +161323,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -158706,21 +161357,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -158739,9 +161392,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -158764,7 +161418,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -158812,17 +161467,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -158843,10 +161498,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -158861,7 +161517,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -158996,7 +161653,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -159013,9 +161670,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -159102,7 +161759,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -159255,7 +161913,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -159308,9 +161966,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -159362,30 +162023,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -159413,10 +162074,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -159437,12 +162100,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -159524,9 +162188,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -159552,7 +162217,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -159570,7 +162235,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -159603,21 +162269,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -159636,9 +162304,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -159661,7 +162330,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -159709,17 +162379,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -159740,10 +162410,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -159758,7 +162429,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -159893,7 +162565,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -159910,9 +162582,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -159999,7 +162671,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -160152,7 +162825,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -160205,9 +162878,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -160259,30 +162935,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -160310,10 +162986,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -160334,12 +163012,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -160421,9 +163100,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -160449,7 +163129,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -160467,7 +163147,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -160500,21 +163181,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -160533,9 +163216,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -160558,7 +163242,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -160606,17 +163291,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -160637,10 +163322,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -160655,7 +163341,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -160790,7 +163477,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -160807,9 +163494,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -160896,7 +163583,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -161049,7 +163737,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -161102,9 +163790,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -161156,30 +163847,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -161207,10 +163898,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -161231,12 +163924,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -161318,9 +164012,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -161346,7 +164041,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -161364,7 +164059,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -161397,21 +164093,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -161430,9 +164128,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -161455,7 +164154,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -161503,17 +164203,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -161534,10 +164234,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -161552,7 +164253,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -161687,7 +164389,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -161704,9 +164406,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -161793,7 +164495,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -161946,7 +164649,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -161999,9 +164702,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -162053,30 +164759,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -162104,10 +164810,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -162128,12 +164836,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -162215,9 +164924,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -162243,7 +164953,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -162261,7 +164971,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -162294,21 +165005,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -162327,9 +165040,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -162352,7 +165066,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -162400,17 +165115,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -162431,10 +165146,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -162449,7 +165165,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -162584,7 +165301,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -162601,9 +165318,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -162690,7 +165407,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -162843,7 +165561,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -162896,9 +165614,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -162950,30 +165671,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -163001,10 +165722,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -163025,12 +165748,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -163112,9 +165836,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -163140,7 +165865,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -163158,7 +165883,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -163191,21 +165917,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -163224,9 +165952,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -163249,7 +165978,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -163297,17 +166027,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -163328,10 +166058,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -163346,7 +166077,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -163481,7 +166213,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -163498,9 +166230,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -163587,7 +166319,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -163740,7 +166473,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -163793,9 +166526,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -163847,30 +166583,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -163898,10 +166634,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -163922,12 +166660,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -164009,9 +166748,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -164037,7 +166777,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -164055,7 +166795,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -164088,21 +166829,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -164121,9 +166864,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -164146,7 +166890,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -164194,17 +166939,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -164225,10 +166970,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -164243,7 +166989,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -164378,7 +167125,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -164395,9 +167142,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -164484,7 +167231,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -164637,7 +167385,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -164690,9 +167438,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -164744,30 +167495,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -164795,10 +167546,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -164819,12 +167572,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -164906,9 +167660,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -164934,7 +167689,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -164952,7 +167707,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -164985,21 +167741,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -165018,9 +167776,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -165043,7 +167802,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -165091,17 +167851,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -165122,10 +167882,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -165140,7 +167901,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -165275,7 +168037,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -165292,9 +168054,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -165381,7 +168143,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -165534,7 +168297,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -165587,9 +168350,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -165641,30 +168407,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -165692,10 +168458,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -165716,12 +168484,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -165803,9 +168572,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -165831,7 +168601,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -165849,7 +168619,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -165882,21 +168653,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -165915,9 +168688,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -165940,7 +168714,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -165988,17 +168763,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -166019,10 +168794,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -166037,7 +168813,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -166172,7 +168949,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -166189,9 +168966,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -166278,7 +169055,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -166431,7 +169209,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -166484,9 +169262,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -166538,30 +169319,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -166589,10 +169370,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -166613,12 +169396,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -166700,9 +169484,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -166728,7 +169513,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -166746,7 +169531,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -166779,21 +169565,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -166812,9 +169600,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -166837,7 +169626,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -166885,17 +169675,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -166916,10 +169706,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -166934,7 +169725,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -167069,7 +169861,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -167086,9 +169878,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -167175,7 +169967,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -167328,7 +170121,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -167381,9 +170174,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -167435,30 +170231,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -167486,10 +170282,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -167510,12 +170308,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -167597,9 +170396,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -167625,7 +170425,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -167643,7 +170443,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -167676,21 +170477,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -167709,9 +170512,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -167734,7 +170538,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -167782,17 +170587,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -167813,10 +170618,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -167831,7 +170637,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -167966,7 +170773,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -167983,9 +170790,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -168072,7 +170879,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -168225,7 +171033,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -168278,9 +171086,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -168332,30 +171143,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -168383,10 +171194,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -168407,12 +171220,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -168494,9 +171308,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -168522,7 +171337,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -168540,7 +171355,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -168573,21 +171389,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -168606,9 +171424,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -168631,7 +171450,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -168679,17 +171499,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -168710,10 +171530,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -168728,7 +171549,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -168863,7 +171685,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -168880,9 +171702,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -168969,7 +171791,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -169122,7 +171945,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -169175,9 +171998,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -169229,30 +172055,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -169280,10 +172106,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -169304,12 +172132,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -169391,9 +172220,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -169419,7 +172249,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -169437,7 +172267,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -169470,21 +172301,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -169503,9 +172336,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -169528,7 +172362,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -169576,17 +172411,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -169607,10 +172442,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -169625,7 +172461,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -169760,7 +172597,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -169777,9 +172614,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -169866,7 +172703,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -170019,7 +172857,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -170072,9 +172910,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -170126,30 +172967,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -170177,10 +173018,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -170201,12 +173044,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -170288,9 +173132,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -170316,7 +173161,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -170334,7 +173179,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -170367,21 +173213,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -170400,9 +173248,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -170425,7 +173274,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -170473,17 +173323,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -170504,10 +173354,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -170522,7 +173373,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -170657,7 +173509,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -170674,9 +173526,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -170763,7 +173615,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -170916,7 +173769,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -170969,9 +173822,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -171023,30 +173879,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -171074,10 +173930,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -171098,12 +173956,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -171185,9 +174044,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -171213,7 +174073,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -171231,7 +174091,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -171264,21 +174125,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -171297,9 +174160,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -171322,7 +174186,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -171370,17 +174235,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -171401,10 +174266,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -171419,7 +174285,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -171554,7 +174421,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -171571,9 +174438,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -171660,7 +174527,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -171813,7 +174681,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -171866,9 +174734,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -171920,30 +174791,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -171971,10 +174842,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -171995,12 +174868,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -172082,9 +174956,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -172110,7 +174985,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -172128,7 +175003,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -172161,21 +175037,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -172194,9 +175072,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -172219,7 +175098,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -172267,17 +175147,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -172298,10 +175178,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -172316,7 +175197,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -172451,7 +175333,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -172468,9 +175350,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -172557,7 +175439,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -172710,7 +175593,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -172763,9 +175646,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -172817,30 +175703,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -172868,10 +175754,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -172892,12 +175780,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -172979,9 +175868,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -173007,7 +175897,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -173025,7 +175915,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -173058,21 +175949,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -173091,9 +175984,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -173116,7 +176010,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -173164,17 +176059,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -173195,10 +176090,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -173213,7 +176109,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -173348,7 +176245,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -173365,9 +176262,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -173454,7 +176351,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -173607,7 +176505,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -173660,9 +176558,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -173714,30 +176615,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -173765,10 +176666,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -173789,12 +176692,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -173876,9 +176780,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -173904,7 +176809,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -173922,7 +176827,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -173955,21 +176861,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -173988,9 +176896,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -174013,7 +176922,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -174061,17 +176971,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -174092,10 +177002,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -174110,7 +177021,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -174245,7 +177157,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -174262,9 +177174,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -174351,7 +177263,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -174504,7 +177417,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -174557,9 +177470,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -174611,30 +177527,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -174662,10 +177578,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -174686,12 +177604,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -174773,9 +177692,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -174801,7 +177721,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -174819,7 +177739,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -174852,21 +177773,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -174885,9 +177808,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -174910,7 +177834,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -174958,17 +177883,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -174989,10 +177914,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -175007,7 +177933,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -175142,7 +178069,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -175159,9 +178086,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -175248,7 +178175,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -175401,7 +178329,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -175454,9 +178382,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -175508,30 +178439,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -175559,10 +178490,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -175583,12 +178516,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -175670,9 +178604,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -175698,7 +178633,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -175716,7 +178651,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -175749,21 +178685,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -175782,9 +178720,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -175807,7 +178746,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -175855,17 +178795,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -175886,10 +178826,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -175904,7 +178845,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -176039,7 +178981,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -176056,9 +178998,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -176145,7 +179087,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -176298,7 +179241,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -176351,9 +179294,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -176405,30 +179351,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -176456,10 +179402,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -176480,12 +179428,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -176567,9 +179516,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -176595,7 +179545,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -176613,7 +179563,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -176646,21 +179597,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -176679,9 +179632,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -176704,7 +179658,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -176752,17 +179707,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -176783,10 +179738,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -176801,7 +179757,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -176936,7 +179893,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -176953,9 +179910,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -177042,7 +179999,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -177195,7 +180153,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -177248,9 +180206,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -177302,30 +180263,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -177353,10 +180314,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -177377,12 +180340,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -177464,9 +180428,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -177492,7 +180457,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -177510,7 +180475,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -177543,21 +180509,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -177576,9 +180544,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -177601,7 +180570,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -177649,17 +180619,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -177680,10 +180650,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -177698,7 +180669,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -177833,7 +180805,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -177850,9 +180822,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -177939,7 +180911,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -178092,7 +181065,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -178145,9 +181118,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -178199,30 +181175,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -178250,10 +181226,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -178274,12 +181252,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -178361,9 +181340,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -178389,7 +181369,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -178407,7 +181387,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -178440,21 +181421,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -178473,9 +181456,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -178498,7 +181482,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -178546,17 +181531,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -178577,10 +181562,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -178595,7 +181581,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -178730,7 +181717,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -178747,9 +181734,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -178836,7 +181823,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -178989,7 +181977,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -179042,9 +182030,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -179096,30 +182087,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -179147,10 +182138,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -179171,12 +182164,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -179258,9 +182252,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -179286,7 +182281,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -179304,7 +182299,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -179337,21 +182333,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -179370,9 +182368,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -179395,7 +182394,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -179443,17 +182443,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -179474,10 +182474,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -179492,7 +182493,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -179627,7 +182629,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -179644,9 +182646,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -179733,7 +182735,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -179886,7 +182889,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -179939,9 +182942,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -179993,30 +182999,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -180044,10 +183050,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -180068,12 +183076,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -180155,9 +183164,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -180183,7 +183193,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -180201,7 +183211,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -180234,21 +183245,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -180267,9 +183280,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -180292,7 +183306,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -180340,17 +183355,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -180371,10 +183386,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -180389,7 +183405,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -180524,7 +183541,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -180541,9 +183558,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -180630,7 +183647,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -180783,7 +183801,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -180836,9 +183854,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -180890,30 +183911,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -180941,10 +183962,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -180965,12 +183988,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -181052,9 +184076,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -181080,7 +184105,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -181098,7 +184123,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -181131,21 +184157,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -181164,9 +184192,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -181189,7 +184218,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -181237,17 +184267,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -181268,10 +184298,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -181286,7 +184317,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -181421,7 +184453,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -181438,9 +184470,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -181527,7 +184559,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -181680,7 +184713,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -181733,9 +184766,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -181787,30 +184823,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -181838,10 +184874,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -181862,12 +184900,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -181949,9 +184988,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -181977,7 +185017,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -181995,7 +185035,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -182028,21 +185069,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -182061,9 +185104,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -182086,7 +185130,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -182134,17 +185179,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -182165,10 +185210,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -182183,7 +185229,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -182318,7 +185365,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -182335,9 +185382,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -182424,7 +185471,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -182577,7 +185625,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -182630,9 +185678,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -182684,30 +185735,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -182735,10 +185786,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -182759,12 +185812,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -182846,9 +185900,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -182874,7 +185929,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -182892,7 +185947,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -182925,21 +185981,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -182958,9 +186016,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -182983,7 +186042,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -183031,17 +186091,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -183062,10 +186122,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -183080,7 +186141,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -183215,7 +186277,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -183232,9 +186294,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -183321,7 +186383,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -183474,7 +186537,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -183527,9 +186590,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -183581,30 +186647,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -183632,10 +186698,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -183656,12 +186724,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -183743,9 +186812,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -183771,7 +186841,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -183789,7 +186859,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -183822,21 +186893,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -183855,9 +186928,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -183880,7 +186954,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -183928,17 +187003,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -183959,10 +187034,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -183977,7 +187053,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -184112,7 +187189,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -184129,9 +187206,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -184218,7 +187295,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -184371,7 +187449,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -184424,9 +187502,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -184478,30 +187559,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -184529,10 +187610,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -184553,12 +187636,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -184640,9 +187724,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -184668,7 +187753,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -184686,7 +187771,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -184719,21 +187805,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -184752,9 +187840,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -184777,7 +187866,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -184825,17 +187915,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -184856,10 +187946,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -184874,7 +187965,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -185009,7 +188101,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -185026,9 +188118,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -185115,7 +188207,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -185268,7 +188361,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -185321,9 +188414,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -185375,30 +188471,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -185426,10 +188522,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -185450,12 +188548,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -185537,9 +188636,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -185565,7 +188665,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -185583,7 +188683,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -185616,21 +188717,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -185649,9 +188752,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -185674,7 +188778,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -185722,17 +188827,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -185753,10 +188858,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -185771,7 +188877,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -185906,7 +189013,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -185923,9 +189030,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -186012,7 +189119,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -186165,7 +189273,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -186218,9 +189326,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -186272,30 +189383,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -186323,10 +189434,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -186347,12 +189460,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -186434,9 +189548,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -186462,7 +189577,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -186480,7 +189595,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -186513,21 +189629,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -186546,9 +189664,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -186571,7 +189690,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -186619,17 +189739,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -186650,10 +189770,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -186668,7 +189789,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -186803,7 +189925,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -186820,9 +189942,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -186909,7 +190031,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -187062,7 +190185,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -187115,9 +190238,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -187169,30 +190295,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -187220,10 +190346,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -187244,12 +190372,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -187331,9 +190460,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -187359,7 +190489,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -187377,7 +190507,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -187410,21 +190541,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -187443,9 +190576,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -187468,7 +190602,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -187516,17 +190651,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -187547,10 +190682,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -187565,7 +190701,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -187700,7 +190837,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -187717,9 +190854,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -187806,7 +190943,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -187959,7 +191097,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -188012,9 +191150,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -188066,30 +191207,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -188117,10 +191258,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -188141,12 +191284,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -188228,9 +191372,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -188256,7 +191401,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -188274,7 +191419,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -188307,21 +191453,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -188340,9 +191488,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -188365,7 +191514,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -188413,17 +191563,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -188444,10 +191594,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -188462,7 +191613,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -188597,7 +191749,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -188614,9 +191766,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -188703,7 +191855,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -188856,7 +192009,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -188909,9 +192062,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -188963,30 +192119,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -189014,10 +192170,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -189038,12 +192196,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -189125,9 +192284,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -189153,7 +192313,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -189171,7 +192331,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -189204,21 +192365,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -189237,9 +192400,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -189262,7 +192426,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -189310,17 +192475,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -189341,10 +192506,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -189359,7 +192525,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -189494,7 +192661,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -189511,9 +192678,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -189600,7 +192767,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -189753,7 +192921,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -189806,9 +192974,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -189860,30 +193031,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -189911,10 +193082,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -189935,12 +193108,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -190022,9 +193196,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -190050,7 +193225,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -190068,7 +193243,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -190101,21 +193277,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -190134,9 +193312,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -190159,7 +193338,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -190207,17 +193387,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -190238,10 +193418,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -190256,7 +193437,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -190391,7 +193573,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -190408,9 +193590,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -190497,7 +193679,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -190650,7 +193833,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -190703,9 +193886,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -190757,30 +193943,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -190808,10 +193994,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -190832,12 +194020,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -190919,9 +194108,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -190947,7 +194137,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -190965,7 +194155,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -190998,21 +194189,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -191031,9 +194224,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -191056,7 +194250,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -191104,17 +194299,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -191135,10 +194330,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -191153,7 +194349,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -191288,7 +194485,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -191305,9 +194502,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -191394,7 +194591,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -191547,7 +194745,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -191600,9 +194798,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -191654,30 +194855,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -191705,10 +194906,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -191729,12 +194932,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -191816,9 +195020,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -191844,7 +195049,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -191862,7 +195067,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -191895,21 +195101,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -191928,9 +195136,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -191953,7 +195162,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -192001,17 +195211,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -192032,10 +195242,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -192050,7 +195261,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -192185,7 +195397,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -192202,9 +195414,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -192291,7 +195503,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -192444,7 +195657,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -192497,9 +195710,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -192551,30 +195767,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -192602,10 +195818,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -192626,12 +195844,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -192713,9 +195932,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -192741,7 +195961,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -192759,7 +195979,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -192792,21 +196013,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -192825,9 +196048,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -192850,7 +196074,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -192898,17 +196123,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -192929,10 +196154,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -192947,7 +196173,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -193082,7 +196309,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -193099,9 +196326,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -193188,7 +196415,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -193341,7 +196569,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -193394,9 +196622,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -193448,30 +196679,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -193499,10 +196730,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -193523,12 +196756,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -193610,9 +196844,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -193638,7 +196873,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -193656,7 +196891,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -193689,21 +196925,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -193722,9 +196960,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -193747,7 +196986,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -193795,17 +197035,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -193826,10 +197066,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -193844,7 +197085,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -193979,7 +197221,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -193996,9 +197238,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -194085,7 +197327,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -194238,7 +197481,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -194291,9 +197534,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -194345,30 +197591,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -194396,10 +197642,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -194420,12 +197668,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -194507,9 +197756,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -194535,7 +197785,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -194553,7 +197803,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -194586,21 +197837,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -194619,9 +197872,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -194644,7 +197898,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -194692,17 +197947,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -194723,10 +197978,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -194741,7 +197997,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -194876,7 +198133,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -194893,9 +198150,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -194982,7 +198239,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -195135,7 +198393,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -195188,9 +198446,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -195242,30 +198503,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -195293,10 +198554,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -195317,12 +198580,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -195404,9 +198668,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -195432,7 +198697,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -195450,7 +198715,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -195483,21 +198749,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -195516,9 +198784,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -195541,7 +198810,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -195589,17 +198859,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -195620,10 +198890,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -195638,7 +198909,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -195773,7 +199045,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -195790,9 +199062,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -195879,7 +199151,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -196032,7 +199305,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -196085,9 +199358,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -196139,30 +199415,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -196190,10 +199466,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -196214,12 +199492,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -196301,9 +199580,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -196329,7 +199609,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -196347,7 +199627,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -196380,21 +199661,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -196413,9 +199696,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -196438,7 +199722,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -196486,17 +199771,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -196517,10 +199802,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -196535,7 +199821,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -196670,7 +199957,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -196687,9 +199974,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -196776,7 +200063,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -196929,7 +200217,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -196982,9 +200270,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -197036,30 +200327,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -197087,10 +200378,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -197111,12 +200404,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -197198,9 +200492,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -197226,7 +200521,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -197244,7 +200539,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -197277,21 +200573,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -197310,9 +200608,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -197335,7 +200634,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -197383,17 +200683,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -197414,10 +200714,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -197432,7 +200733,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -197567,7 +200869,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -197584,9 +200886,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -197673,7 +200975,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -197826,7 +201129,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -197879,9 +201182,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -197933,30 +201239,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -197984,10 +201290,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -198008,12 +201316,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -198095,9 +201404,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -198123,7 +201433,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -198141,7 +201451,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -198174,21 +201485,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -198207,9 +201520,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -198232,7 +201546,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -198280,17 +201595,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -198311,10 +201626,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -198329,7 +201645,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -198464,7 +201781,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -198481,9 +201798,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -198570,7 +201887,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -198723,7 +202041,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -198776,9 +202094,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -198830,30 +202151,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -198881,10 +202202,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -198905,12 +202228,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -198992,9 +202316,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -199020,7 +202345,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -199038,7 +202363,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -199071,21 +202397,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -199104,9 +202432,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -199129,7 +202458,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -199177,17 +202507,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -199208,10 +202538,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -199226,7 +202557,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -199361,7 +202693,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -199378,9 +202710,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -199467,7 +202799,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -199620,7 +202953,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -199673,9 +203006,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -199727,30 +203063,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -199778,10 +203114,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -199802,12 +203140,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -199889,9 +203228,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -199917,7 +203257,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -199935,7 +203275,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -199968,21 +203309,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -200001,9 +203344,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -200026,7 +203370,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -200074,17 +203419,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -200105,10 +203450,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -200123,7 +203469,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -200258,7 +203605,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -200275,9 +203622,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -200364,7 +203711,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -200517,7 +203865,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -200570,9 +203918,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -200624,30 +203975,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -200675,10 +204026,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -200699,12 +204052,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -200786,9 +204140,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -200814,7 +204169,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -200832,7 +204187,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -200865,21 +204221,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -200898,9 +204256,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -200923,7 +204282,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -200971,17 +204331,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -201002,10 +204362,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -201020,7 +204381,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -201155,7 +204517,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -201172,9 +204534,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -201261,7 +204623,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -201414,7 +204777,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -201467,9 +204830,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -201521,30 +204887,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -201572,10 +204938,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -201596,12 +204964,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -201683,9 +205052,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -201711,7 +205081,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -201729,7 +205099,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -201762,21 +205133,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -201795,9 +205168,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -201820,7 +205194,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -201868,17 +205243,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -201899,10 +205274,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -201917,7 +205293,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -202052,7 +205429,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -202069,9 +205446,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -202158,7 +205535,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -202311,7 +205689,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -202364,9 +205742,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -202418,30 +205799,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -202469,10 +205850,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -202493,12 +205876,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -202580,9 +205964,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -202608,7 +205993,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -202626,7 +206011,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -202659,21 +206045,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -202692,9 +206080,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -202717,7 +206106,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -202765,17 +206155,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -202796,10 +206186,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -202814,7 +206205,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -202949,7 +206341,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -202966,9 +206358,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -203055,7 +206447,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -203208,7 +206601,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -203261,9 +206654,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -203315,30 +206711,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -203366,10 +206762,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -203390,12 +206788,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -203477,9 +206876,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -203505,7 +206905,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -203523,7 +206923,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -203556,21 +206957,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -203589,9 +206992,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -203614,7 +207018,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -203662,17 +207067,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -203693,10 +207098,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -203711,7 +207117,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -203846,7 +207253,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -203863,9 +207270,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -203952,7 +207359,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -204105,7 +207513,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -204158,9 +207566,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -204212,30 +207623,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -204263,10 +207674,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -204287,12 +207700,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -204374,9 +207788,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -204402,7 +207817,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -204420,7 +207835,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -204453,21 +207869,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -204486,9 +207904,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -204511,7 +207930,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -204559,17 +207979,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -204590,10 +208010,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -204608,7 +208029,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -204743,7 +208165,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -204760,9 +208182,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -204849,7 +208271,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -205002,7 +208425,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -205055,9 +208478,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -205109,30 +208535,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -205160,10 +208586,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -205184,12 +208612,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -205271,9 +208700,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -205299,7 +208729,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -205317,7 +208747,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -205350,21 +208781,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -205383,9 +208816,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -205408,7 +208842,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -205456,17 +208891,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -205487,10 +208922,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -205505,7 +208941,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -205640,7 +209077,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -205657,9 +209094,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -205746,7 +209183,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -205899,7 +209337,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -205952,9 +209390,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -206006,30 +209447,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -206057,10 +209498,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -206081,12 +209524,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -206168,9 +209612,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -206196,7 +209641,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -206214,7 +209659,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -206247,21 +209693,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -206280,9 +209728,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -206305,7 +209754,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -206353,17 +209803,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -206384,10 +209834,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -206402,7 +209853,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -206537,7 +209989,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -206554,9 +210006,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -206643,7 +210095,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -206796,7 +210249,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -206849,9 +210302,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -206903,30 +210359,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -206954,10 +210410,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -206978,12 +210436,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -207065,9 +210524,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -207093,7 +210553,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -207111,7 +210571,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -207144,21 +210605,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -207177,9 +210640,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -207202,7 +210666,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -207250,17 +210715,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -207281,10 +210746,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -207299,7 +210765,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -207434,7 +210901,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -207451,9 +210918,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -207540,7 +211007,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -207693,7 +211161,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -207746,9 +211214,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -207800,30 +211271,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -207851,10 +211322,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -207875,12 +211348,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -207962,9 +211436,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -207990,7 +211465,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -208008,7 +211483,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -208041,21 +211517,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -208074,9 +211552,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -208099,7 +211578,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -208147,17 +211627,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -208178,10 +211658,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -208196,7 +211677,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -208331,7 +211813,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -208348,9 +211830,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -208437,7 +211919,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -208590,7 +212073,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -208643,9 +212126,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -208697,30 +212183,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -208748,10 +212234,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -208772,12 +212260,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -208859,9 +212348,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -208887,7 +212377,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -208905,7 +212395,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -208938,21 +212429,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -208971,9 +212464,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -208996,7 +212490,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -209044,17 +212539,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -209075,10 +212570,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -209093,7 +212589,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -209228,7 +212725,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -209245,9 +212742,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -209334,7 +212831,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -209487,7 +212985,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -209540,9 +213038,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -209594,30 +213095,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -209645,10 +213146,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -209669,12 +213172,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -209756,9 +213260,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -209784,7 +213289,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -209802,7 +213307,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -209835,21 +213341,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -209868,9 +213376,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -209893,7 +213402,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -209941,17 +213451,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -209972,10 +213482,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -209990,7 +213501,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -210125,7 +213637,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -210142,9 +213654,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -210231,7 +213743,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -210384,7 +213897,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -210437,9 +213950,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -210491,30 +214007,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -210542,10 +214058,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -210566,12 +214084,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -210653,9 +214172,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -210681,7 +214201,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -210699,7 +214219,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -210732,21 +214253,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -210765,9 +214288,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -210790,7 +214314,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -210838,17 +214363,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -210869,10 +214394,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -210887,7 +214413,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -211022,7 +214549,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -211039,9 +214566,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -211128,7 +214655,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -211281,7 +214809,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -211334,9 +214862,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -211388,30 +214919,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -211439,10 +214970,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -211463,12 +214996,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -211550,9 +215084,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -211578,7 +215113,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -211596,7 +215131,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -211629,21 +215165,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -211662,9 +215200,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -211687,7 +215226,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -211735,17 +215275,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -211766,10 +215306,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -211784,7 +215325,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -211919,7 +215461,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -211936,9 +215478,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -212025,7 +215567,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -212178,7 +215721,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -212231,9 +215774,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -212285,30 +215831,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -212336,10 +215882,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -212360,12 +215908,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -212447,9 +215996,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -212475,7 +216025,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -212493,7 +216043,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -212526,21 +216077,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -212559,9 +216112,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -212584,7 +216138,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -212632,17 +216187,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -212663,10 +216218,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -212681,7 +216237,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -212816,7 +216373,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -212833,9 +216390,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -212922,7 +216479,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -213075,7 +216633,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -213128,9 +216686,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -213182,30 +216743,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -213233,10 +216794,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -213257,12 +216820,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -213344,9 +216908,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -213372,7 +216937,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -213390,7 +216955,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -213423,21 +216989,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -213456,9 +217024,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -213481,7 +217050,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -213529,17 +217099,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -213560,10 +217130,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -213578,7 +217149,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -213713,7 +217285,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -213730,9 +217302,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -213819,7 +217391,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -213972,7 +217545,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -214025,9 +217598,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -214079,30 +217655,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -214130,10 +217706,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -214154,12 +217732,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -214241,9 +217820,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -214269,7 +217849,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -214287,7 +217867,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -214320,21 +217901,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -214353,9 +217936,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -214378,7 +217962,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -214426,17 +218011,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -214457,10 +218042,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -214475,7 +218061,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -214610,7 +218197,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -214627,9 +218214,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -214716,7 +218303,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -214869,7 +218457,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -214922,9 +218510,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -214976,30 +218567,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -215027,10 +218618,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -215051,12 +218644,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -215138,9 +218732,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -215166,7 +218761,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -215184,7 +218779,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -215217,21 +218813,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -215250,9 +218848,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -215275,7 +218874,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -215323,17 +218923,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -215354,10 +218954,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -215372,7 +218973,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -215507,7 +219109,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -215524,9 +219126,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -215613,7 +219215,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -215766,7 +219369,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -215819,9 +219422,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -215873,30 +219479,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -215924,10 +219530,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -215948,12 +219556,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -216035,9 +219644,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -216063,7 +219673,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -216081,7 +219691,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -216114,21 +219725,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -216147,9 +219760,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -216172,7 +219786,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -216220,17 +219835,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -216251,10 +219866,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -216269,7 +219885,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -216404,7 +220021,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -216421,9 +220038,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -216510,7 +220127,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -216663,7 +220281,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -216716,9 +220334,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -216770,30 +220391,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -216821,10 +220442,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -216845,12 +220468,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -216932,9 +220556,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -216960,7 +220585,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -216978,7 +220603,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -217011,21 +220637,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -217044,9 +220672,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -217069,7 +220698,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -217117,17 +220747,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -217148,10 +220778,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -217166,7 +220797,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -217301,7 +220933,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -217318,9 +220950,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -217407,7 +221039,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -217560,7 +221193,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -217613,9 +221246,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -217667,30 +221303,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -217718,10 +221354,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -217742,12 +221380,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -217829,9 +221468,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -217857,7 +221497,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -217875,7 +221515,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -217908,21 +221549,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -217941,9 +221584,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -217966,7 +221610,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -218014,17 +221659,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -218045,10 +221690,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -218063,7 +221709,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -218198,7 +221845,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -218215,9 +221862,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -218304,7 +221951,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -218457,7 +222105,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -218510,9 +222158,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -218564,30 +222215,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -218615,10 +222266,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -218639,12 +222292,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -218726,9 +222380,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -218754,7 +222409,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -218772,7 +222427,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -218805,21 +222461,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -218838,9 +222496,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -218863,7 +222522,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -218911,17 +222571,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -218942,10 +222602,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -218960,7 +222621,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -219095,7 +222757,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -219112,9 +222774,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -219201,7 +222863,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -219354,7 +223017,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -219407,9 +223070,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -219461,30 +223127,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -219512,10 +223178,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -219536,12 +223204,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -219623,9 +223292,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -219651,7 +223321,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -219669,7 +223339,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -219702,21 +223373,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -219735,9 +223408,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -219760,7 +223434,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -219808,17 +223483,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -219839,10 +223514,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -219857,7 +223533,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -219992,7 +223669,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -220009,9 +223686,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -220098,7 +223775,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -220251,7 +223929,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -220304,9 +223982,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -220358,30 +224039,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -220409,10 +224090,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -220433,12 +224116,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -220520,9 +224204,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -220548,7 +224233,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -220566,7 +224251,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -220599,21 +224285,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -220632,9 +224320,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -220657,7 +224346,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -220705,17 +224395,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -220736,10 +224426,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -220754,7 +224445,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -220889,7 +224581,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -220906,9 +224598,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -220995,7 +224687,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -221148,7 +224841,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -221201,9 +224894,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -221255,30 +224951,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -221306,10 +225002,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -221330,12 +225028,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -221417,9 +225116,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -221445,7 +225145,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -221463,7 +225163,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -221496,21 +225197,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -221529,9 +225232,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -221554,7 +225258,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -221602,17 +225307,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -221633,10 +225338,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -221651,7 +225357,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -221786,7 +225493,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -221803,9 +225510,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -221892,7 +225599,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -222045,7 +225753,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -222098,9 +225806,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -222152,30 +225863,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -222203,10 +225914,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -222227,12 +225940,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -222314,9 +226028,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -222342,7 +226057,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -222360,7 +226075,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -222393,21 +226109,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -222426,9 +226144,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -222451,7 +226170,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -222499,17 +226219,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -222530,10 +226250,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -222548,7 +226269,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -222683,7 +226405,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -222700,9 +226422,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -222789,7 +226511,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -222942,7 +226665,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -222995,9 +226718,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -223049,30 +226775,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -223100,10 +226826,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -223124,12 +226852,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -223211,9 +226940,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -223239,7 +226969,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -223257,7 +226987,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -223290,21 +227021,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -223323,9 +227056,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -223348,7 +227082,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -223396,17 +227131,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -223427,10 +227162,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -223445,7 +227181,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -223580,7 +227317,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -223597,9 +227334,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -223686,7 +227423,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -223839,7 +227577,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -223892,9 +227630,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -223946,30 +227687,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -223997,10 +227738,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -224021,12 +227764,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -224108,9 +227852,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -224136,7 +227881,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -224154,7 +227899,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -224187,21 +227933,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -224220,9 +227968,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -224245,7 +227994,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -224293,17 +228043,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -224324,10 +228074,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -224342,7 +228093,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -224477,7 +228229,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -224494,9 +228246,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -224583,7 +228335,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -224736,7 +228489,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -224789,9 +228542,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -224843,30 +228599,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -224894,10 +228650,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -224918,12 +228676,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -225005,9 +228764,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -225033,7 +228793,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -225051,7 +228811,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -225084,21 +228845,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -225117,9 +228880,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -225142,7 +228906,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -225190,17 +228955,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -225221,10 +228986,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -225239,7 +229005,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -225374,7 +229141,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -225391,9 +229158,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -225480,7 +229247,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -225633,7 +229401,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -225686,9 +229454,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -225740,30 +229511,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -225791,10 +229562,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -225815,12 +229588,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -225902,9 +229676,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -225930,7 +229705,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -225948,7 +229723,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -225981,21 +229757,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -226014,9 +229792,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -226039,7 +229818,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -226087,17 +229867,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -226118,10 +229898,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -226136,7 +229917,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -226271,7 +230053,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -226288,9 +230070,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -226377,7 +230159,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -226530,7 +230313,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -226583,9 +230366,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -226637,30 +230423,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -226688,10 +230474,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -226712,12 +230500,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -226799,9 +230588,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -226827,7 +230617,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -226845,7 +230635,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -226878,21 +230669,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -226911,9 +230704,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -226936,7 +230730,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -226984,17 +230779,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -227015,10 +230810,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -227033,7 +230829,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -227168,7 +230965,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -227185,9 +230982,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -227274,7 +231071,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -227427,7 +231225,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -227480,9 +231278,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -227534,30 +231335,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -227585,10 +231386,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -227609,12 +231412,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -227696,9 +231500,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -227724,7 +231529,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -227742,7 +231547,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -227775,21 +231581,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -227808,9 +231616,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -227833,7 +231642,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -227881,17 +231691,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -227912,10 +231722,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -227930,7 +231741,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -228065,7 +231877,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -228082,9 +231894,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -228171,7 +231983,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -228324,7 +232137,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -228377,9 +232190,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -228431,30 +232247,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -228482,10 +232298,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -228506,12 +232324,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -228593,9 +232412,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -228621,7 +232441,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -228639,7 +232459,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -228672,21 +232493,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -228705,9 +232528,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -228730,7 +232554,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -228778,17 +232603,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -228809,10 +232634,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -228827,7 +232653,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -228962,7 +232789,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -228979,9 +232806,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -229068,7 +232895,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -229221,7 +233049,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -229274,9 +233102,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -229328,30 +233159,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -229379,10 +233210,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -229403,12 +233236,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -229490,9 +233324,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -229518,7 +233353,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -229536,7 +233371,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -229569,21 +233405,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -229602,9 +233440,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -229627,7 +233466,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -229675,17 +233515,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -229706,10 +233546,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -229724,7 +233565,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -229859,7 +233701,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -229876,9 +233718,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -229965,7 +233807,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -230118,7 +233961,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -230171,9 +234014,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -230225,30 +234071,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -230276,10 +234122,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -230300,12 +234148,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -230387,9 +234236,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -230415,7 +234265,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -230433,7 +234283,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -230466,21 +234317,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -230499,9 +234352,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -230524,7 +234378,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -230572,17 +234427,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -230603,10 +234458,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -230621,7 +234477,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -230756,7 +234613,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -230773,9 +234630,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -230862,7 +234719,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -231015,7 +234873,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -231068,9 +234926,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -231122,30 +234983,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -231173,10 +235034,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -231197,12 +235060,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -231284,9 +235148,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -231312,7 +235177,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -231330,7 +235195,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -231363,21 +235229,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -231396,9 +235264,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -231421,7 +235290,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -231469,17 +235339,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -231500,10 +235370,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -231518,7 +235389,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -231653,7 +235525,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -231670,9 +235542,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -231759,7 +235631,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -231912,7 +235785,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -231965,9 +235838,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -232019,30 +235895,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -232070,10 +235946,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -232094,12 +235972,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -232181,9 +236060,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -232209,7 +236089,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -232227,7 +236107,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -232260,21 +236141,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -232293,9 +236176,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -232318,7 +236202,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -232366,17 +236251,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -232397,10 +236282,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -232415,7 +236301,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -232550,7 +236437,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -232567,9 +236454,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -232656,7 +236543,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -232809,7 +236697,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -232862,9 +236750,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -232916,30 +236807,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -232967,10 +236858,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -232991,12 +236884,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -233078,9 +236972,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -233106,7 +237001,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -233124,7 +237019,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -233157,21 +237053,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -233190,9 +237088,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -233215,7 +237114,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -233263,17 +237163,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -233294,10 +237194,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -233312,7 +237213,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -233447,7 +237349,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -233464,9 +237366,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -233553,7 +237455,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -233706,7 +237609,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -233759,9 +237662,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -233813,30 +237719,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -233864,10 +237770,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -233888,12 +237796,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -233975,9 +237884,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -234003,7 +237913,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -234021,7 +237931,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -234054,21 +237965,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -234087,9 +238000,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -234112,7 +238026,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -234160,17 +238075,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -234191,10 +238106,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -234209,7 +238125,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -234344,7 +238261,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -234361,9 +238278,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -234450,7 +238367,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -234603,7 +238521,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -234656,9 +238574,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -234710,30 +238631,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -234761,10 +238682,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -234785,12 +238708,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -234872,9 +238796,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -234900,7 +238825,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -234918,7 +238843,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -234951,21 +238877,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -234984,9 +238912,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -235009,7 +238938,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -235057,17 +238987,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -235088,10 +239018,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -235106,7 +239037,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -235241,7 +239173,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -235258,9 +239190,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -235347,7 +239279,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -235500,7 +239433,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -235553,9 +239486,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -235607,30 +239543,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -235658,10 +239594,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -235682,12 +239620,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -235769,9 +239708,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -235797,7 +239737,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -235815,7 +239755,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -235848,21 +239789,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -235881,9 +239824,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -235906,7 +239850,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -235954,17 +239899,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -235985,10 +239930,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -236003,7 +239949,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -236138,7 +240085,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -236155,9 +240102,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -236244,7 +240191,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -236397,7 +240345,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -236450,9 +240398,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -236504,30 +240455,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -236555,10 +240506,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -236579,12 +240532,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -236666,9 +240620,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -236694,7 +240649,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -236712,7 +240667,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -236745,21 +240701,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -236778,9 +240736,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -236803,7 +240762,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -236851,17 +240811,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -236882,10 +240842,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -236900,7 +240861,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -237035,7 +240997,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -237052,9 +241014,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -237141,7 +241103,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -237294,7 +241257,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -237347,9 +241310,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -237401,30 +241367,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -237452,10 +241418,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -237476,12 +241444,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -237563,9 +241532,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -237591,7 +241561,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -237609,7 +241579,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -237642,21 +241613,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -237675,9 +241648,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -237700,7 +241674,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -237748,17 +241723,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -237779,10 +241754,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -237797,7 +241773,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -237932,7 +241909,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -237949,9 +241926,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -238038,7 +242015,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -238191,7 +242169,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -238244,9 +242222,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -238298,30 +242279,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -238349,10 +242330,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -238373,12 +242356,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -238460,9 +242444,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -238488,7 +242473,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -238506,7 +242491,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -238539,21 +242525,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -238572,9 +242560,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -238597,7 +242586,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -238645,17 +242635,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -238676,10 +242666,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -238694,7 +242685,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -238829,7 +242821,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -238846,9 +242838,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -238935,7 +242927,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -239088,7 +243081,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -239141,9 +243134,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -239195,30 +243191,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -239246,10 +243242,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -239270,12 +243268,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -239357,9 +243356,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -239385,7 +243385,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -239403,7 +243403,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -239436,21 +243437,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -239469,9 +243472,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -239494,7 +243498,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -239542,17 +243547,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -239573,10 +243578,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -239591,7 +243597,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -239726,7 +243733,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -239743,9 +243750,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -239832,7 +243839,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -239985,7 +243993,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -240038,9 +244046,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -240092,30 +244103,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -240143,10 +244154,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -240167,12 +244180,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -240254,9 +244268,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -240282,7 +244297,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -240300,7 +244315,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -240333,21 +244349,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -240366,9 +244384,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -240391,7 +244410,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -240439,17 +244459,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -240470,10 +244490,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -240488,7 +244509,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -240623,7 +244645,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -240640,9 +244662,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -240729,7 +244751,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -240882,7 +244905,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -240935,9 +244958,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -240989,30 +245015,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -241040,10 +245066,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -241064,12 +245092,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -241151,9 +245180,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -241179,7 +245209,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -241197,7 +245227,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -241230,21 +245261,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -241263,9 +245296,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -241288,7 +245322,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -241336,17 +245371,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -241367,10 +245402,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -241385,7 +245421,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -241520,7 +245557,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -241537,9 +245574,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -241626,7 +245663,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -241779,7 +245817,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -241832,9 +245870,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -241886,30 +245927,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -241937,10 +245978,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -241961,12 +246004,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -242048,9 +246092,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -242076,7 +246121,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -242094,7 +246139,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -242127,21 +246173,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -242160,9 +246208,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -242185,7 +246234,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -242233,17 +246283,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -242264,10 +246314,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -242282,7 +246333,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -242417,7 +246469,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -242434,9 +246486,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -242523,7 +246575,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -242676,7 +246729,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -242729,9 +246782,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -242783,30 +246839,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -242834,10 +246890,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -242858,12 +246916,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -242945,9 +247004,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -242973,7 +247033,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -242991,7 +247051,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -243024,21 +247085,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -243057,9 +247120,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -243082,7 +247146,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -243130,17 +247195,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -243161,10 +247226,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -243179,7 +247245,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -243314,7 +247381,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -243331,9 +247398,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -243420,7 +247487,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -243573,7 +247641,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -243626,9 +247694,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -243680,30 +247751,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -243731,10 +247802,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -243755,12 +247828,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -243842,9 +247916,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -243870,7 +247945,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -243888,7 +247963,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -243921,21 +247997,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -243954,9 +248032,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -243979,7 +248058,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -244027,17 +248107,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -244058,10 +248138,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -244076,7 +248157,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -244211,7 +248293,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -244228,9 +248310,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -244317,7 +248399,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -244470,7 +248553,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -244523,9 +248606,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -244577,30 +248663,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -244628,10 +248714,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -244652,12 +248740,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -244739,9 +248828,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -244767,7 +248857,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -244785,7 +248875,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -244818,21 +248909,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -244851,9 +248944,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -244876,7 +248970,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -244924,17 +249019,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -244955,10 +249050,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -244973,7 +249069,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -245108,7 +249205,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -245125,9 +249222,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -245214,7 +249311,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -245367,7 +249465,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -245420,9 +249518,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -245474,30 +249575,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -245525,10 +249626,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -245549,12 +249652,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -245636,9 +249740,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -245664,7 +249769,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -245682,7 +249787,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -245715,21 +249821,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -245748,9 +249856,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -245773,7 +249882,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -245821,17 +249931,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -245852,10 +249962,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -245870,7 +249981,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -246005,7 +250117,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -246022,9 +250134,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -246111,7 +250223,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -246264,7 +250377,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -246317,9 +250430,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -246371,30 +250487,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -246422,10 +250538,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -246446,12 +250564,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -246533,9 +250652,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -246561,7 +250681,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -246579,7 +250699,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -246612,21 +250733,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -246645,9 +250768,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -246670,7 +250794,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -246718,17 +250843,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -246749,10 +250874,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -246767,7 +250893,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -246902,7 +251029,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -246919,9 +251046,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -247008,7 +251135,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -247161,7 +251289,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -247214,9 +251342,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -247268,30 +251399,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -247319,10 +251450,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -247343,12 +251476,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -247430,9 +251564,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -247458,7 +251593,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -247476,7 +251611,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -247509,21 +251645,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -247542,9 +251680,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -247567,7 +251706,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -247615,17 +251755,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -247646,10 +251786,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -247664,7 +251805,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -247799,7 +251941,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -247816,9 +251958,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -247905,7 +252047,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -248058,7 +252201,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -248111,9 +252254,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -248165,30 +252311,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -248216,10 +252362,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -248240,12 +252388,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -248327,9 +252476,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -248355,7 +252505,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -248373,7 +252523,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -248406,21 +252557,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -248439,9 +252592,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -248464,7 +252618,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -248512,17 +252667,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -248543,10 +252698,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -248561,7 +252717,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -248696,7 +252853,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -248713,9 +252870,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -248802,7 +252959,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -248955,7 +253113,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -249008,9 +253166,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -249062,30 +253223,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -249113,10 +253274,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -249137,12 +253300,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -249224,9 +253388,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -249252,7 +253417,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -249270,7 +253435,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -249303,21 +253469,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -249336,9 +253504,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -249361,7 +253530,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -249409,17 +253579,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -249440,10 +253610,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -249458,7 +253629,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -249593,7 +253765,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -249610,9 +253782,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -249699,7 +253871,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -249852,7 +254025,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -249905,9 +254078,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -249959,30 +254135,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -250010,10 +254186,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -250034,12 +254212,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -250121,9 +254300,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -250149,7 +254329,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -250167,7 +254347,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -250200,21 +254381,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -250233,9 +254416,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -250258,7 +254442,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -250306,17 +254491,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -250337,10 +254522,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -250355,7 +254541,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -250490,7 +254677,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -250507,9 +254694,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -250596,7 +254783,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -250749,7 +254937,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -250802,9 +254990,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -250856,30 +255047,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -250907,10 +255098,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -250931,12 +255124,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -251018,9 +255212,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -251046,7 +255241,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -251064,7 +255259,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -251097,21 +255293,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -251130,9 +255328,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -251155,7 +255354,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -251203,17 +255403,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -251234,10 +255434,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -251252,7 +255453,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -251387,7 +255589,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -251404,9 +255606,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -251493,7 +255695,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -251646,7 +255849,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -251699,9 +255902,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -251753,30 +255959,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -251804,10 +256010,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -251828,12 +256036,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -251915,9 +256124,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -251943,7 +256153,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -251961,7 +256171,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -251994,21 +256205,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -252027,9 +256240,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -252052,7 +256266,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -252100,17 +256315,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -252131,10 +256346,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -252149,7 +256365,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -252284,7 +256501,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -252301,9 +256518,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -252390,7 +256607,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -252543,7 +256761,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -252596,9 +256814,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -252650,30 +256871,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -252701,10 +256922,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -252725,12 +256948,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -252812,9 +257036,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -252840,7 +257065,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -252858,7 +257083,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -252891,21 +257117,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -252924,9 +257152,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -252949,7 +257178,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -252997,17 +257227,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -253028,10 +257258,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -253046,7 +257277,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -253181,7 +257413,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -253198,9 +257430,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -253287,7 +257519,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -253440,7 +257673,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -253493,9 +257726,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -253547,30 +257783,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -253598,10 +257834,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -253622,12 +257860,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -253709,9 +257948,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -253737,7 +257977,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -253755,7 +257995,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -253788,21 +258029,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -253821,9 +258064,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -253846,7 +258090,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -253894,17 +258139,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -253925,10 +258170,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -253943,7 +258189,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -254078,7 +258325,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -254095,9 +258342,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -254184,7 +258431,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -254337,7 +258585,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -254390,9 +258638,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -254444,30 +258695,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -254495,10 +258746,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -254519,12 +258772,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -254606,9 +258860,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -254634,7 +258889,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -254652,7 +258907,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -254685,21 +258941,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -254718,9 +258976,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -254743,7 +259002,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -254791,17 +259051,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -254822,10 +259082,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -254840,7 +259101,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -254975,7 +259237,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -254992,9 +259254,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -255081,7 +259343,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -255234,7 +259497,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -255287,9 +259550,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -255341,30 +259607,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -255392,10 +259658,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -255416,12 +259684,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -255503,9 +259772,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -255531,7 +259801,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -255549,7 +259819,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -255582,21 +259853,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -255615,9 +259888,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -255640,7 +259914,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -255688,17 +259963,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -255719,10 +259994,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -255737,7 +260013,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -255872,7 +260149,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -255889,9 +260166,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -255978,7 +260255,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -256131,7 +260409,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -256184,9 +260462,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -256238,30 +260519,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -256289,10 +260570,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -256313,12 +260596,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -256400,9 +260684,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -256428,7 +260713,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -256446,7 +260731,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -256479,21 +260765,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -256512,9 +260800,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -256537,7 +260826,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -256585,17 +260875,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -256616,10 +260906,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -256634,7 +260925,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -256769,7 +261061,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -256786,9 +261078,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -256875,7 +261167,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -257028,7 +261321,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -257081,9 +261374,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -257135,30 +261431,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -257186,10 +261482,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -257210,12 +261508,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -257297,9 +261596,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -257325,7 +261625,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -257343,7 +261643,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -257376,21 +261677,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -257409,9 +261712,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -257434,7 +261738,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -257482,17 +261787,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -257513,10 +261818,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -257531,7 +261837,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -257666,7 +261973,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -257683,9 +261990,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -257772,7 +262079,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -257925,7 +262233,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -257978,9 +262286,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -258032,30 +262343,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -258083,10 +262394,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -258107,12 +262420,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -258194,9 +262508,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -258222,7 +262537,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -258240,7 +262555,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -258273,21 +262589,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -258306,9 +262624,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -258331,7 +262650,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -258379,17 +262699,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -258410,10 +262730,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -258428,7 +262749,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -258563,7 +262885,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -258580,9 +262902,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -258669,7 +262991,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -258822,7 +263145,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -258875,9 +263198,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -258929,30 +263255,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -258980,10 +263306,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -259004,12 +263332,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -259091,9 +263420,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -259119,7 +263449,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -259137,7 +263467,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -259170,21 +263501,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -259203,9 +263536,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -259228,7 +263562,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -259276,17 +263611,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -259307,10 +263642,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -259325,7 +263661,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -259460,7 +263797,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -259477,9 +263814,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -259566,7 +263903,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -259719,7 +264057,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -259772,9 +264110,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -259826,30 +264167,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -259877,10 +264218,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -259901,12 +264244,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -259988,9 +264332,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -260016,7 +264361,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -260034,7 +264379,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -260067,21 +264413,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -260100,9 +264448,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -260125,7 +264474,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -260173,17 +264523,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -260204,10 +264554,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -260222,7 +264573,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -260357,7 +264709,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -260374,9 +264726,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -260463,7 +264815,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -260616,7 +264969,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -260669,9 +265022,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -260723,30 +265079,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -260774,10 +265130,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -260798,12 +265156,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -260885,9 +265244,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -260913,7 +265273,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -260931,7 +265291,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -260964,21 +265325,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -260997,9 +265360,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -261022,7 +265386,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -261070,17 +265435,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -261101,10 +265466,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -261119,7 +265485,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -261254,7 +265621,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -261271,9 +265638,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -261360,7 +265727,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -261513,7 +265881,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -261566,9 +265934,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -261620,30 +265991,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -261671,10 +266042,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -261695,12 +266068,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -261782,9 +266156,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -261810,7 +266185,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -261828,7 +266203,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -261861,21 +266237,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -261894,9 +266272,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -261919,7 +266298,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -261967,17 +266347,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -261998,10 +266378,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -262016,7 +266397,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -262151,7 +266533,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -262168,9 +266550,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -262257,7 +266639,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -262410,7 +266793,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -262463,9 +266846,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -262517,30 +266903,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -262568,10 +266954,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -262592,12 +266980,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -262679,9 +267068,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -262707,7 +267097,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -262725,7 +267115,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -262758,21 +267149,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -262791,9 +267184,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -262816,7 +267210,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -262864,17 +267259,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -262895,10 +267290,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -262913,7 +267309,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -263048,7 +267445,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -263065,9 +267462,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -263154,7 +267551,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -263307,7 +267705,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -263360,9 +267758,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -263414,30 +267815,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -263465,10 +267866,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -263489,12 +267892,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -263576,9 +267980,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -263604,7 +268009,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -263622,7 +268027,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -263655,21 +268061,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -263688,9 +268096,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -263713,7 +268122,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -263761,17 +268171,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -263792,10 +268202,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -263810,7 +268221,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -263945,7 +268357,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -263962,9 +268374,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -264051,7 +268463,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -264204,7 +268617,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -264257,9 +268670,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -264311,30 +268727,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -264362,10 +268778,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -264386,12 +268804,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -264473,9 +268892,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -264501,7 +268921,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -264519,7 +268939,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -264552,21 +268973,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -264585,9 +269008,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -264610,7 +269034,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -264658,17 +269083,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -264689,10 +269114,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -264707,7 +269133,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -264842,7 +269269,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -264859,9 +269286,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -264948,7 +269375,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -265101,7 +269529,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -265154,9 +269582,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -265208,30 +269639,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -265259,10 +269690,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -265283,12 +269716,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -265370,9 +269804,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -265398,7 +269833,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -265416,7 +269851,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -265449,21 +269885,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -265482,9 +269920,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -265507,7 +269946,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -265555,17 +269995,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -265586,10 +270026,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -265604,7 +270045,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -265739,7 +270181,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -265756,9 +270198,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -265845,7 +270287,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -265998,7 +270441,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -266051,9 +270494,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -266105,30 +270551,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -266156,10 +270602,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -266180,12 +270628,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -266267,9 +270716,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -266295,7 +270745,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -266313,7 +270763,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -266346,21 +270797,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -266379,9 +270832,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -266404,7 +270858,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -266452,17 +270907,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -266483,10 +270938,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -266501,7 +270957,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -266636,7 +271093,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -266653,9 +271110,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -266742,7 +271199,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -266895,7 +271353,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -266948,9 +271406,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -267002,30 +271463,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -267053,10 +271514,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -267077,12 +271540,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -267164,9 +271628,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -267192,7 +271657,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -267210,7 +271675,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -267243,21 +271709,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -267276,9 +271744,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -267301,7 +271770,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -267349,17 +271819,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -267380,10 +271850,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -267398,7 +271869,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -267533,7 +272005,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -267550,9 +272022,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -267639,7 +272111,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -267792,7 +272265,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -267845,9 +272318,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -267899,30 +272375,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -267950,10 +272426,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -267974,12 +272452,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -268061,9 +272540,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -268089,7 +272569,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -268107,7 +272587,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -268140,21 +272621,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -268173,9 +272656,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -268198,7 +272682,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -268246,17 +272731,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -268277,10 +272762,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -268295,7 +272781,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -268430,7 +272917,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -268447,9 +272934,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -268536,7 +273023,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -268689,7 +273177,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -268742,9 +273230,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -268796,30 +273287,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -268847,10 +273338,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -268871,12 +273364,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -268958,9 +273452,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -268986,7 +273481,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -269004,7 +273499,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -269037,21 +273533,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -269070,9 +273568,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -269095,7 +273594,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -269143,17 +273643,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -269174,10 +273674,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -269192,7 +273693,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -269327,7 +273829,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -269344,9 +273846,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -269433,7 +273935,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -269586,7 +274089,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -269639,9 +274142,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -269693,30 +274199,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -269744,10 +274250,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -269768,12 +274276,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -269855,9 +274364,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -269883,7 +274393,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -269901,7 +274411,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -269934,21 +274445,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -269967,9 +274480,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -269992,7 +274506,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -270040,17 +274555,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -270071,10 +274586,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -270089,7 +274605,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -270224,7 +274741,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -270241,9 +274758,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -270330,7 +274847,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -270483,7 +275001,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -270536,9 +275054,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -270590,30 +275111,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -270641,10 +275162,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -270665,12 +275188,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -270752,9 +275276,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -270780,7 +275305,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -270798,7 +275323,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -270831,21 +275357,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -270864,9 +275392,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -270889,7 +275418,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -270937,17 +275467,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -270968,10 +275498,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -270986,7 +275517,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -271121,7 +275653,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -271138,9 +275670,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -271227,7 +275759,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -271380,7 +275913,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -271433,9 +275966,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -271487,30 +276023,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -271538,10 +276074,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -271562,12 +276100,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -271649,9 +276188,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -271677,7 +276217,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -271695,7 +276235,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -271728,21 +276269,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -271761,9 +276304,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -271786,7 +276330,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -271834,17 +276379,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -271865,10 +276410,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -271883,7 +276429,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -272018,7 +276565,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -272035,9 +276582,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -272124,7 +276671,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -272277,7 +276825,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -272330,9 +276878,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -272384,30 +276935,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -272435,10 +276986,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -272459,12 +277012,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -272546,9 +277100,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -272574,7 +277129,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -272592,7 +277147,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -272625,21 +277181,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -272658,9 +277216,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -272683,7 +277242,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -272731,17 +277291,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -272762,10 +277322,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -272780,7 +277341,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -272915,7 +277477,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -272932,9 +277494,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -273021,7 +277583,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -273174,7 +277737,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -273227,9 +277790,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -273281,30 +277847,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -273332,10 +277898,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -273356,12 +277924,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -273443,9 +278012,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -273471,7 +278041,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -273489,7 +278059,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -273522,21 +278093,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -273555,9 +278128,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -273580,7 +278154,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -273628,17 +278203,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -273659,10 +278234,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -273677,7 +278253,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -273812,7 +278389,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -273829,9 +278406,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -273918,7 +278495,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -274071,7 +278649,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -274124,9 +278702,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -274178,30 +278759,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -274229,10 +278810,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -274253,12 +278836,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -274340,9 +278924,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -274368,7 +278953,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -274386,7 +278971,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -274419,21 +279005,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -274452,9 +279040,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -274477,7 +279066,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -274525,17 +279115,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -274556,10 +279146,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -274574,7 +279165,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -274709,7 +279301,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -274726,9 +279318,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -274815,7 +279407,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -274968,7 +279561,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -275021,9 +279614,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -275075,30 +279671,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -275126,10 +279722,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -275150,12 +279748,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -275237,9 +279836,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -275265,7 +279865,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -275283,7 +279883,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -275316,21 +279917,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -275349,9 +279952,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -275374,7 +279978,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -275422,17 +280027,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -275453,10 +280058,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -275471,7 +280077,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -275606,7 +280213,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -275623,9 +280230,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -275712,7 +280319,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -275865,7 +280473,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -275918,9 +280526,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -275972,30 +280583,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -276023,10 +280634,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -276047,12 +280660,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -276134,9 +280748,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -276162,7 +280777,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -276180,7 +280795,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -276213,21 +280829,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -276246,9 +280864,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -276271,7 +280890,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -276319,17 +280939,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -276350,10 +280970,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -276368,7 +280989,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -276503,7 +281125,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -276520,9 +281142,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -276609,7 +281231,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -276762,7 +281385,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -276815,9 +281438,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -276869,30 +281495,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -276920,10 +281546,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -276944,12 +281572,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -277031,9 +281660,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -277059,7 +281689,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -277077,7 +281707,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -277110,21 +281741,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -277143,9 +281776,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -277168,7 +281802,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -277216,17 +281851,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -277247,10 +281882,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -277265,7 +281901,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -277400,7 +282037,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -277417,9 +282054,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -277506,7 +282143,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -277659,7 +282297,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -277712,9 +282350,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -277766,30 +282407,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -277817,10 +282458,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -277841,12 +282484,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -277928,9 +282572,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -277956,7 +282601,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -277974,7 +282619,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -278007,21 +282653,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -278040,9 +282688,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -278065,7 +282714,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -278113,17 +282763,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -278144,10 +282794,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -278162,7 +282813,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -278297,7 +282949,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -278314,9 +282966,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -278403,7 +283055,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -278556,7 +283209,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -278609,9 +283262,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -278663,30 +283319,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -278714,10 +283370,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -278738,12 +283396,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -278825,9 +283484,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -278853,7 +283513,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -278871,7 +283531,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -278904,21 +283565,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -278937,9 +283600,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -278962,7 +283626,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -279010,17 +283675,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -279041,10 +283706,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -279059,7 +283725,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -279194,7 +283861,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -279211,9 +283878,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -279300,7 +283967,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -279453,7 +284121,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -279506,9 +284174,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -279560,30 +284231,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -279611,10 +284282,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -279635,12 +284308,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -279722,9 +284396,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -279750,7 +284425,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -279768,7 +284443,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -279801,21 +284477,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -279834,9 +284512,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -279859,7 +284538,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -279907,17 +284587,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -279938,10 +284618,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -279956,7 +284637,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -280091,7 +284773,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -280108,9 +284790,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -280197,7 +284879,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -280350,7 +285033,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -280403,9 +285086,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -280457,30 +285143,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -280508,10 +285194,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -280532,12 +285220,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -280619,9 +285308,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -280647,7 +285337,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -280665,7 +285355,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -280698,21 +285389,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -280731,9 +285424,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -280756,7 +285450,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -280804,17 +285499,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -280835,10 +285530,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -280853,7 +285549,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -280988,7 +285685,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -281005,9 +285702,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -281094,7 +285791,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -281247,7 +285945,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -281300,9 +285998,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -281354,30 +286055,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -281405,10 +286106,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -281429,12 +286132,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -281516,9 +286220,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -281544,7 +286249,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -281562,7 +286267,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -281595,21 +286301,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -281628,9 +286336,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -281653,7 +286362,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -281701,17 +286411,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -281732,10 +286442,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -281750,7 +286461,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -281885,7 +286597,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -281902,9 +286614,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -281991,7 +286703,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -282144,7 +286857,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -282197,9 +286910,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -282251,30 +286967,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -282302,10 +287018,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -282326,12 +287044,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -282413,9 +287132,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -282441,7 +287161,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -282459,7 +287179,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -282492,21 +287213,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -282525,9 +287248,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -282550,7 +287274,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -282598,17 +287323,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -282629,10 +287354,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -282647,7 +287373,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -282782,7 +287509,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -282799,9 +287526,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -282888,7 +287615,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -283041,7 +287769,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -283094,9 +287822,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -283148,30 +287879,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -283199,10 +287930,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -283223,12 +287956,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -283310,9 +288044,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -283338,7 +288073,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -283356,7 +288091,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -283389,21 +288125,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -283422,9 +288160,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -283447,7 +288186,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -283495,17 +288235,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -283526,10 +288266,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -283544,7 +288285,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -283679,7 +288421,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -283696,9 +288438,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -283785,7 +288527,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -283938,7 +288681,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -283991,9 +288734,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -284045,30 +288791,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -284096,10 +288842,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -284120,12 +288868,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -284207,9 +288956,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -284235,7 +288985,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -284253,7 +289003,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -284286,21 +289037,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -284319,9 +289072,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -284344,7 +289098,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -284392,17 +289147,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -284423,10 +289178,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -284441,7 +289197,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -284576,7 +289333,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -284593,9 +289350,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -284682,7 +289439,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -284835,7 +289593,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -284888,9 +289646,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -284942,30 +289703,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -284993,10 +289754,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -285017,12 +289780,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -285104,9 +289868,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -285132,7 +289897,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -285150,7 +289915,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -285183,21 +289949,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -285216,9 +289984,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -285241,7 +290010,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -285289,17 +290059,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -285320,10 +290090,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -285338,7 +290109,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -285473,7 +290245,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -285490,9 +290262,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -285579,7 +290351,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -285732,7 +290505,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -285785,9 +290558,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -285839,30 +290615,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -285890,10 +290666,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -285914,12 +290692,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -286001,9 +290780,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -286029,7 +290809,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -286047,7 +290827,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -286080,21 +290861,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -286113,9 +290896,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -286138,7 +290922,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -286186,17 +290971,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -286217,10 +291002,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -286235,7 +291021,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -286370,7 +291157,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -286387,9 +291174,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -286476,7 +291263,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -286629,7 +291417,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -286682,9 +291470,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -286736,30 +291527,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -286787,10 +291578,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -286811,12 +291604,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -286898,9 +291692,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -286926,7 +291721,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -286944,7 +291739,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -286977,21 +291773,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -287010,9 +291808,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -287035,7 +291834,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -287083,17 +291883,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -287114,10 +291914,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -287132,7 +291933,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -287267,7 +292069,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -287284,9 +292086,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -287373,7 +292175,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -287526,7 +292329,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -287579,9 +292382,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -287633,30 +292439,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -287684,10 +292490,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -287708,12 +292516,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -287795,9 +292604,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -287823,7 +292633,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -287841,7 +292651,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -287874,21 +292685,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -287907,9 +292720,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -287932,7 +292746,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -287980,17 +292795,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -288011,10 +292826,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -288029,7 +292845,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -288164,7 +292981,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -288181,9 +292998,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -288270,7 +293087,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -288423,7 +293241,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -288476,9 +293294,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -288530,30 +293351,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -288581,10 +293402,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -288605,12 +293428,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -288692,9 +293516,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -288720,7 +293545,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -288738,7 +293563,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -288771,21 +293597,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -288804,9 +293632,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -288829,7 +293658,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -288877,17 +293707,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -288908,10 +293738,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -288926,7 +293757,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -289061,7 +293893,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -289078,9 +293910,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -289167,7 +293999,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -289320,7 +294153,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -289373,9 +294206,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -289427,30 +294263,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -289478,10 +294314,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -289502,12 +294340,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -289589,9 +294428,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -289617,7 +294457,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -289635,7 +294475,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -289668,21 +294509,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -289701,9 +294544,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -289726,7 +294570,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -289774,17 +294619,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -289805,10 +294650,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -289823,7 +294669,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -289958,7 +294805,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -289975,9 +294822,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -290064,7 +294911,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -290217,7 +295065,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -290270,9 +295118,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -290324,30 +295175,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -290375,10 +295226,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -290399,12 +295252,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -290486,9 +295340,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -290514,7 +295369,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -290532,7 +295387,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -290565,21 +295421,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -290598,9 +295456,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -290623,7 +295482,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -290671,17 +295531,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -290702,10 +295562,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -290720,7 +295581,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -290855,7 +295717,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -290872,9 +295734,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -290961,7 +295823,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -291114,7 +295977,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -291167,9 +296030,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -291221,30 +296087,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -291272,10 +296138,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -291296,12 +296164,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -291383,9 +296252,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -291411,7 +296281,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -291429,7 +296299,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -291462,21 +296333,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -291495,9 +296368,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -291520,7 +296394,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -291568,17 +296443,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -291599,10 +296474,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -291617,7 +296493,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -291752,7 +296629,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -291769,9 +296646,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -291858,7 +296735,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -292011,7 +296889,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -292064,9 +296942,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -292118,30 +296999,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -292169,10 +297050,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -292193,12 +297076,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -292280,9 +297164,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -292308,7 +297193,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -292326,7 +297211,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -292359,21 +297245,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -292392,9 +297280,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -292417,7 +297306,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -292465,17 +297355,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -292496,10 +297386,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -292514,7 +297405,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -292649,7 +297541,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -292666,9 +297558,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -292755,7 +297647,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -292908,7 +297801,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -292961,9 +297854,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -293015,30 +297911,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -293066,10 +297962,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -293090,12 +297988,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -293177,9 +298076,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -293205,7 +298105,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -293223,7 +298123,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -293256,21 +298157,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -293289,9 +298192,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -293314,7 +298218,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -293362,17 +298267,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -293393,10 +298298,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -293411,7 +298317,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -293546,7 +298453,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -293563,9 +298470,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -293652,7 +298559,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -293805,7 +298713,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -293858,9 +298766,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -293912,30 +298823,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -293963,10 +298874,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -293987,12 +298900,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -294074,9 +298988,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -294102,7 +299017,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -294120,7 +299035,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -294153,21 +299069,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -294186,9 +299104,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -294211,7 +299130,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -294259,17 +299179,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -294290,10 +299210,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -294308,7 +299229,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -294443,7 +299365,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -294460,9 +299382,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -294549,7 +299471,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -294702,7 +299625,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -294755,9 +299678,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -294809,30 +299735,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -294860,10 +299786,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -294884,12 +299812,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -294971,9 +299900,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -294999,7 +299929,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -295017,7 +299947,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -295050,21 +299981,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -295083,9 +300016,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -295108,7 +300042,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -295156,17 +300091,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -295187,10 +300122,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -295205,7 +300141,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -295340,7 +300277,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -295357,9 +300294,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -295446,7 +300383,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -295599,7 +300537,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -295652,9 +300590,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -295706,30 +300647,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -295757,10 +300698,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -295781,12 +300724,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -295868,9 +300812,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -295896,7 +300841,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -295914,7 +300859,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -295947,21 +300893,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -295980,9 +300928,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -296005,7 +300954,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -296053,17 +301003,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -296084,10 +301034,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -296102,7 +301053,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -296237,7 +301189,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -296254,9 +301206,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -296343,7 +301295,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -296496,7 +301449,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -296549,9 +301502,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -296603,30 +301559,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -296654,10 +301610,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -296678,12 +301636,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -296765,9 +301724,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -296793,7 +301753,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -296811,7 +301771,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -296844,21 +301805,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -296877,9 +301840,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -296902,7 +301866,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -296950,17 +301915,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -296981,10 +301946,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -296999,7 +301965,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -297134,7 +302101,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -297151,9 +302118,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -297240,7 +302207,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -297393,7 +302361,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -297446,9 +302414,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -297500,30 +302471,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -297551,10 +302522,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -297575,12 +302548,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -297662,9 +302636,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -297690,7 +302665,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -297708,7 +302683,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -297741,21 +302717,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -297774,9 +302752,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -297799,7 +302778,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -297847,17 +302827,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -297878,10 +302858,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -297896,7 +302877,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -298031,7 +303013,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -298048,9 +303030,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -298137,7 +303119,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -298290,7 +303273,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -298343,9 +303326,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -298397,30 +303383,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -298448,10 +303434,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -298472,12 +303460,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -298559,9 +303548,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -298587,7 +303577,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -298605,7 +303595,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -298638,21 +303629,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -298671,9 +303664,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -298696,7 +303690,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -298744,17 +303739,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -298775,10 +303770,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -298793,7 +303789,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -298928,7 +303925,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -298945,9 +303942,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -299034,7 +304031,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -299187,7 +304185,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -299240,9 +304238,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -299294,30 +304295,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -299345,10 +304346,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -299369,12 +304372,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -299456,9 +304460,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -299484,7 +304489,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -299502,7 +304507,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -299535,21 +304541,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -299568,9 +304576,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -299593,7 +304602,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -299641,17 +304651,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -299672,10 +304682,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -299690,7 +304701,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -299825,7 +304837,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -299842,9 +304854,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -299931,7 +304943,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -300084,7 +305097,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -300137,9 +305150,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -300191,30 +305207,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -300242,10 +305258,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -300266,12 +305284,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -300353,9 +305372,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -300381,7 +305401,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -300399,7 +305419,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -300432,21 +305453,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -300465,9 +305488,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -300490,7 +305514,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -300538,17 +305563,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -300569,10 +305594,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -300587,7 +305613,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -300722,7 +305749,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -300739,9 +305766,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -300828,7 +305855,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -300981,7 +306009,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -301034,9 +306062,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -301088,30 +306119,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -301139,10 +306170,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -301163,12 +306196,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -301250,9 +306284,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -301278,7 +306313,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -301296,7 +306331,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -301329,21 +306365,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -301362,9 +306400,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -301387,7 +306426,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -301435,17 +306475,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -301466,10 +306506,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -301484,7 +306525,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -301619,7 +306661,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -301636,9 +306678,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -301725,7 +306767,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -301878,7 +306921,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -301931,9 +306974,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -301985,30 +307031,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -302036,10 +307082,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -302060,12 +307108,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -302147,9 +307196,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -302175,7 +307225,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -302193,7 +307243,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -302226,21 +307277,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -302259,9 +307312,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -302284,7 +307338,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -302332,17 +307387,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -302363,10 +307418,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -302381,7 +307437,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -302516,7 +307573,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -302533,9 +307590,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -302622,7 +307679,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -302775,7 +307833,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -302828,9 +307886,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -302882,30 +307943,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -302933,10 +307994,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -302957,12 +308020,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -303044,9 +308108,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -303072,7 +308137,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -303090,7 +308155,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -303123,21 +308189,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -303156,9 +308224,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -303181,7 +308250,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -303229,17 +308299,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -303260,10 +308330,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -303278,7 +308349,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -303413,7 +308485,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -303430,9 +308502,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -303519,7 +308591,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -303672,7 +308745,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -303725,9 +308798,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -303779,30 +308855,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -303830,10 +308906,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -303854,12 +308932,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -303941,9 +309020,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -303969,7 +309049,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -303987,7 +309067,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -304020,21 +309101,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -304053,9 +309136,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -304078,7 +309162,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -304126,17 +309211,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -304157,10 +309242,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -304175,7 +309261,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -304310,7 +309397,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -304327,9 +309414,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -304416,7 +309503,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -304569,7 +309657,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -304622,9 +309710,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -304676,30 +309767,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -304727,10 +309818,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -304751,12 +309844,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -304838,9 +309932,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -304866,7 +309961,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -304884,7 +309979,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -304917,21 +310013,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -304950,9 +310048,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -304975,7 +310074,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -305023,17 +310123,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -305054,10 +310154,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -305072,7 +310173,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -305207,7 +310309,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -305224,9 +310326,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -305313,7 +310415,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -305466,7 +310569,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -305519,9 +310622,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -305573,30 +310679,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -305624,10 +310730,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -305648,12 +310756,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -305735,9 +310844,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -305763,7 +310873,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -305781,7 +310891,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -305814,21 +310925,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -305847,9 +310960,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -305872,7 +310986,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -305920,17 +311035,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -305951,10 +311066,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -305969,7 +311085,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -306104,7 +311221,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -306121,9 +311238,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -306210,7 +311327,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -306363,7 +311481,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -306416,9 +311534,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -306470,30 +311591,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -306521,10 +311642,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -306545,12 +311668,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -306632,9 +311756,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -306660,7 +311785,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -306678,7 +311803,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -306711,21 +311837,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -306744,9 +311872,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -306769,7 +311898,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -306817,17 +311947,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -306848,10 +311978,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -306866,7 +311997,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -307001,7 +312133,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -307018,9 +312150,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -307107,7 +312239,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -307260,7 +312393,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -307313,9 +312446,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -307367,30 +312503,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -307418,10 +312554,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -307442,12 +312580,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -307529,9 +312668,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -307557,7 +312697,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -307575,7 +312715,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -307608,21 +312749,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -307641,9 +312784,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -307666,7 +312810,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -307714,17 +312859,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -307745,10 +312890,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -307763,7 +312909,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -307898,7 +313045,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -307915,9 +313062,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -308004,7 +313151,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -308157,7 +313305,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -308210,9 +313358,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -308264,30 +313415,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -308315,10 +313466,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -308339,12 +313492,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -308426,9 +313580,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -308454,7 +313609,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -308472,7 +313627,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -308505,21 +313661,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -308538,9 +313696,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -308563,7 +313722,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -308611,17 +313771,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -308642,10 +313802,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -308660,7 +313821,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -308795,7 +313957,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -308812,9 +313974,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -308901,7 +314063,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -309054,7 +314217,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -309107,9 +314270,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -309161,30 +314327,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -309212,10 +314378,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -309236,12 +314404,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -309323,9 +314492,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -309351,7 +314521,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -309369,7 +314539,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -309402,21 +314573,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -309435,9 +314608,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -309460,7 +314634,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -309508,17 +314683,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -309539,10 +314714,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -309557,7 +314733,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -309692,7 +314869,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -309709,9 +314886,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -309798,7 +314975,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -309951,7 +315129,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -310004,9 +315182,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -310058,30 +315239,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -310109,10 +315290,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -310133,12 +315316,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -310220,9 +315404,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -310248,7 +315433,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -310266,7 +315451,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -310299,21 +315485,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -310332,9 +315520,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -310357,7 +315546,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -310405,17 +315595,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -310436,10 +315626,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -310454,7 +315645,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -310589,7 +315781,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -310606,9 +315798,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -310695,7 +315887,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -310848,7 +316041,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -310901,9 +316094,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -310955,30 +316151,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -311006,10 +316202,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -311030,12 +316228,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -311117,9 +316316,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -311145,7 +316345,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -311163,7 +316363,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -311196,21 +316397,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -311229,9 +316432,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -311254,7 +316458,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -311302,17 +316507,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -311333,10 +316538,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -311351,7 +316557,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -311486,7 +316693,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -311503,9 +316710,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -311592,7 +316799,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -311745,7 +316953,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -311798,9 +317006,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -311852,30 +317063,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -311903,10 +317114,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -311927,12 +317140,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -312014,9 +317228,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -312042,7 +317257,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -312060,7 +317275,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -312093,21 +317309,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -312126,9 +317344,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -312151,7 +317370,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -312199,17 +317419,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -312230,10 +317450,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -312248,7 +317469,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -312383,7 +317605,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -312400,9 +317622,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -312489,7 +317711,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -312642,7 +317865,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -312695,9 +317918,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -312749,30 +317975,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -312800,10 +318026,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -312824,12 +318052,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -312911,9 +318140,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -312939,7 +318169,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -312957,7 +318187,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -312990,21 +318221,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -313023,9 +318256,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -313048,7 +318282,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -313096,17 +318331,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -313127,10 +318362,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -313145,7 +318381,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -313280,7 +318517,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -313297,9 +318534,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -313386,7 +318623,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -313539,7 +318777,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -313592,9 +318830,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -313646,30 +318887,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -313697,10 +318938,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -313721,12 +318964,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -313808,9 +319052,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -313836,7 +319081,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -313854,7 +319099,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -313887,21 +319133,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -313920,9 +319168,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -313945,7 +319194,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -313993,17 +319243,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -314024,10 +319274,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -314042,7 +319293,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -314177,7 +319429,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -314194,9 +319446,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -314283,7 +319535,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -314436,7 +319689,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -314489,9 +319742,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -314543,30 +319799,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -314594,10 +319850,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -314618,12 +319876,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -314705,9 +319964,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -314733,7 +319993,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -314751,7 +320011,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -314784,21 +320045,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -314817,9 +320080,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -314842,7 +320106,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 @@ -314890,17 +320155,17 @@ T1222.002,No,-,0 T1110.001,No,-,0 T1216.001,No,-,0 T1597.002,No,-,0 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,28 -T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,28 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml,29 +T1003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml,29 T1129,No,-,0 T1602,No,-,0 T1561.002,No,-,0 @@ -314921,10 +320186,11 @@ T1590.002,No,-,0 T1501,No,-,0 T1514,No,-,0 T1123,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,5 -T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,5 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,6 +T1543,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,6 T1133,No,-,0 T1109,No,-,0 T1546.006,No,-,0 @@ -314939,7 +320205,8 @@ T1560.003,No,-,0 T1578,No,-,0 T1069,No,-,0 T1114,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_pst_export_alert.yml,4 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,2 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,2 T1596.002,No,-,0 T1542.001,No,-,0 T1594,No,-,0 @@ -315074,7 +320341,7 @@ T1024,No,-,0 T1536,No,-,0 T1091,No,-,0 T1005,No,-,0 -T1140,No,-,0 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,1 T1137.005,No,-,0 T1562,No,-,9 T1586.002,No,-,0 @@ -315091,9 +320358,9 @@ T1583.001,No,-,0 T1560.002,No,-,0 T1055.003,No,-,0 T1079,No,-,0 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,9 -T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,9 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml,10 +T1036,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,10 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security_content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 @@ -315180,7 +320447,8 @@ T1535,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2 T1155,No,-,0 T1563,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_access_user_content_via_powersploit_modules.yml,1 T1027.001,No,-,0 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,1 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,2 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,2 T1484.001,No,-,0 T1217,No,-,0 T1552.004,No,-,0 @@ -315333,7 +320601,7 @@ T1583.006,No,-,0 T1528,No,-,0 T1598.002,No,-,0 T1098.001,No,-,0 -T1204,No,-,3 +T1204,Yes,https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml,4 T1491.001,No,-,0 T1564.002,No,-,0 T1134.003,No,-,0 @@ -315386,9 +320654,12 @@ T1169,No,-,0 T1574.010,No,-,0 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,1 T1199,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_active_directory_infrastructure_via_powersploit_modules.yml,1 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,3 -T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,3 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml,6 +T1136.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml,6 T1069.001,No,-,0 T1149,No,-,0 T1593,No,-,0 @@ -315440,30 +320711,30 @@ T1601,No,-,0 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,4 T1574,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml,4 T1027.005,No,-,0 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,42 -T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,42 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml,44 +T1078,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml,44 T1571,No,-,0 T1585.001,No,-,0 T1073,No,-,0 @@ -315491,10 +320762,12 @@ T1546.004,No,-,0 T1187,No,-,0 T1134.005,No,-,0 T1599,No,-,0 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,4 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,4 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,6 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,6 T1488,No,-,0 T1553,No,-,1 T1548.004,No,-,0 @@ -315515,12 +320788,13 @@ T1593.001,No,-,0 T1546.015,No,-,0 T1589.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml,1 T1195.002,No,-,0 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,6 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,6 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,7 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,7 T1102.002,No,-,0 T1203,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,1 T1137.004,No,-,0 @@ -315602,9 +320876,10 @@ T1146,No,-,0 T1519,No,-,0 T1194,No,-,0 T1200,No,-,0 -T1505,No,-,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,2 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,2 +T1505,No,-,2 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,3 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,3 T1132.002,No,-,0 T1556.001,No,-,0 T1537,No,-,0 @@ -315630,7 +320905,7 @@ T1059.005,No,-,0 T1564.005,No,-,0 T1543.002,No,-,0 T1563.002,No,-,0 -T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,7 +T1136,Yes,https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml,10 T1584.004,No,-,0 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,2 T1526,Yes,https://github.com/splunk/security_content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,2 @@ -315648,7 +320923,8 @@ T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections T1550.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___detect_pass_hash.yml,2 T1052,No,-,0 T1574.002,No,-,0 -T1105,No,-,0 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,2 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,2 T1098.002,No,-,0 T1588.003,No,-,0 T1126,No,-,0 @@ -315681,21 +320957,23 @@ T1204.001,No,-,0 T1550.001,No,-,0 T1547.008,No,-,0 T1569.002,No,-,0 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,15 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,15 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,17 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,17 T1480.001,No,-,0 T1008,No,-,0 T1564.004,No,-,0 @@ -315714,9 +320992,10 @@ T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/o36 T1556,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml,3 T1056.004,No,-,0 T1495,No,-,0 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,3 -T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,3 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml,4 +T1490,Yes,https://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml,4 T1546.007,No,-,0 T1566.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1090.001,No,-,0 @@ -315739,7 +321018,8 @@ T1574.004,No,-,0 T1601.002,No,-,0 T1078.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,1 T1211,No,-,0 -T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,4 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,5 +T1127,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml,5 T1529,No,-,0 T1077,No,-,0 T1574.012,No,-,0 diff --git a/docs/mitre-map/coverage.json b/docs/mitre-map/coverage.json index f06fce047f..211697bea2 100644 --- a/docs/mitre-map/coverage.json +++ b/docs/mitre-map/coverage.json @@ -54,7 +54,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -83,8 +83,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -108,8 +108,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -296,7 +296,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -324,7 +328,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -444,8 +448,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -635,7 +639,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -723,8 +731,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -792,7 +800,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -832,8 +840,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -867,8 +875,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -981,8 +989,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -1020,7 +1028,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -1057,7 +1065,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -1096,8 +1108,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -1124,8 +1136,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -1160,8 +1172,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -1216,7 +1228,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -1245,8 +1257,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -1270,8 +1282,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -1458,7 +1470,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -1486,7 +1502,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -1606,8 +1622,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -1797,7 +1813,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -1885,8 +1905,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -1954,7 +1974,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -1994,8 +2014,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -2029,8 +2049,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -2143,8 +2163,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -2182,7 +2202,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -2219,7 +2239,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -2258,8 +2282,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -2286,8 +2310,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -2322,8 +2346,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -2378,7 +2402,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -2407,8 +2431,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -2432,8 +2456,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -2620,7 +2644,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -2648,7 +2676,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -2768,8 +2796,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -2959,7 +2987,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -3047,8 +3079,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -3116,7 +3148,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -3156,8 +3188,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -3191,8 +3223,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -3305,8 +3337,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -3344,7 +3376,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -3381,7 +3413,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -3420,8 +3456,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -3448,8 +3484,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -3484,8 +3520,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -3540,7 +3576,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -3569,8 +3605,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -3594,8 +3630,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -3782,7 +3818,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -3810,7 +3850,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -3930,8 +3970,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -4121,7 +4161,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -4209,8 +4253,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -4278,7 +4322,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -4318,8 +4362,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -4353,8 +4397,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -4467,8 +4511,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -4506,7 +4550,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -4543,7 +4587,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -4582,8 +4630,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -4610,8 +4658,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -4646,8 +4694,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -4702,7 +4750,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -4731,8 +4779,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -4756,8 +4804,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -4944,7 +4992,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -4972,7 +5024,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -5092,8 +5144,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -5283,7 +5335,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -5371,8 +5427,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -5440,7 +5496,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -5480,8 +5536,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -5515,8 +5571,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -5629,8 +5685,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -5668,7 +5724,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -5705,7 +5761,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -5744,8 +5804,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -5772,8 +5832,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -5808,8 +5868,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -5864,7 +5924,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -5893,8 +5953,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -5918,8 +5978,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -6106,7 +6166,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -6134,7 +6198,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -6254,8 +6318,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -6445,7 +6509,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -6533,8 +6601,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -6602,7 +6670,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -6642,8 +6710,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -6677,8 +6745,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -6791,8 +6859,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -6830,7 +6898,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -6867,7 +6935,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -6906,8 +6978,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -6934,8 +7006,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -6970,8 +7042,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -7026,7 +7098,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -7055,8 +7127,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -7080,8 +7152,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -7268,7 +7340,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -7296,7 +7372,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -7416,8 +7492,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -7607,7 +7683,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -7695,8 +7775,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -7764,7 +7844,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -7804,8 +7884,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -7839,8 +7919,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -7953,8 +8033,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -7992,7 +8072,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -8029,7 +8109,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -8068,8 +8152,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -8096,8 +8180,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -8132,8 +8216,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -8188,7 +8272,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -8217,8 +8301,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -8242,8 +8326,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -8430,7 +8514,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -8458,7 +8546,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -8578,8 +8666,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -8769,7 +8857,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -8857,8 +8949,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -8926,7 +9018,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -8966,8 +9058,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -9001,8 +9093,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -9115,8 +9207,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -9154,7 +9246,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -9191,7 +9283,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -9230,8 +9326,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -9258,8 +9354,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -9294,8 +9390,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -9350,7 +9446,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -9379,8 +9475,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -9404,8 +9500,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -9592,7 +9688,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -9620,7 +9720,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -9740,8 +9840,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -9931,7 +10031,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -10019,8 +10123,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -10088,7 +10192,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -10128,8 +10232,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -10163,8 +10267,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -10277,8 +10381,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -10316,7 +10420,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -10353,7 +10457,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -10392,8 +10500,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -10420,8 +10528,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -10456,8 +10564,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -10512,7 +10620,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -10541,8 +10649,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -10566,8 +10674,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -10754,7 +10862,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -10782,7 +10894,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -10902,8 +11014,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -11093,7 +11205,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -11181,8 +11297,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -11250,7 +11366,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -11290,8 +11406,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -11325,8 +11441,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -11439,8 +11555,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -11478,7 +11594,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -11515,7 +11631,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -11554,8 +11674,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -11582,8 +11702,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -11618,8 +11738,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -11674,7 +11794,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -11703,8 +11823,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -11728,8 +11848,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -11916,7 +12036,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -11944,7 +12068,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -12064,8 +12188,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -12255,7 +12379,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -12343,8 +12471,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -12412,7 +12540,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -12452,8 +12580,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -12487,8 +12615,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -12601,8 +12729,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -12640,7 +12768,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -12677,7 +12805,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -12716,8 +12848,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -12744,8 +12876,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -12780,8 +12912,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -12836,7 +12968,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -12865,8 +12997,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -12890,8 +13022,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -13078,7 +13210,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -13106,7 +13242,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -13226,8 +13362,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -13417,7 +13553,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -13505,8 +13645,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -13574,7 +13714,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -13614,8 +13754,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -13649,8 +13789,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -13763,8 +13903,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -13802,7 +13942,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -13839,7 +13979,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -13878,8 +14022,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -13906,8 +14050,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -13942,8 +14086,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -13998,7 +14142,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -14027,8 +14171,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -14052,8 +14196,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -14240,7 +14384,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -14268,7 +14416,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -14388,8 +14536,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -14579,7 +14727,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -14667,8 +14819,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -14736,7 +14888,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -14776,8 +14928,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -14811,8 +14963,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -14925,8 +15077,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -14964,7 +15116,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -15001,7 +15153,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -15040,8 +15196,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -15068,8 +15224,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -15104,8 +15260,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -15160,7 +15316,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -15189,8 +15345,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -15214,8 +15370,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -15402,7 +15558,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -15430,7 +15590,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -15550,8 +15710,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -15741,7 +15901,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -15829,8 +15993,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -15898,7 +16062,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -15938,8 +16102,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -15973,8 +16137,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -16087,8 +16251,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -16126,7 +16290,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -16163,7 +16327,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -16202,8 +16370,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -16230,8 +16398,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -16266,8 +16434,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -16322,7 +16490,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -16351,8 +16519,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -16376,8 +16544,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -16564,7 +16732,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -16592,7 +16764,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -16712,8 +16884,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -16903,7 +17075,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -16991,8 +17167,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -17060,7 +17236,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -17100,8 +17276,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -17135,8 +17311,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -17249,8 +17425,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -17288,7 +17464,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -17325,7 +17501,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -17364,8 +17544,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -17392,8 +17572,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -17428,8 +17608,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -17484,7 +17664,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -17513,8 +17693,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -17538,8 +17718,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -17726,7 +17906,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -17754,7 +17938,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -17874,8 +18058,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -18065,7 +18249,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -18153,8 +18341,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -18222,7 +18410,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -18262,8 +18450,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -18297,8 +18485,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -18411,8 +18599,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -18450,7 +18638,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -18487,7 +18675,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -18526,8 +18718,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -18554,8 +18746,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -18590,8 +18782,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -18646,7 +18838,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -18675,8 +18867,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -18700,8 +18892,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -18888,7 +19080,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -18916,7 +19112,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -19036,8 +19232,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -19227,7 +19423,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -19315,8 +19515,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -19384,7 +19584,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -19424,8 +19624,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -19459,8 +19659,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -19573,8 +19773,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -19612,7 +19812,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -19649,7 +19849,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -19688,8 +19892,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -19716,8 +19920,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -19752,8 +19956,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -19808,7 +20012,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -19837,8 +20041,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -19862,8 +20066,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -20050,7 +20254,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -20078,7 +20286,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -20198,8 +20406,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -20389,7 +20597,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -20477,8 +20689,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -20546,7 +20758,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -20586,8 +20798,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -20621,8 +20833,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -20735,8 +20947,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -20774,7 +20986,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -20811,7 +21023,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -20850,8 +21066,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -20878,8 +21094,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -20914,8 +21130,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -20970,7 +21186,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -20999,8 +21215,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -21024,8 +21240,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -21212,7 +21428,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -21240,7 +21460,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -21360,8 +21580,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -21551,7 +21771,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -21639,8 +21863,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -21708,7 +21932,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -21748,8 +21972,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -21783,8 +22007,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -21897,8 +22121,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -21936,7 +22160,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -21973,7 +22197,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -22012,8 +22240,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -22040,8 +22268,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -22076,8 +22304,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -22132,7 +22360,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -22161,8 +22389,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -22186,8 +22414,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -22374,7 +22602,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -22402,7 +22634,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -22522,8 +22754,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -22713,7 +22945,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -22801,8 +23037,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -22870,7 +23106,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -22910,8 +23146,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -22945,8 +23181,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -23059,8 +23295,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -23098,7 +23334,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -23135,7 +23371,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -23174,8 +23414,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -23202,8 +23442,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -23238,8 +23478,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -23294,7 +23534,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -23323,8 +23563,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -23348,8 +23588,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -23536,7 +23776,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -23564,7 +23808,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -23684,8 +23928,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -23875,7 +24119,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -23963,8 +24211,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -24032,7 +24280,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -24072,8 +24320,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -24107,8 +24355,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -24221,8 +24469,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -24260,7 +24508,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -24297,7 +24545,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -24336,8 +24588,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -24364,8 +24616,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -24400,8 +24652,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -24456,7 +24708,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -24485,8 +24737,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -24510,8 +24762,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -24698,7 +24950,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -24726,7 +24982,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -24846,8 +25102,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -25037,7 +25293,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -25125,8 +25385,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -25194,7 +25454,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -25234,8 +25494,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -25269,8 +25529,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -25383,8 +25643,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -25422,7 +25682,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -25459,7 +25719,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -25498,8 +25762,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -25526,8 +25790,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -25562,8 +25826,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -25618,7 +25882,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -25647,8 +25911,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -25672,8 +25936,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -25860,7 +26124,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -25888,7 +26156,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -26008,8 +26276,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -26199,7 +26467,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -26287,8 +26559,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -26356,7 +26628,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -26396,8 +26668,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -26431,8 +26703,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -26545,8 +26817,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -26584,7 +26856,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -26621,7 +26893,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -26660,8 +26936,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -26688,8 +26964,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -26724,8 +27000,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -26780,7 +27056,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -26809,8 +27085,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -26834,8 +27110,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -27022,7 +27298,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -27050,7 +27330,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -27170,8 +27450,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -27361,7 +27641,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -27449,8 +27733,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -27518,7 +27802,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -27558,8 +27842,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -27593,8 +27877,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -27707,8 +27991,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -27746,7 +28030,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -27783,7 +28067,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -27822,8 +28110,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -27850,8 +28138,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -27886,8 +28174,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -27942,7 +28230,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -27971,8 +28259,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -27996,8 +28284,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -28184,7 +28472,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -28212,7 +28504,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -28332,8 +28624,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -28523,7 +28815,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -28611,8 +28907,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -28680,7 +28976,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -28720,8 +29016,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -28755,8 +29051,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -28869,8 +29165,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -28908,7 +29204,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -28945,7 +29241,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -28984,8 +29284,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -29012,8 +29312,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -29048,8 +29348,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -29104,7 +29404,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -29133,8 +29433,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -29158,8 +29458,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -29346,7 +29646,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -29374,7 +29678,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -29494,8 +29798,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -29685,7 +29989,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -29773,8 +30081,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -29842,7 +30150,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -29882,8 +30190,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -29917,8 +30225,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -30031,8 +30339,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -30070,7 +30378,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -30107,7 +30415,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -30146,8 +30458,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -30174,8 +30486,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -30210,8 +30522,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -30266,7 +30578,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -30295,8 +30607,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -30320,8 +30632,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -30508,7 +30820,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -30536,7 +30852,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -30656,8 +30972,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -30847,7 +31163,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -30935,8 +31255,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -31004,7 +31324,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -31044,8 +31364,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -31079,8 +31399,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -31193,8 +31513,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -31232,7 +31552,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -31269,7 +31589,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -31308,8 +31632,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -31336,8 +31660,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -31372,8 +31696,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -31428,7 +31752,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -31457,8 +31781,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -31482,8 +31806,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -31670,7 +31994,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -31698,7 +32026,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -31818,8 +32146,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -32009,7 +32337,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -32097,8 +32429,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -32166,7 +32498,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -32206,8 +32538,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -32241,8 +32573,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -32355,8 +32687,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -32394,7 +32726,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -32431,7 +32763,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -32470,8 +32806,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -32498,8 +32834,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -32534,8 +32870,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -32590,7 +32926,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -32619,8 +32955,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -32644,8 +32980,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -32832,7 +33168,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -32860,7 +33200,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -32980,8 +33320,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -33171,7 +33511,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -33259,8 +33603,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -33328,7 +33672,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -33368,8 +33712,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -33403,8 +33747,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -33517,8 +33861,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -33556,7 +33900,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -33593,7 +33937,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -33632,8 +33980,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -33660,8 +34008,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -33696,8 +34044,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -33752,7 +34100,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -33781,8 +34129,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -33806,8 +34154,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -33994,7 +34342,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -34022,7 +34374,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -34142,8 +34494,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -34333,7 +34685,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -34421,8 +34777,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -34490,7 +34846,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -34530,8 +34886,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -34565,8 +34921,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -34679,8 +35035,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -34718,7 +35074,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -34755,7 +35111,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -34794,8 +35154,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -34822,8 +35182,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -34858,8 +35218,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -34914,7 +35274,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -34943,8 +35303,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -34968,8 +35328,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -35156,7 +35516,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -35184,7 +35548,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -35304,8 +35668,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -35495,7 +35859,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -35583,8 +35951,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -35652,7 +36020,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -35692,8 +36060,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -35727,8 +36095,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -35841,8 +36209,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -35880,7 +36248,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -35917,7 +36285,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -35956,8 +36328,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -35984,8 +36356,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -36020,8 +36392,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -36076,7 +36448,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -36105,8 +36477,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -36130,8 +36502,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -36318,7 +36690,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -36346,7 +36722,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -36466,8 +36842,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -36657,7 +37033,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -36745,8 +37125,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -36814,7 +37194,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -36854,8 +37234,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -36889,8 +37269,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -37003,8 +37383,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -37042,7 +37422,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -37079,7 +37459,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -37118,8 +37502,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -37146,8 +37530,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -37182,8 +37566,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -37238,7 +37622,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -37267,8 +37651,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -37292,8 +37676,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -37480,7 +37864,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -37508,7 +37896,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -37628,8 +38016,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -37819,7 +38207,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -37907,8 +38299,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -37976,7 +38368,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -38016,8 +38408,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -38051,8 +38443,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -38165,8 +38557,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -38204,7 +38596,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -38241,7 +38633,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -38280,8 +38676,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -38308,8 +38704,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -38344,8 +38740,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -38400,7 +38796,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -38429,8 +38825,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -38454,8 +38850,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -38642,7 +39038,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -38670,7 +39070,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -38790,8 +39190,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -38981,7 +39381,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -39069,8 +39473,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -39138,7 +39542,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -39178,8 +39582,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -39213,8 +39617,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -39327,8 +39731,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -39366,7 +39770,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -39403,7 +39807,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -39442,8 +39850,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -39470,8 +39878,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -39506,8 +39914,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -39562,7 +39970,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -39591,8 +39999,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -39616,8 +40024,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -39804,7 +40212,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -39832,7 +40244,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -39952,8 +40364,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -40143,7 +40555,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -40231,8 +40647,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -40300,7 +40716,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -40340,8 +40756,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -40375,8 +40791,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -40489,8 +40905,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -40528,7 +40944,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -40565,7 +40981,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -40604,8 +41024,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -40632,8 +41052,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -40668,8 +41088,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -40724,7 +41144,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -40753,8 +41173,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -40778,8 +41198,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -40966,7 +41386,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -40994,7 +41418,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -41114,8 +41538,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -41305,7 +41729,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -41393,8 +41821,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -41462,7 +41890,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -41502,8 +41930,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -41537,8 +41965,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -41651,8 +42079,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -41690,7 +42118,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -41727,7 +42155,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -41766,8 +42198,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -41794,8 +42226,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -41830,8 +42262,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -41886,7 +42318,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -41915,8 +42347,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -41940,8 +42372,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -42128,7 +42560,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -42156,7 +42592,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -42276,8 +42712,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -42467,7 +42903,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -42555,8 +42995,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -42624,7 +43064,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -42664,8 +43104,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -42699,8 +43139,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -42813,8 +43253,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -42852,7 +43292,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -42889,7 +43329,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -42928,8 +43372,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -42956,8 +43400,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -42992,8 +43436,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -43048,7 +43492,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -43077,8 +43521,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -43102,8 +43546,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -43290,7 +43734,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -43318,7 +43766,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -43438,8 +43886,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -43629,7 +44077,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -43717,8 +44169,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -43786,7 +44238,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -43826,8 +44278,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -43861,8 +44313,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -43975,8 +44427,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -44014,7 +44466,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -44051,7 +44503,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -44090,8 +44546,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -44118,8 +44574,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -44154,8 +44610,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -44210,7 +44666,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -44239,8 +44695,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -44264,8 +44720,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -44452,7 +44908,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -44480,7 +44940,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -44600,8 +45060,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -44791,7 +45251,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -44879,8 +45343,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -44948,7 +45412,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -44988,8 +45452,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -45023,8 +45487,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -45137,8 +45601,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -45176,7 +45640,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -45213,7 +45677,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -45252,8 +45720,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -45280,8 +45748,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -45316,8 +45784,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -45372,7 +45840,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -45401,8 +45869,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -45426,8 +45894,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -45614,7 +46082,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -45642,7 +46114,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -45762,8 +46234,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -45953,7 +46425,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -46041,8 +46517,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -46110,7 +46586,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -46150,8 +46626,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -46185,8 +46661,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -46299,8 +46775,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -46338,7 +46814,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -46375,7 +46851,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -46414,8 +46894,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -46442,8 +46922,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -46478,8 +46958,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -46534,7 +47014,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -46563,8 +47043,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -46588,8 +47068,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -46776,7 +47256,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -46804,7 +47288,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -46924,8 +47408,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -47115,7 +47599,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -47203,8 +47691,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -47272,7 +47760,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -47312,8 +47800,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -47347,8 +47835,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -47461,8 +47949,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -47500,7 +47988,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -47537,7 +48025,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -47576,8 +48068,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -47604,8 +48096,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -47640,8 +48132,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -47696,7 +48188,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -47725,8 +48217,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -47750,8 +48242,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -47938,7 +48430,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -47966,7 +48462,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -48086,8 +48582,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -48277,7 +48773,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -48365,8 +48865,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -48434,7 +48934,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -48474,8 +48974,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -48509,8 +49009,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -48623,8 +49123,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -48662,7 +49162,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -48699,7 +49199,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -48738,8 +49242,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -48766,8 +49270,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -48802,8 +49306,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -48858,7 +49362,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -48887,8 +49391,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -48912,8 +49416,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -49100,7 +49604,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -49128,7 +49636,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -49248,8 +49756,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -49439,7 +49947,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -49527,8 +50039,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -49596,7 +50108,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -49636,8 +50148,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -49671,8 +50183,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -49785,8 +50297,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -49824,7 +50336,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -49861,7 +50373,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -49900,8 +50416,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -49928,8 +50444,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -49964,8 +50480,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -50020,7 +50536,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -50049,8 +50565,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -50074,8 +50590,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -50262,7 +50778,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -50290,7 +50810,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -50410,8 +50930,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -50601,7 +51121,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -50689,8 +51213,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -50758,7 +51282,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -50798,8 +51322,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -50833,8 +51357,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -50947,8 +51471,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -50986,7 +51510,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -51023,7 +51547,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -51062,8 +51590,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -51090,8 +51618,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -51126,8 +51654,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -51182,7 +51710,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -51211,8 +51739,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -51236,8 +51764,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -51424,7 +51952,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -51452,7 +51984,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -51572,8 +52104,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -51763,7 +52295,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -51851,8 +52387,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -51920,7 +52456,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -51960,8 +52496,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -51995,8 +52531,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -52109,8 +52645,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -52148,7 +52684,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -52185,7 +52721,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -52224,8 +52764,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -52252,8 +52792,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -52288,8 +52828,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -52344,7 +52884,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -52373,8 +52913,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -52398,8 +52938,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -52586,7 +53126,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -52614,7 +53158,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -52734,8 +53278,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -52925,7 +53469,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -53013,8 +53561,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -53082,7 +53630,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -53122,8 +53670,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -53157,8 +53705,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -53271,8 +53819,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -53310,7 +53858,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -53347,7 +53895,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -53386,8 +53938,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -53414,8 +53966,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -53450,8 +54002,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -53506,7 +54058,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -53535,8 +54087,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -53560,8 +54112,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -53748,7 +54300,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -53776,7 +54332,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -53896,8 +54452,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -54087,7 +54643,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -54175,8 +54735,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -54244,7 +54804,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -54284,8 +54844,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -54319,8 +54879,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -54433,8 +54993,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -54472,7 +55032,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -54509,7 +55069,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -54548,8 +55112,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -54576,8 +55140,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -54612,8 +55176,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -54668,7 +55232,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -54697,8 +55261,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -54722,8 +55286,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -54910,7 +55474,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -54938,7 +55506,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -55058,8 +55626,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -55249,7 +55817,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -55337,8 +55909,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -55406,7 +55978,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -55446,8 +56018,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -55481,8 +56053,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -55595,8 +56167,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -55634,7 +56206,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -55671,7 +56243,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -55710,8 +56286,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -55738,8 +56314,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -55774,8 +56350,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -55830,7 +56406,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -55859,8 +56435,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -55884,8 +56460,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -56072,7 +56648,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -56100,7 +56680,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -56220,8 +56800,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -56411,7 +56991,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -56499,8 +57083,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -56568,7 +57152,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -56608,8 +57192,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -56643,8 +57227,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -56757,8 +57341,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -56796,7 +57380,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -56833,7 +57417,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -56872,8 +57460,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -56900,8 +57488,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -56936,8 +57524,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -56992,7 +57580,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -57021,8 +57609,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -57046,8 +57634,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -57234,7 +57822,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -57262,7 +57854,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -57382,8 +57974,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -57573,7 +58165,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -57661,8 +58257,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -57730,7 +58326,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -57770,8 +58366,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -57805,8 +58401,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -57919,8 +58515,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -57958,7 +58554,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -57995,7 +58591,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -58034,8 +58634,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -58062,8 +58662,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -58098,8 +58698,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -58154,7 +58754,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -58183,8 +58783,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -58208,8 +58808,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -58396,7 +58996,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -58424,7 +59028,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -58544,8 +59148,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -58735,7 +59339,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -58823,8 +59431,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -58892,7 +59500,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -58932,8 +59540,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -58967,8 +59575,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -59081,8 +59689,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -59120,7 +59728,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -59157,7 +59765,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -59196,8 +59808,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -59224,8 +59836,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -59260,8 +59872,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -59316,7 +59928,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -59345,8 +59957,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -59370,8 +59982,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -59558,7 +60170,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -59586,7 +60202,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -59706,8 +60322,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -59897,7 +60513,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -59985,8 +60605,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -60054,7 +60674,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -60094,8 +60714,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -60129,8 +60749,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -60243,8 +60863,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -60282,7 +60902,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -60319,7 +60939,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -60358,8 +60982,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -60386,8 +61010,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -60422,8 +61046,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -60478,7 +61102,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -60507,8 +61131,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -60532,8 +61156,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -60720,7 +61344,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -60748,7 +61376,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -60868,8 +61496,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -61059,7 +61687,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -61147,8 +61779,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -61216,7 +61848,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -61256,8 +61888,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -61291,8 +61923,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -61405,8 +62037,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -61444,7 +62076,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -61481,7 +62113,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -61520,8 +62156,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -61548,8 +62184,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -61584,8 +62220,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -61640,7 +62276,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -61669,8 +62305,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -61694,8 +62330,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -61882,7 +62518,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -61910,7 +62550,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -62030,8 +62670,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -62221,7 +62861,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -62309,8 +62953,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -62378,7 +63022,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -62418,8 +63062,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -62453,8 +63097,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -62567,8 +63211,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -62606,7 +63250,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -62643,7 +63287,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -62682,8 +63330,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -62710,8 +63358,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -62746,8 +63394,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -62802,7 +63450,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -62831,8 +63479,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -62856,8 +63504,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -63044,7 +63692,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -63072,7 +63724,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -63192,8 +63844,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -63383,7 +64035,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -63471,8 +64127,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -63540,7 +64196,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -63580,8 +64236,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -63615,8 +64271,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -63729,8 +64385,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -63768,7 +64424,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -63805,7 +64461,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -63844,8 +64504,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -63872,8 +64532,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -63908,8 +64568,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -63964,7 +64624,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -63993,8 +64653,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -64018,8 +64678,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -64206,7 +64866,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -64234,7 +64898,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -64354,8 +65018,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -64545,7 +65209,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -64633,8 +65301,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -64702,7 +65370,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -64742,8 +65410,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -64777,8 +65445,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -64891,8 +65559,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -64930,7 +65598,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -64967,7 +65635,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -65006,8 +65678,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -65034,8 +65706,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -65070,8 +65742,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -65126,7 +65798,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -65155,8 +65827,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -65180,8 +65852,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -65368,7 +66040,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -65396,7 +66072,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -65516,8 +66192,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -65707,7 +66383,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -65795,8 +66475,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -65864,7 +66544,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -65904,8 +66584,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -65939,8 +66619,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -66053,8 +66733,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -66092,7 +66772,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -66129,7 +66809,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -66168,8 +66852,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -66196,8 +66880,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -66232,8 +66916,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -66288,7 +66972,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -66317,8 +67001,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -66342,8 +67026,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -66530,7 +67214,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -66558,7 +67246,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -66678,8 +67366,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -66869,7 +67557,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -66957,8 +67649,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -67026,7 +67718,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -67066,8 +67758,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -67101,8 +67793,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -67215,8 +67907,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -67254,7 +67946,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -67291,7 +67983,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -67330,8 +68026,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -67358,8 +68054,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -67394,8 +68090,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -67450,7 +68146,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -67479,8 +68175,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -67504,8 +68200,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -67692,7 +68388,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -67720,7 +68420,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -67840,8 +68540,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -68031,7 +68731,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -68119,8 +68823,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -68188,7 +68892,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -68228,8 +68932,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -68263,8 +68967,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -68377,8 +69081,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -68416,7 +69120,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -68453,7 +69157,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -68492,8 +69200,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -68520,8 +69228,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -68556,8 +69264,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -68612,7 +69320,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -68641,8 +69349,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -68666,8 +69374,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -68854,7 +69562,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -68882,7 +69594,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -69002,8 +69714,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -69193,7 +69905,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -69281,8 +69997,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -69350,7 +70066,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -69390,8 +70106,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -69425,8 +70141,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -69539,8 +70255,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -69578,7 +70294,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -69615,7 +70331,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -69654,8 +70374,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -69682,8 +70402,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -69718,8 +70438,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -69774,7 +70494,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -69803,8 +70523,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -69828,8 +70548,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -70016,7 +70736,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -70044,7 +70768,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -70164,8 +70888,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -70355,7 +71079,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -70443,8 +71171,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -70512,7 +71240,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -70552,8 +71280,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -70587,8 +71315,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -70701,8 +71429,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -70740,7 +71468,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -70777,7 +71505,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -70816,8 +71548,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -70844,8 +71576,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -70880,8 +71612,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -70936,7 +71668,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -70965,8 +71697,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -70990,8 +71722,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -71178,7 +71910,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -71206,7 +71942,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -71326,8 +72062,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -71517,7 +72253,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -71605,8 +72345,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -71674,7 +72414,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -71714,8 +72454,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -71749,8 +72489,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -71863,8 +72603,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -71902,7 +72642,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -71939,7 +72679,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -71978,8 +72722,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -72006,8 +72750,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -72042,8 +72786,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -72098,7 +72842,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -72127,8 +72871,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -72152,8 +72896,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -72340,7 +73084,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -72368,7 +73116,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -72488,8 +73236,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -72679,7 +73427,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -72767,8 +73519,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -72836,7 +73588,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -72876,8 +73628,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -72911,8 +73663,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -73025,8 +73777,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -73064,7 +73816,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -73101,7 +73853,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -73140,8 +73896,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -73168,8 +73924,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -73204,8 +73960,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -73260,7 +74016,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -73289,8 +74045,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -73314,8 +74070,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -73502,7 +74258,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -73530,7 +74290,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -73650,8 +74410,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -73841,7 +74601,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -73929,8 +74693,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -73998,7 +74762,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -74038,8 +74802,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -74073,8 +74837,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -74187,8 +74951,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -74226,7 +74990,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -74263,7 +75027,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -74302,8 +75070,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -74330,8 +75098,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -74366,8 +75134,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -74422,7 +75190,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -74451,8 +75219,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -74476,8 +75244,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -74664,7 +75432,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -74692,7 +75464,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -74812,8 +75584,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -75003,7 +75775,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -75091,8 +75867,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -75160,7 +75936,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -75200,8 +75976,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -75235,8 +76011,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -75349,8 +76125,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -75388,7 +76164,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -75425,7 +76201,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -75464,8 +76244,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -75492,8 +76272,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -75528,8 +76308,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -75584,7 +76364,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -75613,8 +76393,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -75638,8 +76418,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -75826,7 +76606,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -75854,7 +76638,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -75974,8 +76758,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -76165,7 +76949,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -76253,8 +77041,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -76322,7 +77110,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -76362,8 +77150,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -76397,8 +77185,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -76511,8 +77299,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -76550,7 +77338,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -76587,7 +77375,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -76626,8 +77418,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -76654,8 +77446,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -76690,8 +77482,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -76746,7 +77538,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -76775,8 +77567,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -76800,8 +77592,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -76988,7 +77780,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -77016,7 +77812,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -77136,8 +77932,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -77327,7 +78123,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -77415,8 +78215,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -77484,7 +78284,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -77524,8 +78324,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -77559,8 +78359,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -77673,8 +78473,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -77712,7 +78512,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -77749,7 +78549,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -77788,8 +78592,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -77816,8 +78620,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -77852,8 +78656,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -77908,7 +78712,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -77937,8 +78741,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -77962,8 +78766,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -78150,7 +78954,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -78178,7 +78986,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -78298,8 +79106,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -78489,7 +79297,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -78577,8 +79389,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -78646,7 +79458,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -78686,8 +79498,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -78721,8 +79533,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -78835,8 +79647,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -78874,7 +79686,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -78911,7 +79723,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -78950,8 +79766,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -78978,8 +79794,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -79014,8 +79830,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -79070,7 +79886,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -79099,8 +79915,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -79124,8 +79940,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -79312,7 +80128,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -79340,7 +80160,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -79460,8 +80280,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -79651,7 +80471,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -79739,8 +80563,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -79808,7 +80632,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -79848,8 +80672,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -79883,8 +80707,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -79997,8 +80821,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -80036,7 +80860,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -80073,7 +80897,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -80112,8 +80940,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -80140,8 +80968,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -80176,8 +81004,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -80232,7 +81060,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -80261,8 +81089,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -80286,8 +81114,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -80474,7 +81302,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -80502,7 +81334,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -80622,8 +81454,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -80813,7 +81645,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -80901,8 +81737,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -80970,7 +81806,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -81010,8 +81846,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -81045,8 +81881,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -81159,8 +81995,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -81198,7 +82034,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -81235,7 +82071,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -81274,8 +82114,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -81302,8 +82142,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -81338,8 +82178,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -81394,7 +82234,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -81423,8 +82263,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -81448,8 +82288,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -81636,7 +82476,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -81664,7 +82508,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -81784,8 +82628,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -81975,7 +82819,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -82063,8 +82911,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -82132,7 +82980,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -82172,8 +83020,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -82207,8 +83055,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -82321,8 +83169,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -82360,7 +83208,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -82397,7 +83245,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -82436,8 +83288,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -82464,8 +83316,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -82500,8 +83352,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -82556,7 +83408,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -82585,8 +83437,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -82610,8 +83462,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -82798,7 +83650,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -82826,7 +83682,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -82946,8 +83802,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -83137,7 +83993,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -83225,8 +84085,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -83294,7 +84154,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -83334,8 +84194,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -83369,8 +84229,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -83483,8 +84343,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -83522,7 +84382,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -83559,7 +84419,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -83598,8 +84462,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -83626,8 +84490,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -83662,8 +84526,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -83718,7 +84582,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -83747,8 +84611,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -83772,8 +84636,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -83960,7 +84824,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -83988,7 +84856,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -84108,8 +84976,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -84299,7 +85167,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -84387,8 +85259,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -84456,7 +85328,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -84496,8 +85368,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -84531,8 +85403,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -84645,8 +85517,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -84684,7 +85556,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -84721,7 +85593,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -84760,8 +85636,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -84788,8 +85664,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -84824,8 +85700,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -84880,7 +85756,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -84909,8 +85785,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -84934,8 +85810,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -85122,7 +85998,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -85150,7 +86030,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -85270,8 +86150,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -85461,7 +86341,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -85549,8 +86433,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -85618,7 +86502,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -85658,8 +86542,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -85693,8 +86577,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -85807,8 +86691,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -85846,7 +86730,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -85883,7 +86767,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -85922,8 +86810,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -85950,8 +86838,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -85986,8 +86874,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -86042,7 +86930,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -86071,8 +86959,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -86096,8 +86984,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -86284,7 +87172,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -86312,7 +87204,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -86432,8 +87324,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -86623,7 +87515,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -86711,8 +87607,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -86780,7 +87676,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -86820,8 +87716,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -86855,8 +87751,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -86969,8 +87865,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -87008,7 +87904,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -87045,7 +87941,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -87084,8 +87984,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -87112,8 +88012,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -87148,8 +88048,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -87204,7 +88104,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -87233,8 +88133,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -87258,8 +88158,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -87446,7 +88346,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -87474,7 +88378,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -87594,8 +88498,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -87785,7 +88689,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -87873,8 +88781,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -87942,7 +88850,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -87982,8 +88890,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -88017,8 +88925,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -88131,8 +89039,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -88170,7 +89078,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -88207,7 +89115,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -88246,8 +89158,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -88274,8 +89186,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -88310,8 +89222,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -88366,7 +89278,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -88395,8 +89307,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -88420,8 +89332,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -88608,7 +89520,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -88636,7 +89552,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -88756,8 +89672,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -88947,7 +89863,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -89035,8 +89955,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -89104,7 +90024,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -89144,8 +90064,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -89179,8 +90099,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -89293,8 +90213,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -89332,7 +90252,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -89369,7 +90289,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -89408,8 +90332,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -89436,8 +90360,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -89472,8 +90396,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -89528,7 +90452,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -89557,8 +90481,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -89582,8 +90506,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -89770,7 +90694,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -89798,7 +90726,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -89918,8 +90846,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -90109,7 +91037,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -90197,8 +91129,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -90266,7 +91198,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -90306,8 +91238,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -90341,8 +91273,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -90455,8 +91387,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -90494,7 +91426,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -90531,7 +91463,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -90570,8 +91506,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -90598,8 +91534,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -90634,8 +91570,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -90690,7 +91626,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -90719,8 +91655,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -90744,8 +91680,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -90932,7 +91868,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -90960,7 +91900,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -91080,8 +92020,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -91271,7 +92211,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -91359,8 +92303,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -91428,7 +92372,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -91468,8 +92412,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -91503,8 +92447,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -91617,8 +92561,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -91656,7 +92600,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -91693,7 +92637,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -91732,8 +92680,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -91760,8 +92708,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -91796,8 +92744,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -91852,7 +92800,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -91881,8 +92829,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -91906,8 +92854,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -92094,7 +93042,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -92122,7 +93074,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -92242,8 +93194,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -92433,7 +93385,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -92521,8 +93477,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -92590,7 +93546,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -92630,8 +93586,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -92665,8 +93621,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -92779,8 +93735,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -92818,7 +93774,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -92855,7 +93811,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -92894,8 +93854,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -92922,8 +93882,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -92958,8 +93918,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -93014,7 +93974,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -93043,8 +94003,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -93068,8 +94028,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -93256,7 +94216,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -93284,7 +94248,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -93404,8 +94368,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -93595,7 +94559,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -93683,8 +94651,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -93752,7 +94720,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -93792,8 +94760,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -93827,8 +94795,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -93941,8 +94909,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -93980,7 +94948,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -94017,7 +94985,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -94056,8 +95028,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -94084,8 +95056,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -94120,8 +95092,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -94176,7 +95148,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -94205,8 +95177,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -94230,8 +95202,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -94418,7 +95390,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -94446,7 +95422,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -94566,8 +95542,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -94757,7 +95733,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -94845,8 +95825,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -94914,7 +95894,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -94954,8 +95934,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -94989,8 +95969,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -95103,8 +96083,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -95142,7 +96122,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -95179,7 +96159,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -95218,8 +96202,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -95246,8 +96230,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -95282,8 +96266,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -95338,7 +96322,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -95367,8 +96351,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -95392,8 +96376,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -95580,7 +96564,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -95608,7 +96596,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -95728,8 +96716,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -95919,7 +96907,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -96007,8 +96999,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -96076,7 +97068,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -96116,8 +97108,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -96151,8 +97143,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -96265,8 +97257,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -96304,7 +97296,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -96341,7 +97333,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -96380,8 +97376,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -96408,8 +97404,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -96444,8 +97440,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -96500,7 +97496,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -96529,8 +97525,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -96554,8 +97550,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -96742,7 +97738,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -96770,7 +97770,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -96890,8 +97890,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -97081,7 +98081,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -97169,8 +98173,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -97238,7 +98242,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -97278,8 +98282,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -97313,8 +98317,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -97427,8 +98431,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -97466,7 +98470,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -97503,7 +98507,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -97542,8 +98550,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -97570,8 +98578,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -97606,8 +98614,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -97662,7 +98670,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -97691,8 +98699,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -97716,8 +98724,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -97904,7 +98912,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -97932,7 +98944,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -98052,8 +99064,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -98243,7 +99255,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -98331,8 +99347,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -98400,7 +99416,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -98440,8 +99456,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -98475,8 +99491,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -98589,8 +99605,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -98628,7 +99644,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -98665,7 +99681,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -98704,8 +99724,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -98732,8 +99752,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -98768,8 +99788,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -98824,7 +99844,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -98853,8 +99873,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -98878,8 +99898,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -99066,7 +100086,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -99094,7 +100118,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -99214,8 +100238,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -99405,7 +100429,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -99493,8 +100521,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -99562,7 +100590,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -99602,8 +100630,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -99637,8 +100665,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -99751,8 +100779,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -99790,7 +100818,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -99827,7 +100855,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -99866,8 +100898,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -99894,8 +100926,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -99930,8 +100962,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -99986,7 +101018,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -100015,8 +101047,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -100040,8 +101072,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -100228,7 +101260,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -100256,7 +101292,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -100376,8 +101412,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -100567,7 +101603,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -100655,8 +101695,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -100724,7 +101764,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -100764,8 +101804,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -100799,8 +101839,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -100913,8 +101953,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -100952,7 +101992,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -100989,7 +102029,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -101028,8 +102072,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -101056,8 +102100,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -101092,8 +102136,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -101148,7 +102192,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -101177,8 +102221,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -101202,8 +102246,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -101390,7 +102434,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -101418,7 +102466,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -101538,8 +102586,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -101729,7 +102777,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -101817,8 +102869,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -101886,7 +102938,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -101926,8 +102978,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -101961,8 +103013,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -102075,8 +103127,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -102114,7 +103166,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -102151,7 +103203,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -102190,8 +103246,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -102218,8 +103274,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -102254,8 +103310,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -102310,7 +103366,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -102339,8 +103395,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -102364,8 +103420,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -102552,7 +103608,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -102580,7 +103640,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -102700,8 +103760,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -102891,7 +103951,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -102979,8 +104043,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -103048,7 +104112,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -103088,8 +104152,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -103123,8 +104187,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -103237,8 +104301,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -103276,7 +104340,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -103313,7 +104377,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -103352,8 +104420,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -103380,8 +104448,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -103416,8 +104484,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -103472,7 +104540,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -103501,8 +104569,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -103526,8 +104594,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -103714,7 +104782,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -103742,7 +104814,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -103862,8 +104934,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -104053,7 +105125,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -104141,8 +105217,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -104210,7 +105286,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -104250,8 +105326,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -104285,8 +105361,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -104399,8 +105475,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -104438,7 +105514,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -104475,7 +105551,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -104514,8 +105594,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -104542,8 +105622,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -104578,8 +105658,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -104634,7 +105714,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -104663,8 +105743,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -104688,8 +105768,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -104876,7 +105956,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -104904,7 +105988,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -105024,8 +106108,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -105215,7 +106299,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -105303,8 +106391,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -105372,7 +106460,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -105412,8 +106500,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -105447,8 +106535,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -105561,8 +106649,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -105600,7 +106688,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -105637,7 +106725,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -105676,8 +106768,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -105704,8 +106796,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -105740,8 +106832,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -105796,7 +106888,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -105825,8 +106917,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -105850,8 +106942,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -106038,7 +107130,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -106066,7 +107162,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -106186,8 +107282,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -106377,7 +107473,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -106465,8 +107565,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -106534,7 +107634,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -106574,8 +107674,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -106609,8 +107709,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -106723,8 +107823,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -106762,7 +107862,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -106799,7 +107899,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -106838,8 +107942,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -106866,8 +107970,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -106902,8 +108006,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -106958,7 +108062,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -106987,8 +108091,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -107012,8 +108116,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -107200,7 +108304,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -107228,7 +108336,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -107348,8 +108456,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -107539,7 +108647,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -107627,8 +108739,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -107696,7 +108808,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -107736,8 +108848,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -107771,8 +108883,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -107885,8 +108997,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -107924,7 +109036,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -107961,7 +109073,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -108000,8 +109116,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -108028,8 +109144,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -108064,8 +109180,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -108120,7 +109236,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -108149,8 +109265,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -108174,8 +109290,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -108362,7 +109478,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -108390,7 +109510,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -108510,8 +109630,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -108701,7 +109821,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -108789,8 +109913,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -108858,7 +109982,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -108898,8 +110022,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -108933,8 +110057,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -109047,8 +110171,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -109086,7 +110210,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -109123,7 +110247,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -109162,8 +110290,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -109190,8 +110318,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -109226,8 +110354,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -109282,7 +110410,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -109311,8 +110439,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -109336,8 +110464,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -109524,7 +110652,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -109552,7 +110684,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -109672,8 +110804,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -109863,7 +110995,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -109951,8 +111087,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -110020,7 +111156,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -110060,8 +111196,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -110095,8 +111231,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -110209,8 +111345,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -110248,7 +111384,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -110285,7 +111421,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -110324,8 +111464,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -110352,8 +111492,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -110388,8 +111528,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -110444,7 +111584,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -110473,8 +111613,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -110498,8 +111638,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -110686,7 +111826,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -110714,7 +111858,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -110834,8 +111978,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -111025,7 +112169,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -111113,8 +112261,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -111182,7 +112330,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -111222,8 +112370,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -111257,8 +112405,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -111371,8 +112519,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -111410,7 +112558,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -111447,7 +112595,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -111486,8 +112638,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -111514,8 +112666,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -111550,8 +112702,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -111606,7 +112758,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -111635,8 +112787,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -111660,8 +112812,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -111848,7 +113000,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -111876,7 +113032,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -111996,8 +113152,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -112187,7 +113343,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -112275,8 +113435,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -112344,7 +113504,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -112384,8 +113544,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -112419,8 +113579,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -112533,8 +113693,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -112572,7 +113732,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -112609,7 +113769,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -112648,8 +113812,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -112676,8 +113840,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -112712,8 +113876,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -112768,7 +113932,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -112797,8 +113961,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -112822,8 +113986,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -113010,7 +114174,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -113038,7 +114206,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -113158,8 +114326,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -113349,7 +114517,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -113437,8 +114609,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -113506,7 +114678,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -113546,8 +114718,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -113581,8 +114753,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -113695,8 +114867,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -113734,7 +114906,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -113771,7 +114943,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -113810,8 +114986,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -113838,8 +115014,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -113874,8 +115050,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -113930,7 +115106,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -113959,8 +115135,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -113984,8 +115160,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -114172,7 +115348,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -114200,7 +115380,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -114320,8 +115500,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -114511,7 +115691,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -114599,8 +115783,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -114668,7 +115852,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -114708,8 +115892,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -114743,8 +115927,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -114857,8 +116041,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -114896,7 +116080,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -114933,7 +116117,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -114972,8 +116160,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -115000,8 +116188,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -115036,8 +116224,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -115092,7 +116280,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -115121,8 +116309,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -115146,8 +116334,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -115334,7 +116522,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -115362,7 +116554,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -115482,8 +116674,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -115673,7 +116865,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -115761,8 +116957,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -115830,7 +117026,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -115870,8 +117066,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -115905,8 +117101,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -116019,8 +117215,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -116058,7 +117254,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -116095,7 +117291,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -116134,8 +117334,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -116162,8 +117362,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -116198,8 +117398,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -116254,7 +117454,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -116283,8 +117483,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -116308,8 +117508,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -116496,7 +117696,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -116524,7 +117728,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -116644,8 +117848,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -116835,7 +118039,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -116923,8 +118131,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -116992,7 +118200,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -117032,8 +118240,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -117067,8 +118275,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -117181,8 +118389,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -117220,7 +118428,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -117257,7 +118465,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -117296,8 +118508,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -117324,8 +118536,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -117360,8 +118572,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -117416,7 +118628,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -117445,8 +118657,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -117470,8 +118682,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -117658,7 +118870,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -117686,7 +118902,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -117806,8 +119022,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -117997,7 +119213,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -118085,8 +119305,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -118154,7 +119374,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -118194,8 +119414,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -118229,8 +119449,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -118343,8 +119563,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -118382,7 +119602,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -118419,7 +119639,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -118458,8 +119682,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -118486,8 +119710,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -118522,8 +119746,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -118578,7 +119802,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -118607,8 +119831,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -118632,8 +119856,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -118820,7 +120044,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -118848,7 +120076,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -118968,8 +120196,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -119159,7 +120387,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -119247,8 +120479,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -119316,7 +120548,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -119356,8 +120588,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -119391,8 +120623,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -119505,8 +120737,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -119544,7 +120776,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -119581,7 +120813,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -119620,8 +120856,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -119648,8 +120884,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -119684,8 +120920,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -119740,7 +120976,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -119769,8 +121005,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -119794,8 +121030,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -119982,7 +121218,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -120010,7 +121250,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -120130,8 +121370,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -120321,7 +121561,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -120409,8 +121653,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -120478,7 +121722,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -120518,8 +121762,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -120553,8 +121797,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -120667,8 +121911,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -120706,7 +121950,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -120743,7 +121987,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -120782,8 +122030,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -120810,8 +122058,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -120846,8 +122094,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -120902,7 +122150,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -120931,8 +122179,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -120956,8 +122204,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -121144,7 +122392,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -121172,7 +122424,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -121292,8 +122544,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -121483,7 +122735,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -121571,8 +122827,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -121640,7 +122896,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -121680,8 +122936,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -121715,8 +122971,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -121829,8 +123085,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -121868,7 +123124,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -121905,7 +123161,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -121944,8 +123204,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -121972,8 +123232,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -122008,8 +123268,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -122064,7 +123324,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -122093,8 +123353,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -122118,8 +123378,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -122306,7 +123566,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -122334,7 +123598,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -122454,8 +123718,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -122645,7 +123909,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -122733,8 +124001,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -122802,7 +124070,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -122842,8 +124110,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -122877,8 +124145,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -122991,8 +124259,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -123030,7 +124298,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -123067,7 +124335,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -123106,8 +124378,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -123134,8 +124406,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -123170,8 +124442,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -123226,7 +124498,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -123255,8 +124527,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -123280,8 +124552,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -123468,7 +124740,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -123496,7 +124772,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -123616,8 +124892,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -123807,7 +125083,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -123895,8 +125175,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -123964,7 +125244,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -124004,8 +125284,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -124039,8 +125319,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -124153,8 +125433,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -124192,7 +125472,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -124229,7 +125509,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -124268,8 +125552,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -124296,8 +125580,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -124332,8 +125616,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -124388,7 +125672,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -124417,8 +125701,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -124442,8 +125726,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -124630,7 +125914,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -124658,7 +125946,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -124778,8 +126066,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -124969,7 +126257,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -125057,8 +126349,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -125126,7 +126418,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -125166,8 +126458,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -125201,8 +126493,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -125315,8 +126607,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -125354,7 +126646,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -125391,7 +126683,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -125430,8 +126726,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -125458,8 +126754,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -125494,8 +126790,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -125550,7 +126846,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -125579,8 +126875,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -125604,8 +126900,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -125792,7 +127088,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -125820,7 +127120,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -125940,8 +127240,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -126131,7 +127431,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -126219,8 +127523,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -126288,7 +127592,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -126328,8 +127632,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -126363,8 +127667,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -126477,8 +127781,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -126516,7 +127820,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -126553,7 +127857,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -126592,8 +127900,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -126620,8 +127928,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -126656,8 +127964,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -126712,7 +128020,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -126741,8 +128049,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -126766,8 +128074,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -126954,7 +128262,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -126982,7 +128294,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -127102,8 +128414,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -127293,7 +128605,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -127381,8 +128697,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -127450,7 +128766,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -127490,8 +128806,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -127525,8 +128841,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -127639,8 +128955,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -127678,7 +128994,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -127715,7 +129031,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -127754,8 +129074,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -127782,8 +129102,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -127818,8 +129138,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -127874,7 +129194,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -127903,8 +129223,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -127928,8 +129248,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -128116,7 +129436,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -128144,7 +129468,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -128264,8 +129588,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -128455,7 +129779,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -128543,8 +129871,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -128612,7 +129940,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -128652,8 +129980,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -128687,8 +130015,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -128801,8 +130129,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -128840,7 +130168,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -128877,7 +130205,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -128916,8 +130248,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -128944,8 +130276,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -128980,8 +130312,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -129036,7 +130368,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -129065,8 +130397,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -129090,8 +130422,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -129278,7 +130610,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -129306,7 +130642,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -129426,8 +130762,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -129617,7 +130953,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -129705,8 +131045,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -129774,7 +131114,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -129814,8 +131154,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -129849,8 +131189,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -129963,8 +131303,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -130002,7 +131342,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -130039,7 +131379,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -130078,8 +131422,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -130106,8 +131450,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -130142,8 +131486,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -130198,7 +131542,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -130227,8 +131571,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -130252,8 +131596,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -130440,7 +131784,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -130468,7 +131816,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -130588,8 +131936,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -130779,7 +132127,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -130867,8 +132219,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -130936,7 +132288,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -130976,8 +132328,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -131011,8 +132363,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -131125,8 +132477,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -131164,7 +132516,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -131201,7 +132553,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -131240,8 +132596,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -131268,8 +132624,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -131304,8 +132660,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -131360,7 +132716,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -131389,8 +132745,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -131414,8 +132770,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -131602,7 +132958,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -131630,7 +132990,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -131750,8 +133110,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -131941,7 +133301,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -132029,8 +133393,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -132098,7 +133462,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -132138,8 +133502,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -132173,8 +133537,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -132287,8 +133651,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -132326,7 +133690,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -132363,7 +133727,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -132402,8 +133770,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -132430,8 +133798,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -132466,8 +133834,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -132522,7 +133890,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -132551,8 +133919,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -132576,8 +133944,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -132764,7 +134132,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -132792,7 +134164,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -132912,8 +134284,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -133103,7 +134475,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -133191,8 +134567,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -133260,7 +134636,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -133300,8 +134676,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -133335,8 +134711,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -133449,8 +134825,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -133488,7 +134864,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -133525,7 +134901,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -133564,8 +134944,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -133592,8 +134972,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -133628,8 +135008,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -133684,7 +135064,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -133713,8 +135093,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -133738,8 +135118,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -133926,7 +135306,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -133954,7 +135338,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -134074,8 +135458,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -134265,7 +135649,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -134353,8 +135741,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -134422,7 +135810,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -134462,8 +135850,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -134497,8 +135885,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -134611,8 +135999,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -134650,7 +136038,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -134687,7 +136075,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -134726,8 +136118,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -134754,8 +136146,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -134790,8 +136182,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -134846,7 +136238,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -134875,8 +136267,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -134900,8 +136292,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -135088,7 +136480,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -135116,7 +136512,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -135236,8 +136632,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -135427,7 +136823,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -135515,8 +136915,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -135584,7 +136984,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -135624,8 +137024,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -135659,8 +137059,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -135773,8 +137173,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -135812,7 +137212,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -135849,7 +137249,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -135888,8 +137292,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -135916,8 +137320,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -135952,8 +137356,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -136008,7 +137412,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -136037,8 +137441,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -136062,8 +137466,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -136250,7 +137654,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -136278,7 +137686,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -136398,8 +137806,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -136589,7 +137997,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -136677,8 +138089,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -136746,7 +138158,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -136786,8 +138198,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -136821,8 +138233,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -136935,8 +138347,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -136974,7 +138386,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -137011,7 +138423,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -137050,8 +138466,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -137078,8 +138494,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -137114,8 +138530,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -137170,7 +138586,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -137199,8 +138615,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -137224,8 +138640,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -137412,7 +138828,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -137440,7 +138860,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -137560,8 +138980,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -137751,7 +139171,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -137839,8 +139263,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -137908,7 +139332,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -137948,8 +139372,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -137983,8 +139407,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -138097,8 +139521,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -138136,7 +139560,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -138173,7 +139597,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -138212,8 +139640,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -138240,8 +139668,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -138276,8 +139704,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -138332,7 +139760,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -138361,8 +139789,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -138386,8 +139814,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -138574,7 +140002,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -138602,7 +140034,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -138722,8 +140154,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -138913,7 +140345,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -139001,8 +140437,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -139070,7 +140506,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -139110,8 +140546,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -139145,8 +140581,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -139259,8 +140695,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -139298,7 +140734,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -139335,7 +140771,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -139374,8 +140814,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -139402,8 +140842,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -139438,8 +140878,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -139494,7 +140934,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -139523,8 +140963,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -139548,8 +140988,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -139736,7 +141176,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -139764,7 +141208,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -139884,8 +141328,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -140075,7 +141519,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -140163,8 +141611,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -140232,7 +141680,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -140272,8 +141720,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -140307,8 +141755,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -140421,8 +141869,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -140460,7 +141908,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -140497,7 +141945,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -140536,8 +141988,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -140564,8 +142016,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -140600,8 +142052,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -140656,7 +142108,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -140685,8 +142137,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -140710,8 +142162,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -140898,7 +142350,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -140926,7 +142382,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -141046,8 +142502,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -141237,7 +142693,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -141325,8 +142785,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -141394,7 +142854,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -141434,8 +142894,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -141469,8 +142929,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -141583,8 +143043,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -141622,7 +143082,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -141659,7 +143119,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -141698,8 +143162,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -141726,8 +143190,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -141762,8 +143226,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -141818,7 +143282,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -141847,8 +143311,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -141872,8 +143336,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -142060,7 +143524,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -142088,7 +143556,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -142208,8 +143676,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -142399,7 +143867,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -142487,8 +143959,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -142556,7 +144028,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -142596,8 +144068,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -142631,8 +144103,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -142745,8 +144217,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -142784,7 +144256,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -142821,7 +144293,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -142860,8 +144336,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -142888,8 +144364,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -142924,8 +144400,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -142980,7 +144456,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -143009,8 +144485,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -143034,8 +144510,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -143222,7 +144698,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -143250,7 +144730,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -143370,8 +144850,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -143561,7 +145041,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -143649,8 +145133,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -143718,7 +145202,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -143758,8 +145242,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -143793,8 +145277,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -143907,8 +145391,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -143946,7 +145430,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -143983,7 +145467,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -144022,8 +145510,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -144050,8 +145538,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -144086,8 +145574,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -144142,7 +145630,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -144171,8 +145659,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -144196,8 +145684,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -144384,7 +145872,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -144412,7 +145904,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -144532,8 +146024,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -144723,7 +146215,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -144811,8 +146307,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -144880,7 +146376,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -144920,8 +146416,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -144955,8 +146451,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -145069,8 +146565,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -145108,7 +146604,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -145145,7 +146641,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -145184,8 +146684,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -145212,8 +146712,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -145248,8 +146748,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -145304,7 +146804,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -145333,8 +146833,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -145358,8 +146858,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -145546,7 +147046,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -145574,7 +147078,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -145694,8 +147198,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -145885,7 +147389,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -145973,8 +147481,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -146042,7 +147550,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -146082,8 +147590,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -146117,8 +147625,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -146231,8 +147739,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -146270,7 +147778,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -146307,7 +147815,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -146346,8 +147858,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -146374,8 +147886,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -146410,8 +147922,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -146466,7 +147978,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -146495,8 +148007,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -146520,8 +148032,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -146708,7 +148220,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -146736,7 +148252,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -146856,8 +148372,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -147047,7 +148563,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -147135,8 +148655,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -147204,7 +148724,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -147244,8 +148764,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -147279,8 +148799,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -147393,8 +148913,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -147432,7 +148952,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -147469,7 +148989,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -147508,8 +149032,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -147536,8 +149060,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -147572,8 +149096,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -147628,7 +149152,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -147657,8 +149181,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -147682,8 +149206,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -147870,7 +149394,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -147898,7 +149426,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -148018,8 +149546,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -148209,7 +149737,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -148297,8 +149829,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -148366,7 +149898,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -148406,8 +149938,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -148441,8 +149973,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -148555,8 +150087,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -148594,7 +150126,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -148631,7 +150163,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -148670,8 +150206,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -148698,8 +150234,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -148734,8 +150270,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -148790,7 +150326,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -148819,8 +150355,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -148844,8 +150380,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -149032,7 +150568,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -149060,7 +150600,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -149180,8 +150720,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -149371,7 +150911,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -149459,8 +151003,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -149528,7 +151072,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -149568,8 +151112,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -149603,8 +151147,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -149717,8 +151261,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -149756,7 +151300,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -149793,7 +151337,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -149832,8 +151380,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -149860,8 +151408,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -149896,8 +151444,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -149952,7 +151500,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -149981,8 +151529,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -150006,8 +151554,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -150194,7 +151742,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -150222,7 +151774,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -150342,8 +151894,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -150533,7 +152085,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -150621,8 +152177,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -150690,7 +152246,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -150730,8 +152286,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -150765,8 +152321,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -150879,8 +152435,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -150918,7 +152474,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -150955,7 +152511,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -150994,8 +152554,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -151022,8 +152582,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -151058,8 +152618,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -151114,7 +152674,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -151143,8 +152703,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -151168,8 +152728,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -151356,7 +152916,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -151384,7 +152948,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -151504,8 +153068,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -151695,7 +153259,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -151783,8 +153351,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -151852,7 +153420,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -151892,8 +153460,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -151927,8 +153495,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -152041,8 +153609,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -152080,7 +153648,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -152117,7 +153685,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -152156,8 +153728,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -152184,8 +153756,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -152220,8 +153792,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -152276,7 +153848,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -152305,8 +153877,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -152330,8 +153902,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -152518,7 +154090,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -152546,7 +154122,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -152666,8 +154242,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -152857,7 +154433,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -152945,8 +154525,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -153014,7 +154594,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -153054,8 +154634,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -153089,8 +154669,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -153203,8 +154783,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -153242,7 +154822,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -153279,7 +154859,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -153318,8 +154902,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -153346,8 +154930,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -153382,8 +154966,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -153438,7 +155022,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -153467,8 +155051,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -153492,8 +155076,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -153680,7 +155264,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -153708,7 +155296,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -153828,8 +155416,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -154019,7 +155607,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -154107,8 +155699,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -154176,7 +155768,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -154216,8 +155808,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -154251,8 +155843,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -154365,8 +155957,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -154404,7 +155996,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -154441,7 +156033,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -154480,8 +156076,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -154508,8 +156104,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -154544,8 +156140,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -154600,7 +156196,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -154629,8 +156225,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -154654,8 +156250,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -154842,7 +156438,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -154870,7 +156470,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -154990,8 +156590,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -155181,7 +156781,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -155269,8 +156873,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -155338,7 +156942,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -155378,8 +156982,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -155413,8 +157017,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -155527,8 +157131,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -155566,7 +157170,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -155603,7 +157207,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -155642,8 +157250,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -155670,8 +157278,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -155706,8 +157314,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -155762,7 +157370,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -155791,8 +157399,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -155816,8 +157424,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -156004,7 +157612,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -156032,7 +157644,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -156152,8 +157764,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -156343,7 +157955,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -156431,8 +158047,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -156500,7 +158116,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -156540,8 +158156,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -156575,8 +158191,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -156689,8 +158305,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -156728,7 +158344,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -156765,7 +158381,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -156804,8 +158424,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -156832,8 +158452,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -156868,8 +158488,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -156924,7 +158544,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -156953,8 +158573,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -156978,8 +158598,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -157166,7 +158786,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -157194,7 +158818,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -157314,8 +158938,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -157505,7 +159129,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -157593,8 +159221,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -157662,7 +159290,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -157702,8 +159330,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -157737,8 +159365,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -157851,8 +159479,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -157890,7 +159518,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -157927,7 +159555,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -157966,8 +159598,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -157994,8 +159626,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -158030,8 +159662,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -158086,7 +159718,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -158115,8 +159747,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -158140,8 +159772,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -158328,7 +159960,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -158356,7 +159992,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -158476,8 +160112,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -158667,7 +160303,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -158755,8 +160395,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -158824,7 +160464,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -158864,8 +160504,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -158899,8 +160539,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -159013,8 +160653,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -159052,7 +160692,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -159089,7 +160729,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -159128,8 +160772,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -159156,8 +160800,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -159192,8 +160836,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -159248,7 +160892,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -159277,8 +160921,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -159302,8 +160946,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -159490,7 +161134,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -159518,7 +161166,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -159638,8 +161286,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -159829,7 +161477,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -159917,8 +161569,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -159986,7 +161638,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -160026,8 +161678,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -160061,8 +161713,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -160175,8 +161827,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -160214,7 +161866,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -160251,7 +161903,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -160290,8 +161946,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -160318,8 +161974,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -160354,8 +162010,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -160410,7 +162066,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -160439,8 +162095,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -160464,8 +162120,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -160652,7 +162308,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -160680,7 +162340,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -160800,8 +162460,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -160991,7 +162651,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -161079,8 +162743,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -161148,7 +162812,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -161188,8 +162852,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -161223,8 +162887,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -161337,8 +163001,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -161376,7 +163040,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -161413,7 +163077,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -161452,8 +163120,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -161480,8 +163148,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -161516,8 +163184,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -161572,7 +163240,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -161601,8 +163269,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -161626,8 +163294,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -161814,7 +163482,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -161842,7 +163514,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -161962,8 +163634,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -162153,7 +163825,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -162241,8 +163917,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -162310,7 +163986,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -162350,8 +164026,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -162385,8 +164061,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -162499,8 +164175,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -162538,7 +164214,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -162575,7 +164251,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -162614,8 +164294,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -162642,8 +164322,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -162678,8 +164358,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -162734,7 +164414,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -162763,8 +164443,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -162788,8 +164468,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -162976,7 +164656,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -163004,7 +164688,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -163124,8 +164808,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -163315,7 +164999,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -163403,8 +165091,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -163472,7 +165160,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -163512,8 +165200,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -163547,8 +165235,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -163661,8 +165349,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -163700,7 +165388,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -163737,7 +165425,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -163776,8 +165468,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -163804,8 +165496,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -163840,8 +165532,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -163896,7 +165588,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -163925,8 +165617,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -163950,8 +165642,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -164138,7 +165830,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -164166,7 +165862,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -164286,8 +165982,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -164477,7 +166173,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -164565,8 +166265,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -164634,7 +166334,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -164674,8 +166374,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -164709,8 +166409,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -164823,8 +166523,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -164862,7 +166562,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -164899,7 +166599,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -164938,8 +166642,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -164966,8 +166670,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -165002,8 +166706,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -165058,7 +166762,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -165087,8 +166791,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -165112,8 +166816,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -165300,7 +167004,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -165328,7 +167036,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -165448,8 +167156,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -165639,7 +167347,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -165727,8 +167439,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -165796,7 +167508,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -165836,8 +167548,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -165871,8 +167583,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -165985,8 +167697,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -166024,7 +167736,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -166061,7 +167773,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -166100,8 +167816,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -166128,8 +167844,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -166164,8 +167880,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -166220,7 +167936,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -166249,8 +167965,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -166274,8 +167990,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -166462,7 +168178,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -166490,7 +168210,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -166610,8 +168330,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -166801,7 +168521,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -166889,8 +168613,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -166958,7 +168682,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -166998,8 +168722,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -167033,8 +168757,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -167147,8 +168871,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -167186,7 +168910,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -167223,7 +168947,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -167262,8 +168990,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -167290,8 +169018,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -167326,8 +169054,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -167382,7 +169110,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -167411,8 +169139,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -167436,8 +169164,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -167624,7 +169352,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -167652,7 +169384,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -167772,8 +169504,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -167963,7 +169695,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -168051,8 +169787,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -168120,7 +169856,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -168160,8 +169896,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -168195,8 +169931,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -168309,8 +170045,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -168348,7 +170084,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -168385,7 +170121,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -168424,8 +170164,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -168452,8 +170192,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -168488,8 +170228,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -168544,7 +170284,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -168573,8 +170313,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -168598,8 +170338,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -168786,7 +170526,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -168814,7 +170558,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -168934,8 +170678,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -169125,7 +170869,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -169213,8 +170961,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -169282,7 +171030,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -169322,8 +171070,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -169357,8 +171105,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -169471,8 +171219,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -169510,7 +171258,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -169547,7 +171295,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -169586,8 +171338,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -169614,8 +171366,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -169650,8 +171402,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -169706,7 +171458,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -169735,8 +171487,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -169760,8 +171512,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -169948,7 +171700,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -169976,7 +171732,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -170096,8 +171852,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -170287,7 +172043,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -170375,8 +172135,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -170444,7 +172204,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -170484,8 +172244,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -170519,8 +172279,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -170633,8 +172393,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -170672,7 +172432,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -170709,7 +172469,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -170748,8 +172512,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -170776,8 +172540,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -170812,8 +172576,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -170868,7 +172632,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -170897,8 +172661,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -170922,8 +172686,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -171110,7 +172874,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -171138,7 +172906,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -171258,8 +173026,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -171449,7 +173217,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -171537,8 +173309,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -171606,7 +173378,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -171646,8 +173418,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -171681,8 +173453,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -171795,8 +173567,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -171834,7 +173606,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -171871,7 +173643,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -171910,8 +173686,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -171938,8 +173714,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -171974,8 +173750,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -172030,7 +173806,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -172059,8 +173835,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -172084,8 +173860,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -172272,7 +174048,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -172300,7 +174080,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -172420,8 +174200,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -172611,7 +174391,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -172699,8 +174483,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -172768,7 +174552,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -172808,8 +174592,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -172843,8 +174627,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -172957,8 +174741,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -172996,7 +174780,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -173033,7 +174817,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -173072,8 +174860,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -173100,8 +174888,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -173136,8 +174924,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -173192,7 +174980,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -173221,8 +175009,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -173246,8 +175034,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -173434,7 +175222,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -173462,7 +175254,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -173582,8 +175374,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -173773,7 +175565,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -173861,8 +175657,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -173930,7 +175726,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -173970,8 +175766,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -174005,8 +175801,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -174119,8 +175915,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -174158,7 +175954,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -174195,7 +175991,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -174234,8 +176034,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -174262,8 +176062,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -174298,8 +176098,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -174354,7 +176154,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -174383,8 +176183,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -174408,8 +176208,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -174596,7 +176396,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -174624,7 +176428,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -174744,8 +176548,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -174935,7 +176739,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -175023,8 +176831,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -175092,7 +176900,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -175132,8 +176940,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -175167,8 +176975,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -175281,8 +177089,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -175320,7 +177128,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -175357,7 +177165,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -175396,8 +177208,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -175424,8 +177236,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -175460,8 +177272,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -175516,7 +177328,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -175545,8 +177357,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -175570,8 +177382,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -175758,7 +177570,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -175786,7 +177602,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -175906,8 +177722,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -176097,7 +177913,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -176185,8 +178005,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -176254,7 +178074,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -176294,8 +178114,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -176329,8 +178149,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -176443,8 +178263,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -176482,7 +178302,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -176519,7 +178339,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -176558,8 +178382,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -176586,8 +178410,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -176622,8 +178446,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -176678,7 +178502,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -176707,8 +178531,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -176732,8 +178556,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -176920,7 +178744,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -176948,7 +178776,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -177068,8 +178896,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -177259,7 +179087,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -177347,8 +179179,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -177416,7 +179248,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -177456,8 +179288,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -177491,8 +179323,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -177605,8 +179437,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -177644,7 +179476,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -177681,7 +179513,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -177720,8 +179556,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -177748,8 +179584,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -177784,8 +179620,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -177840,7 +179676,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -177869,8 +179705,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -177894,8 +179730,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -178082,7 +179918,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -178110,7 +179950,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -178230,8 +180070,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -178421,7 +180261,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -178509,8 +180353,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -178578,7 +180422,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -178618,8 +180462,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -178653,8 +180497,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -178767,8 +180611,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -178806,7 +180650,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -178843,7 +180687,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -178882,8 +180730,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -178910,8 +180758,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -178946,8 +180794,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -179002,7 +180850,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -179031,8 +180879,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -179056,8 +180904,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -179244,7 +181092,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -179272,7 +181124,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -179392,8 +181244,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -179583,7 +181435,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -179671,8 +181527,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -179740,7 +181596,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -179780,8 +181636,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -179815,8 +181671,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -179929,8 +181785,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -179968,7 +181824,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -180005,7 +181861,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -180044,8 +181904,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -180072,8 +181932,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -180108,8 +181968,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -180164,7 +182024,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -180193,8 +182053,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -180218,8 +182078,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -180406,7 +182266,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -180434,7 +182298,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -180554,8 +182418,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -180745,7 +182609,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -180833,8 +182701,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -180902,7 +182770,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -180942,8 +182810,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -180977,8 +182845,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -181091,8 +182959,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -181130,7 +182998,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -181167,7 +183035,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -181206,8 +183078,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -181234,8 +183106,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -181270,8 +183142,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -181326,7 +183198,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -181355,8 +183227,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -181380,8 +183252,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -181568,7 +183440,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -181596,7 +183472,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -181716,8 +183592,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -181907,7 +183783,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -181995,8 +183875,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -182064,7 +183944,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -182104,8 +183984,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -182139,8 +184019,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -182253,8 +184133,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -182292,7 +184172,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -182329,7 +184209,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -182368,8 +184252,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -182396,8 +184280,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -182432,8 +184316,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -182488,7 +184372,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -182517,8 +184401,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -182542,8 +184426,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -182730,7 +184614,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -182758,7 +184646,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -182878,8 +184766,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -183069,7 +184957,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -183157,8 +185049,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -183226,7 +185118,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -183266,8 +185158,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -183301,8 +185193,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -183415,8 +185307,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -183454,7 +185346,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -183491,7 +185383,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -183530,8 +185426,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -183558,8 +185454,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -183594,8 +185490,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -183650,7 +185546,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -183679,8 +185575,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -183704,8 +185600,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -183892,7 +185788,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -183920,7 +185820,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -184040,8 +185940,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -184231,7 +186131,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -184319,8 +186223,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -184388,7 +186292,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -184428,8 +186332,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -184463,8 +186367,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -184577,8 +186481,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -184616,7 +186520,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -184653,7 +186557,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -184692,8 +186600,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -184720,8 +186628,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -184756,8 +186664,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -184812,7 +186720,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -184841,8 +186749,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -184866,8 +186774,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -185054,7 +186962,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -185082,7 +186994,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -185202,8 +187114,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -185393,7 +187305,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -185481,8 +187397,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -185550,7 +187466,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -185590,8 +187506,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -185625,8 +187541,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -185739,8 +187655,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -185778,7 +187694,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -185815,7 +187731,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -185854,8 +187774,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -185882,8 +187802,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -185918,8 +187838,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -185974,7 +187894,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -186003,8 +187923,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -186028,8 +187948,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -186216,7 +188136,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -186244,7 +188168,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -186364,8 +188288,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -186555,7 +188479,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -186643,8 +188571,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -186712,7 +188640,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -186752,8 +188680,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -186787,8 +188715,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -186901,8 +188829,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -186940,7 +188868,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -186977,7 +188905,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -187016,8 +188948,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -187044,8 +188976,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -187080,8 +189012,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -187136,7 +189068,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -187165,8 +189097,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -187190,8 +189122,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -187378,7 +189310,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -187406,7 +189342,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -187526,8 +189462,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -187717,7 +189653,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -187805,8 +189745,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -187874,7 +189814,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -187914,8 +189854,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -187949,8 +189889,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -188063,8 +190003,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -188102,7 +190042,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -188139,7 +190079,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -188178,8 +190122,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -188206,8 +190150,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -188242,8 +190186,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -188298,7 +190242,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -188327,8 +190271,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -188352,8 +190296,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -188540,7 +190484,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -188568,7 +190516,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -188688,8 +190636,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -188879,7 +190827,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -188967,8 +190919,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -189036,7 +190988,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -189076,8 +191028,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -189111,8 +191063,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -189225,8 +191177,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -189264,7 +191216,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -189301,7 +191253,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -189340,8 +191296,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -189368,8 +191324,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -189404,8 +191360,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -189460,7 +191416,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -189489,8 +191445,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -189514,8 +191470,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -189702,7 +191658,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -189730,7 +191690,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -189850,8 +191810,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -190041,7 +192001,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -190129,8 +192093,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -190198,7 +192162,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -190238,8 +192202,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -190273,8 +192237,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -190387,8 +192351,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -190426,7 +192390,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -190463,7 +192427,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -190502,8 +192470,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -190530,8 +192498,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -190566,8 +192534,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -190622,7 +192590,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -190651,8 +192619,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -190676,8 +192644,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -190864,7 +192832,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -190892,7 +192864,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -191012,8 +192984,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -191203,7 +193175,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -191291,8 +193267,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -191360,7 +193336,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -191400,8 +193376,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -191435,8 +193411,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -191549,8 +193525,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -191588,7 +193564,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -191625,7 +193601,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -191664,8 +193644,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -191692,8 +193672,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -191728,8 +193708,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -191784,7 +193764,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -191813,8 +193793,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -191838,8 +193818,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -192026,7 +194006,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -192054,7 +194038,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -192174,8 +194158,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -192365,7 +194349,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -192453,8 +194441,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -192522,7 +194510,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -192562,8 +194550,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -192597,8 +194585,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -192711,8 +194699,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -192750,7 +194738,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -192787,7 +194775,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -192826,8 +194818,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -192854,8 +194846,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -192890,8 +194882,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -192946,7 +194938,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -192975,8 +194967,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -193000,8 +194992,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -193188,7 +195180,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -193216,7 +195212,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -193336,8 +195332,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -193527,7 +195523,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -193615,8 +195615,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -193684,7 +195684,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -193724,8 +195724,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -193759,8 +195759,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -193873,8 +195873,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -193912,7 +195912,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -193949,7 +195949,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -193988,8 +195992,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -194016,8 +196020,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -194052,8 +196056,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -194108,7 +196112,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -194137,8 +196141,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -194162,8 +196166,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -194350,7 +196354,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -194378,7 +196386,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -194498,8 +196506,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -194689,7 +196697,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -194777,8 +196789,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -194846,7 +196858,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -194886,8 +196898,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -194921,8 +196933,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -195035,8 +197047,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -195074,7 +197086,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -195111,7 +197123,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -195150,8 +197166,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -195178,8 +197194,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -195214,8 +197230,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -195270,7 +197286,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -195299,8 +197315,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -195324,8 +197340,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -195512,7 +197528,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -195540,7 +197560,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -195660,8 +197680,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -195851,7 +197871,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -195939,8 +197963,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -196008,7 +198032,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -196048,8 +198072,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -196083,8 +198107,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -196197,8 +198221,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -196236,7 +198260,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -196273,7 +198297,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -196312,8 +198340,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -196340,8 +198368,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -196376,8 +198404,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -196432,7 +198460,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -196461,8 +198489,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -196486,8 +198514,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -196674,7 +198702,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -196702,7 +198734,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -196822,8 +198854,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -197013,7 +199045,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -197101,8 +199137,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -197170,7 +199206,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -197210,8 +199246,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -197245,8 +199281,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -197359,8 +199395,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -197398,7 +199434,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -197435,7 +199471,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -197474,8 +199514,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -197502,8 +199542,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -197538,8 +199578,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -197594,7 +199634,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -197623,8 +199663,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -197648,8 +199688,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -197836,7 +199876,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -197864,7 +199908,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -197984,8 +200028,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -198175,7 +200219,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -198263,8 +200311,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -198332,7 +200380,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -198372,8 +200420,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -198407,8 +200455,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -198521,8 +200569,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -198560,7 +200608,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -198597,7 +200645,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -198636,8 +200688,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -198664,8 +200716,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -198700,8 +200752,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -198756,7 +200808,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -198785,8 +200837,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -198810,8 +200862,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -198998,7 +201050,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -199026,7 +201082,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -199146,8 +201202,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -199337,7 +201393,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -199425,8 +201485,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -199494,7 +201554,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -199534,8 +201594,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -199569,8 +201629,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -199683,8 +201743,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -199722,7 +201782,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -199759,7 +201819,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -199798,8 +201862,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -199826,8 +201890,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -199862,8 +201926,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -199918,7 +201982,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -199947,8 +202011,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -199972,8 +202036,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -200160,7 +202224,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -200188,7 +202256,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -200308,8 +202376,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -200499,7 +202567,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -200587,8 +202659,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -200656,7 +202728,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -200696,8 +202768,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -200731,8 +202803,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -200845,8 +202917,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -200884,7 +202956,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -200921,7 +202993,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -200960,8 +203036,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -200988,8 +203064,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -201024,8 +203100,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -201080,7 +203156,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -201109,8 +203185,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -201134,8 +203210,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -201322,7 +203398,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -201350,7 +203430,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -201470,8 +203550,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -201661,7 +203741,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -201749,8 +203833,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -201818,7 +203902,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -201858,8 +203942,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -201893,8 +203977,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -202007,8 +204091,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -202046,7 +204130,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -202083,7 +204167,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -202122,8 +204210,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -202150,8 +204238,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -202186,8 +204274,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -202242,7 +204330,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -202271,8 +204359,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -202296,8 +204384,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -202484,7 +204572,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -202512,7 +204604,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -202632,8 +204724,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -202823,7 +204915,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -202911,8 +205007,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -202980,7 +205076,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -203020,8 +205116,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -203055,8 +205151,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -203169,8 +205265,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -203208,7 +205304,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -203245,7 +205341,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -203284,8 +205384,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -203312,8 +205412,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -203348,8 +205448,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -203404,7 +205504,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -203433,8 +205533,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -203458,8 +205558,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -203646,7 +205746,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -203674,7 +205778,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -203794,8 +205898,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -203985,7 +206089,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -204073,8 +206181,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -204142,7 +206250,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -204182,8 +206290,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -204217,8 +206325,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -204331,8 +206439,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -204370,7 +206478,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -204407,7 +206515,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -204446,8 +206558,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -204474,8 +206586,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -204510,8 +206622,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -204566,7 +206678,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -204595,8 +206707,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -204620,8 +206732,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -204808,7 +206920,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -204836,7 +206952,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -204956,8 +207072,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -205147,7 +207263,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -205235,8 +207355,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -205304,7 +207424,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -205344,8 +207464,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -205379,8 +207499,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -205493,8 +207613,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -205532,7 +207652,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -205569,7 +207689,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -205608,8 +207732,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -205636,8 +207760,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -205672,8 +207796,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -205728,7 +207852,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -205757,8 +207881,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -205782,8 +207906,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -205970,7 +208094,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -205998,7 +208126,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -206118,8 +208246,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -206309,7 +208437,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -206397,8 +208529,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -206466,7 +208598,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -206506,8 +208638,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -206541,8 +208673,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -206655,8 +208787,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -206694,7 +208826,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -206731,7 +208863,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -206770,8 +208906,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -206798,8 +208934,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -206834,8 +208970,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -206890,7 +209026,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -206919,8 +209055,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -206944,8 +209080,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -207132,7 +209268,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -207160,7 +209300,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -207280,8 +209420,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -207471,7 +209611,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -207559,8 +209703,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -207628,7 +209772,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -207668,8 +209812,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -207703,8 +209847,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -207817,8 +209961,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -207856,7 +210000,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -207893,7 +210037,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -207932,8 +210080,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -207960,8 +210108,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -207996,8 +210144,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -208052,7 +210200,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -208081,8 +210229,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -208106,8 +210254,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -208294,7 +210442,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -208322,7 +210474,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -208442,8 +210594,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -208633,7 +210785,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -208721,8 +210877,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -208790,7 +210946,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -208830,8 +210986,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -208865,8 +211021,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -208979,8 +211135,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -209018,7 +211174,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -209055,7 +211211,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -209094,8 +211254,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -209122,8 +211282,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -209158,8 +211318,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -209214,7 +211374,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -209243,8 +211403,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -209268,8 +211428,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -209456,7 +211616,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -209484,7 +211648,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -209604,8 +211768,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -209795,7 +211959,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -209883,8 +212051,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -209952,7 +212120,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -209992,8 +212160,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -210027,8 +212195,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -210141,8 +212309,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -210180,7 +212348,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -210217,7 +212385,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -210256,8 +212428,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -210284,8 +212456,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -210320,8 +212492,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -210376,7 +212548,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -210405,8 +212577,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -210430,8 +212602,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -210618,7 +212790,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -210646,7 +212822,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -210766,8 +212942,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -210957,7 +213133,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -211045,8 +213225,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -211114,7 +213294,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -211154,8 +213334,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -211189,8 +213369,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -211303,8 +213483,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -211342,7 +213522,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -211379,7 +213559,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -211418,8 +213602,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -211446,8 +213630,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -211482,8 +213666,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -211538,7 +213722,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -211567,8 +213751,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -211592,8 +213776,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -211780,7 +213964,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -211808,7 +213996,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -211928,8 +214116,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -212119,7 +214307,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -212207,8 +214399,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -212276,7 +214468,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -212316,8 +214508,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -212351,8 +214543,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -212465,8 +214657,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -212504,7 +214696,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -212541,7 +214733,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -212580,8 +214776,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -212608,8 +214804,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -212644,8 +214840,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -212700,7 +214896,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -212729,8 +214925,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -212754,8 +214950,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -212942,7 +215138,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -212970,7 +215170,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -213090,8 +215290,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -213281,7 +215481,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -213369,8 +215573,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -213438,7 +215642,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -213478,8 +215682,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -213513,8 +215717,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -213627,8 +215831,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -213666,7 +215870,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -213703,7 +215907,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -213742,8 +215950,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -213770,8 +215978,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -213806,8 +216014,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -213862,7 +216070,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -213891,8 +216099,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -213916,8 +216124,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -214104,7 +216312,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -214132,7 +216344,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -214252,8 +216464,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -214443,7 +216655,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -214531,8 +216747,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -214600,7 +216816,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -214640,8 +216856,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -214675,8 +216891,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -214789,8 +217005,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -214828,7 +217044,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -214865,7 +217081,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -214904,8 +217124,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -214932,8 +217152,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -214968,8 +217188,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -215024,7 +217244,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -215053,8 +217273,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -215078,8 +217298,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -215266,7 +217486,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -215294,7 +217518,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -215414,8 +217638,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -215605,7 +217829,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -215693,8 +217921,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -215762,7 +217990,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -215802,8 +218030,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -215837,8 +218065,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -215951,8 +218179,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -215990,7 +218218,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -216027,7 +218255,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -216066,8 +218298,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -216094,8 +218326,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -216130,8 +218362,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -216186,7 +218418,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -216215,8 +218447,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -216240,8 +218472,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -216428,7 +218660,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -216456,7 +218692,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -216576,8 +218812,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -216767,7 +219003,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -216855,8 +219095,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -216924,7 +219164,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -216964,8 +219204,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -216999,8 +219239,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -217113,8 +219353,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -217152,7 +219392,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -217189,7 +219429,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -217228,8 +219472,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -217256,8 +219500,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -217292,8 +219536,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -217348,7 +219592,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -217377,8 +219621,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -217402,8 +219646,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -217590,7 +219834,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -217618,7 +219866,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -217738,8 +219986,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -217929,7 +220177,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -218017,8 +220269,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -218086,7 +220338,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -218126,8 +220378,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -218161,8 +220413,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -218275,8 +220527,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -218314,7 +220566,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -218351,7 +220603,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -218390,8 +220646,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -218418,8 +220674,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -218454,8 +220710,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -218510,7 +220766,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -218539,8 +220795,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -218564,8 +220820,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -218752,7 +221008,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -218780,7 +221040,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -218900,8 +221160,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -219091,7 +221351,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -219179,8 +221443,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -219248,7 +221512,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -219288,8 +221552,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -219323,8 +221587,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -219437,8 +221701,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -219476,7 +221740,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -219513,7 +221777,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -219552,8 +221820,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -219580,8 +221848,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -219616,8 +221884,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -219672,7 +221940,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -219701,8 +221969,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -219726,8 +221994,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -219914,7 +222182,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -219942,7 +222214,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -220062,8 +222334,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -220253,7 +222525,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -220341,8 +222617,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -220410,7 +222686,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -220450,8 +222726,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -220485,8 +222761,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -220599,8 +222875,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -220638,7 +222914,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -220675,7 +222951,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -220714,8 +222994,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -220742,8 +223022,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -220778,8 +223058,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -220834,7 +223114,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -220863,8 +223143,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -220888,8 +223168,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -221076,7 +223356,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -221104,7 +223388,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -221224,8 +223508,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -221415,7 +223699,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -221503,8 +223791,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -221572,7 +223860,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -221612,8 +223900,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -221647,8 +223935,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -221761,8 +224049,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -221800,7 +224088,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -221837,7 +224125,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -221876,8 +224168,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -221904,8 +224196,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -221940,8 +224232,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -221996,7 +224288,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -222025,8 +224317,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -222050,8 +224342,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -222238,7 +224530,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -222266,7 +224562,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -222386,8 +224682,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -222577,7 +224873,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -222665,8 +224965,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -222734,7 +225034,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -222774,8 +225074,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -222809,8 +225109,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -222923,8 +225223,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -222962,7 +225262,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -222999,7 +225299,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -223038,8 +225342,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -223066,8 +225370,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -223102,8 +225406,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -223158,7 +225462,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -223187,8 +225491,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -223212,8 +225516,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -223400,7 +225704,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -223428,7 +225736,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -223548,8 +225856,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -223739,7 +226047,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -223827,8 +226139,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -223896,7 +226208,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -223936,8 +226248,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -223971,8 +226283,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -224085,8 +226397,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -224124,7 +226436,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -224161,7 +226473,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -224200,8 +226516,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -224228,8 +226544,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -224264,8 +226580,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -224320,7 +226636,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -224349,8 +226665,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -224374,8 +226690,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -224562,7 +226878,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -224590,7 +226910,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -224710,8 +227030,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -224901,7 +227221,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -224989,8 +227313,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -225058,7 +227382,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -225098,8 +227422,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -225133,8 +227457,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -225247,8 +227571,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -225286,7 +227610,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -225323,7 +227647,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -225362,8 +227690,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -225390,8 +227718,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -225426,8 +227754,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -225482,7 +227810,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -225511,8 +227839,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -225536,8 +227864,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -225724,7 +228052,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -225752,7 +228084,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -225872,8 +228204,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -226063,7 +228395,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -226151,8 +228487,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -226220,7 +228556,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -226260,8 +228596,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -226295,8 +228631,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -226409,8 +228745,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -226448,7 +228784,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -226485,7 +228821,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -226524,8 +228864,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -226552,8 +228892,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -226588,8 +228928,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -226644,7 +228984,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -226673,8 +229013,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -226698,8 +229038,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -226886,7 +229226,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -226914,7 +229258,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -227034,8 +229378,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -227225,7 +229569,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -227313,8 +229661,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -227382,7 +229730,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -227422,8 +229770,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -227457,8 +229805,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -227571,8 +229919,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -227610,7 +229958,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -227647,7 +229995,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -227686,8 +230038,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -227714,8 +230066,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -227750,8 +230102,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -227806,7 +230158,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -227835,8 +230187,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -227860,8 +230212,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -228048,7 +230400,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -228076,7 +230432,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -228196,8 +230552,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -228387,7 +230743,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -228475,8 +230835,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -228544,7 +230904,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -228584,8 +230944,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -228619,8 +230979,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -228733,8 +231093,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -228772,7 +231132,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -228809,7 +231169,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -228848,8 +231212,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -228876,8 +231240,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -228912,8 +231276,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -228968,7 +231332,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -228997,8 +231361,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -229022,8 +231386,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -229210,7 +231574,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -229238,7 +231606,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -229358,8 +231726,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -229549,7 +231917,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -229637,8 +232009,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -229706,7 +232078,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -229746,8 +232118,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -229781,8 +232153,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -229895,8 +232267,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -229934,7 +232306,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -229971,7 +232343,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -230010,8 +232386,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -230038,8 +232414,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -230074,8 +232450,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -230130,7 +232506,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -230159,8 +232535,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -230184,8 +232560,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -230372,7 +232748,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -230400,7 +232780,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -230520,8 +232900,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -230711,7 +233091,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -230799,8 +233183,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -230868,7 +233252,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -230908,8 +233292,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -230943,8 +233327,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -231057,8 +233441,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -231096,7 +233480,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -231133,7 +233517,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -231172,8 +233560,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -231200,8 +233588,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -231236,8 +233624,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -231292,7 +233680,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -231321,8 +233709,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -231346,8 +233734,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -231534,7 +233922,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -231562,7 +233954,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -231682,8 +234074,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -231873,7 +234265,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -231961,8 +234357,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -232030,7 +234426,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -232070,8 +234466,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -232105,8 +234501,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -232219,8 +234615,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -232258,7 +234654,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -232295,7 +234691,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -232334,8 +234734,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -232362,8 +234762,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -232398,8 +234798,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -232454,7 +234854,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -232483,8 +234883,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -232508,8 +234908,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -232696,7 +235096,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -232724,7 +235128,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -232844,8 +235248,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -233035,7 +235439,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -233123,8 +235531,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -233192,7 +235600,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -233232,8 +235640,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -233267,8 +235675,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -233381,8 +235789,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -233420,7 +235828,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -233457,7 +235865,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -233496,8 +235908,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -233524,8 +235936,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -233560,8 +235972,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -233616,7 +236028,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -233645,8 +236057,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -233670,8 +236082,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -233858,7 +236270,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -233886,7 +236302,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -234006,8 +236422,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -234197,7 +236613,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -234285,8 +236705,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -234354,7 +236774,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -234394,8 +236814,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -234429,8 +236849,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -234543,8 +236963,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -234582,7 +237002,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -234619,7 +237039,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -234658,8 +237082,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -234686,8 +237110,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -234722,8 +237146,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -234778,7 +237202,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -234807,8 +237231,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -234832,8 +237256,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -235020,7 +237444,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -235048,7 +237476,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -235168,8 +237596,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -235359,7 +237787,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -235447,8 +237879,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -235516,7 +237948,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -235556,8 +237988,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -235591,8 +238023,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -235705,8 +238137,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -235744,7 +238176,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -235781,7 +238213,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -235820,8 +238256,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -235848,8 +238284,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -235884,8 +238320,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -235940,7 +238376,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -235969,8 +238405,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -235994,8 +238430,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -236182,7 +238618,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -236210,7 +238650,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -236330,8 +238770,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -236521,7 +238961,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -236609,8 +239053,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -236678,7 +239122,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -236718,8 +239162,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -236753,8 +239197,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -236867,8 +239311,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -236906,7 +239350,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -236943,7 +239387,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -236982,8 +239430,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -237010,8 +239458,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -237046,8 +239494,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -237102,7 +239550,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -237131,8 +239579,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -237156,8 +239604,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -237344,7 +239792,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -237372,7 +239824,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -237492,8 +239944,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -237683,7 +240135,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -237771,8 +240227,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -237840,7 +240296,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -237880,8 +240336,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -237915,8 +240371,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -238029,8 +240485,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -238068,7 +240524,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -238105,7 +240561,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -238144,8 +240604,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -238172,8 +240632,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -238208,8 +240668,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -238264,7 +240724,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -238293,8 +240753,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -238318,8 +240778,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -238506,7 +240966,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -238534,7 +240998,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -238654,8 +241118,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -238845,7 +241309,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -238933,8 +241401,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -239002,7 +241470,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -239042,8 +241510,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -239077,8 +241545,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -239191,8 +241659,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -239230,7 +241698,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -239267,7 +241735,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -239306,8 +241778,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -239334,8 +241806,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -239370,8 +241842,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -239426,7 +241898,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -239455,8 +241927,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -239480,8 +241952,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -239668,7 +242140,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -239696,7 +242172,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -239816,8 +242292,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -240007,7 +242483,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -240095,8 +242575,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -240164,7 +242644,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -240204,8 +242684,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -240239,8 +242719,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -240353,8 +242833,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -240392,7 +242872,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -240429,7 +242909,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -240468,8 +242952,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -240496,8 +242980,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -240532,8 +243016,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -240588,7 +243072,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -240617,8 +243101,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -240642,8 +243126,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -240830,7 +243314,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -240858,7 +243346,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -240978,8 +243466,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -241169,7 +243657,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -241257,8 +243749,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -241326,7 +243818,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -241366,8 +243858,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -241401,8 +243893,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -241515,8 +244007,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -241554,7 +244046,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -241591,7 +244083,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -241630,8 +244126,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -241658,8 +244154,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -241694,8 +244190,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -241750,7 +244246,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -241779,8 +244275,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -241804,8 +244300,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -241992,7 +244488,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -242020,7 +244520,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -242140,8 +244640,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -242331,7 +244831,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -242419,8 +244923,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -242488,7 +244992,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -242528,8 +245032,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -242563,8 +245067,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -242677,8 +245181,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -242716,7 +245220,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -242753,7 +245257,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -242792,8 +245300,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -242820,8 +245328,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -242856,8 +245364,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -242912,7 +245420,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -242941,8 +245449,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -242966,8 +245474,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -243154,7 +245662,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -243182,7 +245694,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -243302,8 +245814,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -243493,7 +246005,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -243581,8 +246097,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -243650,7 +246166,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -243690,8 +246206,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -243725,8 +246241,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -243839,8 +246355,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -243878,7 +246394,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -243915,7 +246431,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -243954,8 +246474,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -243982,8 +246502,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -244018,8 +246538,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -244074,7 +246594,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -244103,8 +246623,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -244128,8 +246648,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -244316,7 +246836,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -244344,7 +246868,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -244464,8 +246988,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -244655,7 +247179,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -244743,8 +247271,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -244812,7 +247340,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -244852,8 +247380,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -244887,8 +247415,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -245001,8 +247529,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -245040,7 +247568,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -245077,7 +247605,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -245116,8 +247648,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -245144,8 +247676,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -245180,8 +247712,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -245236,7 +247768,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -245265,8 +247797,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -245290,8 +247822,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -245478,7 +248010,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -245506,7 +248042,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -245626,8 +248162,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -245817,7 +248353,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -245905,8 +248445,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -245974,7 +248514,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -246014,8 +248554,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -246049,8 +248589,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -246163,8 +248703,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -246202,7 +248742,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -246239,7 +248779,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -246278,8 +248822,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -246306,8 +248850,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -246342,8 +248886,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -246398,7 +248942,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -246427,8 +248971,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -246452,8 +248996,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -246640,7 +249184,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -246668,7 +249216,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -246788,8 +249336,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -246979,7 +249527,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -247067,8 +249619,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -247136,7 +249688,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -247176,8 +249728,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -247211,8 +249763,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -247325,8 +249877,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -247364,7 +249916,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -247401,7 +249953,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -247440,8 +249996,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -247468,8 +250024,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -247504,8 +250060,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -247560,7 +250116,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -247589,8 +250145,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -247614,8 +250170,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -247802,7 +250358,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -247830,7 +250390,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -247950,8 +250510,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -248141,7 +250701,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -248229,8 +250793,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -248298,7 +250862,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -248338,8 +250902,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -248373,8 +250937,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -248487,8 +251051,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -248526,7 +251090,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -248563,7 +251127,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -248602,8 +251170,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -248630,8 +251198,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -248666,8 +251234,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -248722,7 +251290,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -248751,8 +251319,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -248776,8 +251344,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -248964,7 +251532,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -248992,7 +251564,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -249112,8 +251684,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -249303,7 +251875,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -249391,8 +251967,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -249460,7 +252036,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -249500,8 +252076,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -249535,8 +252111,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -249649,8 +252225,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -249688,7 +252264,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -249725,7 +252301,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -249764,8 +252344,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -249792,8 +252372,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -249828,8 +252408,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -249884,7 +252464,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -249913,8 +252493,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -249938,8 +252518,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -250126,7 +252706,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -250154,7 +252738,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -250274,8 +252858,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -250465,7 +253049,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -250553,8 +253141,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -250622,7 +253210,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -250662,8 +253250,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -250697,8 +253285,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -250811,8 +253399,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -250850,7 +253438,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -250887,7 +253475,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -250926,8 +253518,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -250954,8 +253546,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -250990,8 +253582,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -251046,7 +253638,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -251075,8 +253667,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -251100,8 +253692,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -251288,7 +253880,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -251316,7 +253912,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -251436,8 +254032,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -251627,7 +254223,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -251715,8 +254315,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -251784,7 +254384,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -251824,8 +254424,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -251859,8 +254459,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -251973,8 +254573,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -252012,7 +254612,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -252049,7 +254649,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -252088,8 +254692,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -252116,8 +254720,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -252152,8 +254756,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -252208,7 +254812,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -252237,8 +254841,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -252262,8 +254866,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -252450,7 +255054,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -252478,7 +255086,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -252598,8 +255206,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -252789,7 +255397,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -252877,8 +255489,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -252946,7 +255558,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -252986,8 +255598,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -253021,8 +255633,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -253135,8 +255747,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -253174,7 +255786,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -253211,7 +255823,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -253250,8 +255866,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -253278,8 +255894,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -253314,8 +255930,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -253370,7 +255986,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -253399,8 +256015,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -253424,8 +256040,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -253612,7 +256228,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -253640,7 +256260,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -253760,8 +256380,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -253951,7 +256571,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -254039,8 +256663,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -254108,7 +256732,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -254148,8 +256772,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -254183,8 +256807,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -254297,8 +256921,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -254336,7 +256960,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -254373,7 +256997,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -254412,8 +257040,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -254440,8 +257068,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -254476,8 +257104,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -254532,7 +257160,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -254561,8 +257189,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -254586,8 +257214,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -254774,7 +257402,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -254802,7 +257434,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -254922,8 +257554,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -255113,7 +257745,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -255201,8 +257837,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -255270,7 +257906,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -255310,8 +257946,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -255345,8 +257981,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -255459,8 +258095,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -255498,7 +258134,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -255535,7 +258171,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -255574,8 +258214,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -255602,8 +258242,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -255638,8 +258278,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -255694,7 +258334,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -255723,8 +258363,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -255748,8 +258388,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -255936,7 +258576,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -255964,7 +258608,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -256084,8 +258728,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -256275,7 +258919,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -256363,8 +259011,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -256432,7 +259080,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -256472,8 +259120,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -256507,8 +259155,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -256621,8 +259269,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -256660,7 +259308,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -256697,7 +259345,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -256736,8 +259388,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -256764,8 +259416,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -256800,8 +259452,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -256856,7 +259508,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -256885,8 +259537,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -256910,8 +259562,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -257098,7 +259750,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -257126,7 +259782,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -257246,8 +259902,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -257437,7 +260093,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -257525,8 +260185,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -257594,7 +260254,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -257634,8 +260294,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -257669,8 +260329,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -257783,8 +260443,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -257822,7 +260482,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -257859,7 +260519,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -257898,8 +260562,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -257926,8 +260590,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -257962,8 +260626,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -258018,7 +260682,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -258047,8 +260711,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -258072,8 +260736,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -258260,7 +260924,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -258288,7 +260956,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -258408,8 +261076,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -258599,7 +261267,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -258687,8 +261359,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -258756,7 +261428,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -258796,8 +261468,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -258831,8 +261503,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -258945,8 +261617,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -258984,7 +261656,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -259021,7 +261693,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -259060,8 +261736,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -259088,8 +261764,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -259124,8 +261800,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -259180,7 +261856,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -259209,8 +261885,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -259234,8 +261910,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -259422,7 +262098,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -259450,7 +262130,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -259570,8 +262250,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -259761,7 +262441,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -259849,8 +262533,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -259918,7 +262602,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -259958,8 +262642,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -259993,8 +262677,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -260107,8 +262791,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -260146,7 +262830,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -260183,7 +262867,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -260222,8 +262910,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -260250,8 +262938,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -260286,8 +262974,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -260342,7 +263030,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -260371,8 +263059,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -260396,8 +263084,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -260584,7 +263272,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -260612,7 +263304,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -260732,8 +263424,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -260923,7 +263615,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -261011,8 +263707,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -261080,7 +263776,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -261120,8 +263816,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -261155,8 +263851,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -261269,8 +263965,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -261308,7 +264004,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -261345,7 +264041,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -261384,8 +264084,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -261412,8 +264112,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -261448,8 +264148,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -261504,7 +264204,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -261533,8 +264233,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -261558,8 +264258,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -261746,7 +264446,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -261774,7 +264478,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -261894,8 +264598,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -262085,7 +264789,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -262173,8 +264881,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -262242,7 +264950,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -262282,8 +264990,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -262317,8 +265025,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -262431,8 +265139,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -262470,7 +265178,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -262507,7 +265215,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -262546,8 +265258,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -262574,8 +265286,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -262610,8 +265322,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -262666,7 +265378,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -262695,8 +265407,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -262720,8 +265432,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -262908,7 +265620,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -262936,7 +265652,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -263056,8 +265772,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -263247,7 +265963,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -263335,8 +266055,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -263404,7 +266124,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -263444,8 +266164,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -263479,8 +266199,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -263593,8 +266313,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -263632,7 +266352,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -263669,7 +266389,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -263708,8 +266432,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -263736,8 +266460,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -263772,8 +266496,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -263828,7 +266552,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -263857,8 +266581,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -263882,8 +266606,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -264070,7 +266794,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -264098,7 +266826,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -264218,8 +266946,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -264409,7 +267137,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -264497,8 +267229,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -264566,7 +267298,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -264606,8 +267338,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -264641,8 +267373,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -264755,8 +267487,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -264794,7 +267526,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -264831,7 +267563,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -264870,8 +267606,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -264898,8 +267634,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -264934,8 +267670,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -264990,7 +267726,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -265019,8 +267755,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -265044,8 +267780,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -265232,7 +267968,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -265260,7 +268000,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -265380,8 +268120,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -265571,7 +268311,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -265659,8 +268403,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -265728,7 +268472,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -265768,8 +268512,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -265803,8 +268547,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -265917,8 +268661,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -265956,7 +268700,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -265993,7 +268737,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -266032,8 +268780,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -266060,8 +268808,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -266096,8 +268844,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -266152,7 +268900,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -266181,8 +268929,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -266206,8 +268954,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -266394,7 +269142,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -266422,7 +269174,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -266542,8 +269294,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -266733,7 +269485,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -266821,8 +269577,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -266890,7 +269646,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -266930,8 +269686,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -266965,8 +269721,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -267079,8 +269835,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -267118,7 +269874,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -267155,7 +269911,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -267194,8 +269954,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -267222,8 +269982,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -267258,8 +270018,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -267314,7 +270074,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -267343,8 +270103,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -267368,8 +270128,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -267556,7 +270316,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -267584,7 +270348,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -267704,8 +270468,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -267895,7 +270659,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -267983,8 +270751,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -268052,7 +270820,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -268092,8 +270860,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -268127,8 +270895,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -268241,8 +271009,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -268280,7 +271048,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -268317,7 +271085,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -268356,8 +271128,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -268384,8 +271156,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -268420,8 +271192,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -268476,7 +271248,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -268505,8 +271277,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -268530,8 +271302,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -268718,7 +271490,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -268746,7 +271522,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -268866,8 +271642,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -269057,7 +271833,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -269145,8 +271925,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -269214,7 +271994,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -269254,8 +272034,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -269289,8 +272069,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -269403,8 +272183,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -269442,7 +272222,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -269479,7 +272259,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -269518,8 +272302,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -269546,8 +272330,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -269582,8 +272366,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -269638,7 +272422,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -269667,8 +272451,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -269692,8 +272476,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -269880,7 +272664,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -269908,7 +272696,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -270028,8 +272816,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -270219,7 +273007,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -270307,8 +273099,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -270376,7 +273168,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -270416,8 +273208,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -270451,8 +273243,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -270565,8 +273357,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -270604,7 +273396,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -270641,7 +273433,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -270680,8 +273476,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -270708,8 +273504,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -270744,8 +273540,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -270800,7 +273596,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -270829,8 +273625,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -270854,8 +273650,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -271042,7 +273838,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -271070,7 +273870,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -271190,8 +273990,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -271381,7 +274181,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -271469,8 +274273,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -271538,7 +274342,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -271578,8 +274382,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -271613,8 +274417,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -271727,8 +274531,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -271766,7 +274570,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -271803,7 +274607,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -271842,8 +274650,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -271870,8 +274678,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -271906,8 +274714,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -271962,7 +274770,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -271991,8 +274799,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -272016,8 +274824,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -272204,7 +275012,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -272232,7 +275044,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -272352,8 +275164,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -272543,7 +275355,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -272631,8 +275447,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -272700,7 +275516,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -272740,8 +275556,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -272775,8 +275591,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -272889,8 +275705,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -272928,7 +275744,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -272965,7 +275781,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -273004,8 +275824,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -273032,8 +275852,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -273068,8 +275888,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -273124,7 +275944,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -273153,8 +275973,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -273178,8 +275998,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -273366,7 +276186,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -273394,7 +276218,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -273514,8 +276338,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -273705,7 +276529,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -273793,8 +276621,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -273862,7 +276690,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -273902,8 +276730,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -273937,8 +276765,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -274051,8 +276879,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -274090,7 +276918,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -274127,7 +276955,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -274166,8 +276998,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -274194,8 +277026,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -274230,8 +277062,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -274286,7 +277118,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -274315,8 +277147,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -274340,8 +277172,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -274528,7 +277360,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -274556,7 +277392,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -274676,8 +277512,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -274867,7 +277703,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -274955,8 +277795,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -275024,7 +277864,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -275064,8 +277904,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -275099,8 +277939,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -275213,8 +278053,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -275252,7 +278092,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -275289,7 +278129,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -275328,8 +278172,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -275356,8 +278200,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -275392,8 +278236,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -275448,7 +278292,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -275477,8 +278321,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -275502,8 +278346,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -275690,7 +278534,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -275718,7 +278566,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -275838,8 +278686,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -276029,7 +278877,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -276117,8 +278969,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -276186,7 +279038,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -276226,8 +279078,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -276261,8 +279113,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -276375,8 +279227,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -276414,7 +279266,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -276451,7 +279303,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -276490,8 +279346,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -276518,8 +279374,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -276554,8 +279410,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -276610,7 +279466,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -276639,8 +279495,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -276664,8 +279520,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -276852,7 +279708,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -276880,7 +279740,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -277000,8 +279860,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -277191,7 +280051,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -277279,8 +280143,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -277348,7 +280212,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -277388,8 +280252,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -277423,8 +280287,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -277537,8 +280401,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -277576,7 +280440,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -277613,7 +280477,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -277652,8 +280520,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -277680,8 +280548,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -277716,8 +280584,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -277772,7 +280640,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -277801,8 +280669,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -277826,8 +280694,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -278014,7 +280882,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -278042,7 +280914,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -278162,8 +281034,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -278353,7 +281225,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -278441,8 +281317,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -278510,7 +281386,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -278550,8 +281426,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -278585,8 +281461,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -278699,8 +281575,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -278738,7 +281614,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -278775,7 +281651,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -278814,8 +281694,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -278842,8 +281722,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -278878,8 +281758,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -278934,7 +281814,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -278963,8 +281843,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -278988,8 +281868,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -279176,7 +282056,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -279204,7 +282088,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -279324,8 +282208,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -279515,7 +282399,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -279603,8 +282491,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -279672,7 +282560,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -279712,8 +282600,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -279747,8 +282635,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -279861,8 +282749,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -279900,7 +282788,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -279937,7 +282825,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -279976,8 +282868,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -280004,8 +282896,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -280040,8 +282932,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -280096,7 +282988,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -280125,8 +283017,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -280150,8 +283042,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -280338,7 +283230,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -280366,7 +283262,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -280486,8 +283382,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -280677,7 +283573,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -280765,8 +283665,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -280834,7 +283734,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -280874,8 +283774,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -280909,8 +283809,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -281023,8 +283923,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -281062,7 +283962,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -281099,7 +283999,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -281138,8 +284042,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -281166,8 +284070,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -281202,8 +284106,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -281258,7 +284162,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -281287,8 +284191,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -281312,8 +284216,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -281500,7 +284404,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -281528,7 +284436,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -281648,8 +284556,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -281839,7 +284747,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -281927,8 +284839,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -281996,7 +284908,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -282036,8 +284948,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -282071,8 +284983,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -282185,8 +285097,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -282224,7 +285136,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -282261,7 +285173,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -282300,8 +285216,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -282328,8 +285244,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -282364,8 +285280,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -282420,7 +285336,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -282449,8 +285365,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -282474,8 +285390,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -282662,7 +285578,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -282690,7 +285610,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -282810,8 +285730,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -283001,7 +285921,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -283089,8 +286013,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -283158,7 +286082,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -283198,8 +286122,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -283233,8 +286157,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -283347,8 +286271,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -283386,7 +286310,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -283423,7 +286347,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -283462,8 +286390,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -283490,8 +286418,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -283526,8 +286454,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -283582,7 +286510,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -283611,8 +286539,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -283636,8 +286564,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -283824,7 +286752,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -283852,7 +286784,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -283972,8 +286904,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -284163,7 +287095,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -284251,8 +287187,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -284320,7 +287256,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -284360,8 +287296,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -284395,8 +287331,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -284509,8 +287445,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -284548,7 +287484,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -284585,7 +287521,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -284624,8 +287564,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -284652,8 +287592,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -284688,8 +287628,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -284744,7 +287684,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -284773,8 +287713,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -284798,8 +287738,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -284986,7 +287926,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -285014,7 +287958,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -285134,8 +288078,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -285325,7 +288269,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -285413,8 +288361,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -285482,7 +288430,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -285522,8 +288470,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -285557,8 +288505,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -285671,8 +288619,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -285710,7 +288658,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -285747,7 +288695,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -285786,8 +288738,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -285814,8 +288766,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -285850,8 +288802,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -285906,7 +288858,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -285935,8 +288887,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -285960,8 +288912,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -286148,7 +289100,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -286176,7 +289132,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -286296,8 +289252,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -286487,7 +289443,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -286575,8 +289535,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -286644,7 +289604,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -286684,8 +289644,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -286719,8 +289679,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -286833,8 +289793,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -286872,7 +289832,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -286909,7 +289869,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -286948,8 +289912,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -286976,8 +289940,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -287012,8 +289976,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -287068,7 +290032,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -287097,8 +290061,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -287122,8 +290086,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -287310,7 +290274,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -287338,7 +290306,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -287458,8 +290426,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -287649,7 +290617,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -287737,8 +290709,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -287806,7 +290778,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -287846,8 +290818,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -287881,8 +290853,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -287995,8 +290967,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -288034,7 +291006,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -288071,7 +291043,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -288110,8 +291086,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -288138,8 +291114,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -288174,8 +291150,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -288230,7 +291206,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -288259,8 +291235,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -288284,8 +291260,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -288472,7 +291448,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -288500,7 +291480,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -288620,8 +291600,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -288811,7 +291791,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -288899,8 +291883,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -288968,7 +291952,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -289008,8 +291992,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -289043,8 +292027,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -289157,8 +292141,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -289196,7 +292180,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -289233,7 +292217,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -289272,8 +292260,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -289300,8 +292288,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -289336,8 +292324,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -289392,7 +292380,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -289421,8 +292409,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -289446,8 +292434,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -289634,7 +292622,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -289662,7 +292654,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -289782,8 +292774,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -289973,7 +292965,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -290061,8 +293057,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -290130,7 +293126,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -290170,8 +293166,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -290205,8 +293201,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -290319,8 +293315,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -290358,7 +293354,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -290395,7 +293391,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -290434,8 +293434,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -290462,8 +293462,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -290498,8 +293498,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -290554,7 +293554,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -290583,8 +293583,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -290608,8 +293608,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -290796,7 +293796,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -290824,7 +293828,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -290944,8 +293948,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -291135,7 +294139,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -291223,8 +294231,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -291292,7 +294300,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -291332,8 +294340,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -291367,8 +294375,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -291481,8 +294489,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -291520,7 +294528,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -291557,7 +294565,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -291596,8 +294608,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -291624,8 +294636,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -291660,8 +294672,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -291716,7 +294728,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -291745,8 +294757,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -291770,8 +294782,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -291958,7 +294970,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -291986,7 +295002,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -292106,8 +295122,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -292297,7 +295313,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -292385,8 +295405,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -292454,7 +295474,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -292494,8 +295514,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -292529,8 +295549,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -292643,8 +295663,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -292682,7 +295702,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -292719,7 +295739,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -292758,8 +295782,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -292786,8 +295810,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -292822,8 +295846,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -292878,7 +295902,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -292907,8 +295931,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -292932,8 +295956,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -293120,7 +296144,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -293148,7 +296176,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -293268,8 +296296,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -293459,7 +296487,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -293547,8 +296579,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -293616,7 +296648,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -293656,8 +296688,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -293691,8 +296723,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -293805,8 +296837,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -293844,7 +296876,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -293881,7 +296913,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -293920,8 +296956,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -293948,8 +296984,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -293984,8 +297020,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -294040,7 +297076,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -294069,8 +297105,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -294094,8 +297130,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -294282,7 +297318,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -294310,7 +297350,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -294430,8 +297470,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -294621,7 +297661,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -294709,8 +297753,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -294778,7 +297822,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -294818,8 +297862,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -294853,8 +297897,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -294967,8 +298011,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -295006,7 +298050,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -295043,7 +298087,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -295082,8 +298130,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -295110,8 +298158,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -295146,8 +298194,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -295202,7 +298250,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -295231,8 +298279,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -295256,8 +298304,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -295444,7 +298492,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -295472,7 +298524,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -295592,8 +298644,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -295783,7 +298835,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -295871,8 +298927,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -295940,7 +298996,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -295980,8 +299036,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -296015,8 +299071,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -296129,8 +299185,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -296168,7 +299224,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -296205,7 +299261,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -296244,8 +299304,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -296272,8 +299332,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -296308,8 +299368,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -296364,7 +299424,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -296393,8 +299453,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -296418,8 +299478,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -296606,7 +299666,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -296634,7 +299698,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -296754,8 +299818,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -296945,7 +300009,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -297033,8 +300101,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -297102,7 +300170,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -297142,8 +300210,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -297177,8 +300245,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -297291,8 +300359,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -297330,7 +300398,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -297367,7 +300435,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -297406,8 +300478,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -297434,8 +300506,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -297470,8 +300542,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -297526,7 +300598,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -297555,8 +300627,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -297580,8 +300652,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -297768,7 +300840,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -297796,7 +300872,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -297916,8 +300992,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -298107,7 +301183,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -298195,8 +301275,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -298264,7 +301344,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -298304,8 +301384,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -298339,8 +301419,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -298453,8 +301533,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -298492,7 +301572,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -298529,7 +301609,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -298568,8 +301652,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -298596,8 +301680,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -298632,8 +301716,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -298688,7 +301772,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -298717,8 +301801,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -298742,8 +301826,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -298930,7 +302014,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -298958,7 +302046,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -299078,8 +302166,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -299269,7 +302357,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -299357,8 +302449,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -299426,7 +302518,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -299466,8 +302558,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -299501,8 +302593,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -299615,8 +302707,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -299654,7 +302746,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -299691,7 +302783,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -299730,8 +302826,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -299758,8 +302854,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -299794,8 +302890,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -299850,7 +302946,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -299879,8 +302975,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -299904,8 +303000,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -300092,7 +303188,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -300120,7 +303220,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -300240,8 +303340,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -300431,7 +303531,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -300519,8 +303623,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -300588,7 +303692,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -300628,8 +303732,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -300663,8 +303767,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -300777,8 +303881,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -300816,7 +303920,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -300853,7 +303957,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -300892,8 +304000,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -300920,8 +304028,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -300956,8 +304064,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -301012,7 +304120,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -301041,8 +304149,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -301066,8 +304174,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -301254,7 +304362,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -301282,7 +304394,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -301402,8 +304514,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -301593,7 +304705,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -301681,8 +304797,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -301750,7 +304866,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -301790,8 +304906,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -301825,8 +304941,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -301939,8 +305055,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -301978,7 +305094,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -302015,7 +305131,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -302054,8 +305174,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -302082,8 +305202,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -302118,8 +305238,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -302174,7 +305294,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -302203,8 +305323,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -302228,8 +305348,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -302416,7 +305536,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -302444,7 +305568,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -302564,8 +305688,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -302755,7 +305879,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -302843,8 +305971,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -302912,7 +306040,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -302952,8 +306080,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -302987,8 +306115,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -303101,8 +306229,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -303140,7 +306268,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -303177,7 +306305,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -303216,8 +306348,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -303244,8 +306376,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -303280,8 +306412,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -303336,7 +306468,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -303365,8 +306497,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -303390,8 +306522,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -303578,7 +306710,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -303606,7 +306742,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -303726,8 +306862,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -303917,7 +307053,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -304005,8 +307145,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -304074,7 +307214,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -304114,8 +307254,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -304149,8 +307289,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -304263,8 +307403,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -304302,7 +307442,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -304339,7 +307479,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -304378,8 +307522,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -304406,8 +307550,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -304442,8 +307586,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -304498,7 +307642,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -304527,8 +307671,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -304552,8 +307696,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -304740,7 +307884,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -304768,7 +307916,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -304888,8 +308036,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -305079,7 +308227,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -305167,8 +308319,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -305236,7 +308388,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -305276,8 +308428,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -305311,8 +308463,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -305425,8 +308577,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -305464,7 +308616,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -305501,7 +308653,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -305540,8 +308696,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -305568,8 +308724,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -305604,8 +308760,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -305660,7 +308816,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -305689,8 +308845,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -305714,8 +308870,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -305902,7 +309058,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -305930,7 +309090,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -306050,8 +309210,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -306241,7 +309401,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -306329,8 +309493,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -306398,7 +309562,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -306438,8 +309602,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -306473,8 +309637,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -306587,8 +309751,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -306626,7 +309790,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -306663,7 +309827,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -306702,8 +309870,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -306730,8 +309898,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -306766,8 +309934,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -306822,7 +309990,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -306851,8 +310019,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -306876,8 +310044,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -307064,7 +310232,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -307092,7 +310264,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -307212,8 +310384,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -307403,7 +310575,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -307491,8 +310667,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -307560,7 +310736,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -307600,8 +310776,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -307635,8 +310811,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -307749,8 +310925,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -307788,7 +310964,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -307825,7 +311001,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -307864,8 +311044,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -307892,8 +311072,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -307928,8 +311108,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -307984,7 +311164,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -308013,8 +311193,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -308038,8 +311218,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -308226,7 +311406,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -308254,7 +311438,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -308374,8 +311558,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -308565,7 +311749,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -308653,8 +311841,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -308722,7 +311910,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -308762,8 +311950,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -308797,8 +311985,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -308911,8 +312099,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -308950,7 +312138,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -308987,7 +312175,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -309026,8 +312218,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -309054,8 +312246,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -309090,8 +312282,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -309146,7 +312338,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -309175,8 +312367,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -309200,8 +312392,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -309388,7 +312580,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -309416,7 +312612,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -309536,8 +312732,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -309727,7 +312923,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -309815,8 +313015,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -309884,7 +313084,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -309924,8 +313124,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -309959,8 +313159,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -310073,8 +313273,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -310112,7 +313312,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -310149,7 +313349,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -310188,8 +313392,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -310216,8 +313420,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -310252,8 +313456,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -310308,7 +313512,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -310337,8 +313541,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -310362,8 +313566,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -310550,7 +313754,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -310578,7 +313786,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -310698,8 +313906,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -310889,7 +314097,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -310977,8 +314189,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -311046,7 +314258,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -311086,8 +314298,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -311121,8 +314333,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -311235,8 +314447,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -311274,7 +314486,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -311311,7 +314523,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -311350,8 +314566,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -311378,8 +314594,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -311414,8 +314630,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -311470,7 +314686,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -311499,8 +314715,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -311524,8 +314740,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -311712,7 +314928,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -311740,7 +314960,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -311860,8 +315080,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -312051,7 +315271,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -312139,8 +315363,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -312208,7 +315432,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -312248,8 +315472,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -312283,8 +315507,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -312397,8 +315621,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -312436,7 +315660,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -312473,7 +315697,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -312512,8 +315740,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -312540,8 +315768,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -312576,8 +315804,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -312632,7 +315860,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -312661,8 +315889,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -312686,8 +315914,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -312874,7 +316102,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -312902,7 +316134,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -313022,8 +316254,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -313213,7 +316445,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -313301,8 +316537,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -313370,7 +316606,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -313410,8 +316646,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -313445,8 +316681,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -313559,8 +316795,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -313598,7 +316834,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -313635,7 +316871,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -313674,8 +316914,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -313702,8 +316942,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -313738,8 +316978,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -313794,7 +317034,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -313823,8 +317063,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -313848,8 +317088,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -314036,7 +317276,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -314064,7 +317308,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -314184,8 +317428,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -314375,7 +317619,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -314463,8 +317711,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -314532,7 +317780,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -314572,8 +317820,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -314607,8 +317855,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -314721,8 +317969,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -314760,7 +318008,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -314797,7 +318045,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -314836,8 +318088,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -314864,8 +318116,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -314900,8 +318152,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -314956,7 +318208,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -314985,8 +318237,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -315010,8 +318262,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -315198,7 +318450,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -315226,7 +318482,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -315346,8 +318602,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -315537,7 +318793,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -315625,8 +318885,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -315694,7 +318954,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -315734,8 +318994,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -315769,8 +319029,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -315883,8 +319143,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -315922,7 +319182,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -315959,7 +319219,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -315998,8 +319262,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -316026,8 +319290,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -316062,8 +319326,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -316118,7 +319382,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -316147,8 +319411,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -316172,8 +319436,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -316360,7 +319624,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -316388,7 +319656,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -316508,8 +319776,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -316699,7 +319967,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -316787,8 +320059,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -316856,7 +320128,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -316896,8 +320168,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -316931,8 +320203,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -317045,8 +320317,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -317084,7 +320356,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -317121,7 +320393,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -317160,8 +320436,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -317188,8 +320464,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -317224,8 +320500,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -317280,7 +320556,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -317309,8 +320585,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -317334,8 +320610,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -317522,7 +320798,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -317550,7 +320830,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -317670,8 +320950,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -317861,7 +321141,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -317949,8 +321233,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -318018,7 +321302,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -318058,8 +321342,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -318093,8 +321377,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -318207,8 +321491,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -318246,7 +321530,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -318283,7 +321567,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -318322,8 +321610,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -318350,8 +321638,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -318386,8 +321674,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -318442,7 +321730,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -318471,8 +321759,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -318496,8 +321784,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -318684,7 +321972,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -318712,7 +322004,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -318832,8 +322124,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -319023,7 +322315,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -319111,8 +322407,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -319180,7 +322476,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -319220,8 +322516,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -319255,8 +322551,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -319369,8 +322665,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -319408,7 +322704,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -319445,7 +322741,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -319484,8 +322784,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -319512,8 +322812,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -319548,8 +322848,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -319604,7 +322904,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -319633,8 +322933,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -319658,8 +322958,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -319846,7 +323146,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -319874,7 +323178,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -319994,8 +323298,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -320185,7 +323489,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -320273,8 +323581,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -320342,7 +323650,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -320382,8 +323690,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -320417,8 +323725,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -320531,8 +323839,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -320570,7 +323878,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -320607,7 +323915,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -320646,8 +323958,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -320674,8 +323986,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -320710,8 +324022,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -320766,7 +324078,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -320795,8 +324107,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -320820,8 +324132,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -321008,7 +324320,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -321036,7 +324352,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -321156,8 +324472,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -321347,7 +324663,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -321435,8 +324755,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -321504,7 +324824,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -321544,8 +324864,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -321579,8 +324899,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -321693,8 +325013,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -321732,7 +325052,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -321769,7 +325089,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -321808,8 +325132,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -321836,8 +325160,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -321872,8 +325196,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -321928,7 +325252,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -321957,8 +325281,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -321982,8 +325306,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -322170,7 +325494,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -322198,7 +325526,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -322318,8 +325646,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -322509,7 +325837,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -322597,8 +325929,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -322666,7 +325998,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -322706,8 +326038,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -322741,8 +326073,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -322855,8 +326187,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -322894,7 +326226,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -322931,7 +326263,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -322970,8 +326306,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -322998,8 +326334,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -323034,8 +326370,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -323090,7 +326426,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -323119,8 +326455,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -323144,8 +326480,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -323332,7 +326668,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -323360,7 +326700,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -323480,8 +326820,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -323671,7 +327011,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -323759,8 +327103,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -323828,7 +327172,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -323868,8 +327212,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -323903,8 +327247,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -324017,8 +327361,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -324056,7 +327400,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -324093,7 +327437,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -324132,8 +327480,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -324160,8 +327508,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -324196,8 +327544,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -324252,7 +327600,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -324281,8 +327629,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -324306,8 +327654,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -324494,7 +327842,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -324522,7 +327874,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -324642,8 +327994,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -324833,7 +328185,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -324921,8 +328277,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -324990,7 +328346,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -325030,8 +328386,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -325065,8 +328421,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -325179,8 +328535,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -325218,7 +328574,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -325255,7 +328611,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -325294,8 +328654,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -325322,8 +328682,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -325358,8 +328718,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -325414,7 +328774,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -325443,8 +328803,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -325468,8 +328828,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -325656,7 +329016,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -325684,7 +329048,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -325804,8 +329168,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -325995,7 +329359,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -326083,8 +329451,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -326152,7 +329520,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -326192,8 +329560,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -326227,8 +329595,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -326341,8 +329709,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -326380,7 +329748,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -326417,7 +329785,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -326456,8 +329828,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -326484,8 +329856,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -326520,8 +329892,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -326576,7 +329948,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -326605,8 +329977,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -326630,8 +330002,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -326818,7 +330190,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -326846,7 +330222,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -326966,8 +330342,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -327157,7 +330533,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -327245,8 +330625,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -327314,7 +330694,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -327354,8 +330734,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -327389,8 +330769,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -327503,8 +330883,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -327542,7 +330922,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -327579,7 +330959,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -327618,8 +331002,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -327646,8 +331030,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -327682,8 +331066,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -327738,7 +331122,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -327767,8 +331151,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -327792,8 +331176,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -327980,7 +331364,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -328008,7 +331396,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -328128,8 +331516,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -328319,7 +331707,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -328407,8 +331799,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -328476,7 +331868,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -328516,8 +331908,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -328551,8 +331943,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -328665,8 +332057,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -328704,7 +332096,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -328741,7 +332133,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -328780,8 +332176,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -328808,8 +332204,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -328844,8 +332240,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -328900,7 +332296,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -328929,8 +332325,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -328954,8 +332350,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -329142,7 +332538,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -329170,7 +332570,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -329290,8 +332690,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -329481,7 +332881,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -329569,8 +332973,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -329638,7 +333042,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -329678,8 +333082,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -329713,8 +333117,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -329827,8 +333231,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -329866,7 +333270,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -329903,7 +333307,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -329942,8 +333350,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -329970,8 +333378,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -330006,8 +333414,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -330062,7 +333470,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -330091,8 +333499,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -330116,8 +333524,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -330304,7 +333712,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -330332,7 +333744,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -330452,8 +333864,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -330643,7 +334055,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -330731,8 +334147,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -330800,7 +334216,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -330840,8 +334256,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -330875,8 +334291,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -330989,8 +334405,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -331028,7 +334444,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -331065,7 +334481,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -331104,8 +334524,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -331132,8 +334552,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -331168,8 +334588,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -331224,7 +334644,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -331253,8 +334673,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -331278,8 +334698,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -331466,7 +334886,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -331494,7 +334918,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -331614,8 +335038,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -331805,7 +335229,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -331893,8 +335321,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -331962,7 +335390,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -332002,8 +335430,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -332037,8 +335465,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -332151,8 +335579,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -332190,7 +335618,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -332227,7 +335655,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -332266,8 +335698,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -332294,8 +335726,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -332330,8 +335762,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -332386,7 +335818,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -332415,8 +335847,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -332440,8 +335872,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -332628,7 +336060,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -332656,7 +336092,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -332776,8 +336212,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -332967,7 +336403,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -333055,8 +336495,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -333124,7 +336564,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -333164,8 +336604,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -333199,8 +336639,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -333313,8 +336753,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -333352,7 +336792,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -333389,7 +336829,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -333428,8 +336872,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -333456,8 +336900,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -333492,8 +336936,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -333548,7 +336992,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -333577,8 +337021,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -333602,8 +337046,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -333790,7 +337234,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -333818,7 +337266,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -333938,8 +337386,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -334129,7 +337577,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -334217,8 +337669,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -334286,7 +337738,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -334326,8 +337778,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -334361,8 +337813,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -334475,8 +337927,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -334514,7 +337966,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -334551,7 +338003,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -334590,8 +338046,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -334618,8 +338074,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -334654,8 +338110,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -334710,7 +338166,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -334739,8 +338195,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -334764,8 +338220,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -334952,7 +338408,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -334980,7 +338440,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -335100,8 +338560,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -335291,7 +338751,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -335379,8 +338843,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -335448,7 +338912,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -335488,8 +338952,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -335523,8 +338987,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -335637,8 +339101,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -335676,7 +339140,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -335713,7 +339177,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -335752,8 +339220,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -335780,8 +339248,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -335816,8 +339284,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -335872,7 +339340,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -335901,8 +339369,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -335926,8 +339394,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -336114,7 +339582,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -336142,7 +339614,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -336262,8 +339734,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -336453,7 +339925,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -336541,8 +340017,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -336610,7 +340086,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -336650,8 +340126,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -336685,8 +340161,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -336799,8 +340275,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -336838,7 +340314,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -336875,7 +340351,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -336914,8 +340394,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -336942,8 +340422,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -336978,8 +340458,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -337034,7 +340514,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -337063,8 +340543,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -337088,8 +340568,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -337276,7 +340756,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -337304,7 +340788,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -337424,8 +340908,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -337615,7 +341099,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -337703,8 +341191,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -337772,7 +341260,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -337812,8 +341300,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -337847,8 +341335,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -337961,8 +341449,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -338000,7 +341488,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -338037,7 +341525,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -338076,8 +341568,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -338104,8 +341596,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -338140,8 +341632,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -338196,7 +341688,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -338225,8 +341717,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -338250,8 +341742,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -338438,7 +341930,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -338466,7 +341962,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -338586,8 +342082,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -338777,7 +342273,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -338865,8 +342365,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -338934,7 +342434,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -338974,8 +342474,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -339009,8 +342509,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -339123,8 +342623,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -339162,7 +342662,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -339199,7 +342699,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -339238,8 +342742,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -339266,8 +342770,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -339302,8 +342806,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -339358,7 +342862,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -339387,8 +342891,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -339412,8 +342916,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -339600,7 +343104,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -339628,7 +343136,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -339748,8 +343256,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -339939,7 +343447,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -340027,8 +343539,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -340096,7 +343608,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -340136,8 +343648,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -340171,8 +343683,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -340285,8 +343797,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -340324,7 +343836,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -340361,7 +343873,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -340400,8 +343916,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -340428,8 +343944,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -340464,8 +343980,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -340520,7 +344036,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -340549,8 +344065,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -340574,8 +344090,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -340762,7 +344278,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -340790,7 +344310,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -340910,8 +344430,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -341101,7 +344621,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -341189,8 +344713,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -341258,7 +344782,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -341298,8 +344822,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -341333,8 +344857,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -341447,8 +344971,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -341486,7 +345010,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -341523,7 +345047,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -341562,8 +345090,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -341590,8 +345118,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -341626,8 +345154,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -341682,7 +345210,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -341711,8 +345239,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -341736,8 +345264,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -341924,7 +345452,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -341952,7 +345484,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -342072,8 +345604,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -342263,7 +345795,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -342351,8 +345887,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -342420,7 +345956,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -342460,8 +345996,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -342495,8 +346031,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -342609,8 +346145,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -342648,7 +346184,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -342685,7 +346221,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -342724,8 +346264,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -342752,8 +346292,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -342788,8 +346328,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -342844,7 +346384,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -342873,8 +346413,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -342898,8 +346438,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -343086,7 +346626,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -343114,7 +346658,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -343234,8 +346778,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -343425,7 +346969,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -343513,8 +347061,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -343582,7 +347130,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -343622,8 +347170,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -343657,8 +347205,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -343771,8 +347319,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -343810,7 +347358,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -343847,7 +347395,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -343886,8 +347438,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -343914,8 +347466,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -343950,8 +347502,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -344006,7 +347558,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -344035,8 +347587,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -344060,8 +347612,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -344248,7 +347800,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -344276,7 +347832,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -344396,8 +347952,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -344587,7 +348143,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -344675,8 +348235,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -344744,7 +348304,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -344784,8 +348344,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -344819,8 +348379,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -344933,8 +348493,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -344972,7 +348532,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -345009,7 +348569,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -345048,8 +348612,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -345076,8 +348640,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -345112,8 +348676,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -345168,7 +348732,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -345197,8 +348761,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -345222,8 +348786,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -345410,7 +348974,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -345438,7 +349006,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -345558,8 +349126,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -345749,7 +349317,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -345837,8 +349409,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -345906,7 +349478,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -345946,8 +349518,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -345981,8 +349553,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -346095,8 +349667,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -346134,7 +349706,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -346171,7 +349743,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -346210,8 +349786,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -346238,8 +349814,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -346274,8 +349850,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -346330,7 +349906,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -346359,8 +349935,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -346384,8 +349960,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -346572,7 +350148,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -346600,7 +350180,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -346720,8 +350300,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -346911,7 +350491,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -346999,8 +350583,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -347068,7 +350652,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -347108,8 +350692,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -347143,8 +350727,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -347257,8 +350841,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -347296,7 +350880,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -347333,7 +350917,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -347372,8 +350960,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -347400,8 +350988,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -347436,8 +351024,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -347492,7 +351080,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -347521,8 +351109,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -347546,8 +351134,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -347734,7 +351322,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -347762,7 +351354,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -347882,8 +351474,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -348073,7 +351665,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -348161,8 +351757,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -348230,7 +351826,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -348270,8 +351866,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -348305,8 +351901,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -348419,8 +352015,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -348458,7 +352054,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -348495,7 +352091,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -348534,8 +352134,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -348562,8 +352162,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -348598,8 +352198,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -348654,7 +352254,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -348683,8 +352283,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -348708,8 +352308,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -348896,7 +352496,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -348924,7 +352528,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -349044,8 +352648,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -349235,7 +352839,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -349323,8 +352931,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -349392,7 +353000,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -349432,8 +353040,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -349467,8 +353075,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -349581,8 +353189,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -349620,7 +353228,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -349657,7 +353265,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -349696,8 +353308,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -349724,8 +353336,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -349760,8 +353372,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -349816,7 +353428,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -349845,8 +353457,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -349870,8 +353482,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -350058,7 +353670,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -350086,7 +353702,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -350206,8 +353822,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -350397,7 +354013,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -350485,8 +354105,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -350554,7 +354174,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -350594,8 +354214,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -350629,8 +354249,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -350743,8 +354363,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -350782,7 +354402,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -350819,7 +354439,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -350858,8 +354482,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -350886,8 +354510,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -350922,8 +354546,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -350978,7 +354602,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -351007,8 +354631,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -351032,8 +354656,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -351220,7 +354844,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -351248,7 +354876,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -351368,8 +354996,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -351559,7 +355187,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -351647,8 +355279,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -351716,7 +355348,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -351756,8 +355388,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -351791,8 +355423,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -351905,8 +355537,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -351944,7 +355576,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -351981,7 +355613,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -352020,8 +355656,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -352048,8 +355684,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -352084,8 +355720,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -352140,7 +355776,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -352169,8 +355805,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -352194,8 +355830,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -352382,7 +356018,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -352410,7 +356050,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -352530,8 +356170,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -352721,7 +356361,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -352809,8 +356453,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -352878,7 +356522,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -352918,8 +356562,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -352953,8 +356597,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -353067,8 +356711,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -353106,7 +356750,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -353143,7 +356787,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -353182,8 +356830,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -353210,8 +356858,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -353246,8 +356894,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -353302,7 +356950,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -353331,8 +356979,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -353356,8 +357004,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -353544,7 +357192,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -353572,7 +357224,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -353692,8 +357344,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -353883,7 +357535,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -353971,8 +357627,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -354040,7 +357696,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -354080,8 +357736,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -354115,8 +357771,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -354229,8 +357885,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -354268,7 +357924,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -354305,7 +357961,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -354344,8 +358004,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -354372,8 +358032,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -354408,8 +358068,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -354464,7 +358124,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -354493,8 +358153,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -354518,8 +358178,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -354706,7 +358366,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -354734,7 +358398,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -354854,8 +358518,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -355045,7 +358709,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -355133,8 +358801,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -355202,7 +358870,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -355242,8 +358910,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -355277,8 +358945,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -355391,8 +359059,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -355430,7 +359098,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -355467,7 +359135,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -355506,8 +359178,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -355534,8 +359206,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -355570,8 +359242,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -355626,7 +359298,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -355655,8 +359327,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -355680,8 +359352,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -355868,7 +359540,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -355896,7 +359572,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -356016,8 +359692,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -356207,7 +359883,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -356295,8 +359975,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -356364,7 +360044,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -356404,8 +360084,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -356439,8 +360119,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -356553,8 +360233,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -356592,7 +360272,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -356629,7 +360309,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -356668,8 +360352,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -356696,8 +360380,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -356732,8 +360416,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -356788,7 +360472,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -356817,8 +360501,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -356842,8 +360526,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -357030,7 +360714,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -357058,7 +360746,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -357178,8 +360866,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -357369,7 +361057,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -357457,8 +361149,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -357526,7 +361218,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -357566,8 +361258,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -357601,8 +361293,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -357715,8 +361407,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -357754,7 +361446,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -357791,7 +361483,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -357830,8 +361526,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -357858,8 +361554,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -357894,8 +361590,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -357950,7 +361646,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -357979,8 +361675,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -358004,8 +361700,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -358192,7 +361888,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -358220,7 +361920,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -358340,8 +362040,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -358531,7 +362231,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -358619,8 +362323,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -358688,7 +362392,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -358728,8 +362432,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -358763,8 +362467,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -358877,8 +362581,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -358916,7 +362620,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -358953,7 +362657,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -358992,8 +362700,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -359020,8 +362728,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -359056,8 +362764,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -359112,7 +362820,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -359141,8 +362849,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -359166,8 +362874,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -359354,7 +363062,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -359382,7 +363094,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -359502,8 +363214,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -359693,7 +363405,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -359781,8 +363497,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -359850,7 +363566,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -359890,8 +363606,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -359925,8 +363641,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -360039,8 +363755,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -360078,7 +363794,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -360115,7 +363831,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -360154,8 +363874,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -360182,8 +363902,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -360218,8 +363938,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -360274,7 +363994,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -360303,8 +364023,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -360328,8 +364048,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -360516,7 +364236,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -360544,7 +364268,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -360664,8 +364388,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -360855,7 +364579,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -360943,8 +364671,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -361012,7 +364740,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -361052,8 +364780,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -361087,8 +364815,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -361201,8 +364929,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -361240,7 +364968,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -361277,7 +365005,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -361316,8 +365048,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -361344,8 +365076,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -361380,8 +365112,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -361436,7 +365168,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -361465,8 +365197,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -361490,8 +365222,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -361678,7 +365410,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -361706,7 +365442,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -361826,8 +365562,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -362017,7 +365753,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -362105,8 +365845,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -362174,7 +365914,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -362214,8 +365954,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -362249,8 +365989,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -362363,8 +366103,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -362402,7 +366142,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -362439,7 +366179,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -362478,8 +366222,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -362506,8 +366250,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -362542,8 +366286,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -362598,7 +366342,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -362627,8 +366371,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -362652,8 +366396,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -362840,7 +366584,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -362868,7 +366616,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -362988,8 +366736,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -363179,7 +366927,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -363267,8 +367019,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -363336,7 +367088,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -363376,8 +367128,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -363411,8 +367163,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -363525,8 +367277,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -363564,7 +367316,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -363601,7 +367353,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -363640,8 +367396,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -363668,8 +367424,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -363704,8 +367460,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -363760,7 +367516,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -363789,8 +367545,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -363814,8 +367570,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -364002,7 +367758,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -364030,7 +367790,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -364150,8 +367910,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -364341,7 +368101,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -364429,8 +368193,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -364498,7 +368262,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -364538,8 +368302,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -364573,8 +368337,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -364687,8 +368451,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -364726,7 +368490,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -364763,7 +368527,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -364802,8 +368570,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -364830,8 +368598,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -364866,8 +368634,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -364922,7 +368690,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -364951,8 +368719,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -364976,8 +368744,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -365164,7 +368932,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -365192,7 +368964,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -365312,8 +369084,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -365503,7 +369275,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -365591,8 +369367,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -365660,7 +369436,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -365700,8 +369476,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -365735,8 +369511,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -365849,8 +369625,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -365888,7 +369664,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -365925,7 +369701,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -365964,8 +369744,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -365992,8 +369772,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -366028,8 +369808,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -366084,7 +369864,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -366113,8 +369893,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -366138,8 +369918,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -366326,7 +370106,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -366354,7 +370138,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -366474,8 +370258,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -366665,7 +370449,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -366753,8 +370541,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -366822,7 +370610,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -366862,8 +370650,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -366897,8 +370685,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -367011,8 +370799,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -367050,7 +370838,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -367087,7 +370875,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -367126,8 +370918,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -367154,8 +370946,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -367190,8 +370982,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -367246,7 +371038,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -367275,8 +371067,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -367300,8 +371092,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -367488,7 +371280,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -367516,7 +371312,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -367636,8 +371432,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -367827,7 +371623,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -367915,8 +371715,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -367984,7 +371784,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -368024,8 +371824,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -368059,8 +371859,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -368173,8 +371973,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -368212,7 +372012,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -368249,7 +372049,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -368288,8 +372092,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -368316,8 +372120,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -368352,8 +372156,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -368408,7 +372212,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -368437,8 +372241,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -368462,8 +372266,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -368650,7 +372454,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -368678,7 +372486,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -368798,8 +372606,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -368989,7 +372797,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -369077,8 +372889,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -369146,7 +372958,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -369186,8 +372998,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -369221,8 +373033,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -369335,8 +373147,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -369374,7 +373186,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -369411,7 +373223,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -369450,8 +373266,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -369478,8 +373294,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -369514,8 +373330,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -369570,7 +373386,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -369599,8 +373415,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -369624,8 +373440,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -369812,7 +373628,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -369840,7 +373660,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -369960,8 +373780,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -370151,7 +373971,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -370239,8 +374063,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -370308,7 +374132,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -370348,8 +374172,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -370383,8 +374207,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -370497,8 +374321,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -370536,7 +374360,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -370573,7 +374397,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -370612,8 +374440,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -370640,8 +374468,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -370676,8 +374504,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -370732,7 +374560,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -370761,8 +374589,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -370786,8 +374614,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -370974,7 +374802,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -371002,7 +374834,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -371122,8 +374954,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -371313,7 +375145,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -371401,8 +375237,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -371470,7 +375306,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -371510,8 +375346,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -371545,8 +375381,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -371659,8 +375495,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -371698,7 +375534,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -371735,7 +375571,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -371774,8 +375614,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -371802,8 +375642,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -371838,8 +375678,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -371894,7 +375734,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -371923,8 +375763,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -371948,8 +375788,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -372136,7 +375976,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -372164,7 +376008,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -372284,8 +376128,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -372475,7 +376319,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -372563,8 +376411,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -372632,7 +376480,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -372672,8 +376520,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -372707,8 +376555,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -372821,8 +376669,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -372860,7 +376708,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -372897,7 +376745,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -372936,8 +376788,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -372964,8 +376816,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -373000,8 +376852,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -373056,7 +376908,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -373085,8 +376937,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -373110,8 +376962,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -373298,7 +377150,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -373326,7 +377182,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -373446,8 +377302,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -373637,7 +377493,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -373725,8 +377585,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -373794,7 +377654,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -373834,8 +377694,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -373869,8 +377729,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -373983,8 +377843,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -374022,7 +377882,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -374059,7 +377919,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -374098,8 +377962,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -374126,8 +377990,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -374162,8 +378026,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -374218,7 +378082,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -374247,8 +378111,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -374272,8 +378136,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -374460,7 +378324,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -374488,7 +378356,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -374608,8 +378476,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -374799,7 +378667,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -374887,8 +378759,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -374956,7 +378828,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -374996,8 +378868,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -375031,8 +378903,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -375145,8 +379017,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -375184,7 +379056,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -375221,7 +379093,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -375260,8 +379136,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -375288,8 +379164,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -375324,8 +379200,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -375380,7 +379256,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -375409,8 +379285,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -375434,8 +379310,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -375622,7 +379498,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -375650,7 +379530,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -375770,8 +379650,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -375961,7 +379841,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -376049,8 +379933,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -376118,7 +380002,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -376158,8 +380042,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -376193,8 +380077,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -376307,8 +380191,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -376346,7 +380230,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -376383,7 +380267,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -376422,8 +380310,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -376450,8 +380338,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -376486,8 +380374,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -376542,7 +380430,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -376571,8 +380459,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -376596,8 +380484,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -376784,7 +380672,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -376812,7 +380704,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -376932,8 +380824,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -377123,7 +381015,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -377211,8 +381107,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -377280,7 +381176,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -377320,8 +381216,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -377355,8 +381251,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -377469,8 +381365,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -377508,7 +381404,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -377545,7 +381441,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -377584,8 +381484,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -377612,8 +381512,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -377648,8 +381548,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -377704,7 +381604,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -377733,8 +381633,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -377758,8 +381658,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -377946,7 +381846,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -377974,7 +381878,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -378094,8 +381998,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -378285,7 +382189,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -378373,8 +382281,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -378442,7 +382350,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -378482,8 +382390,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -378517,8 +382425,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -378631,8 +382539,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -378670,7 +382578,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -378707,7 +382615,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -378746,8 +382658,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -378774,8 +382686,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -378810,8 +382722,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -378866,7 +382778,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -378895,8 +382807,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -378920,8 +382832,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -379108,7 +383020,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -379136,7 +383052,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -379256,8 +383172,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -379447,7 +383363,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -379535,8 +383455,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -379604,7 +383524,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -379644,8 +383564,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -379679,8 +383599,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -379793,8 +383713,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -379832,7 +383752,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -379869,7 +383789,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -379908,8 +383832,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -379936,8 +383860,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -379972,8 +383896,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -380028,7 +383952,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -380057,8 +383981,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -380082,8 +384006,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -380270,7 +384194,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -380298,7 +384226,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -380418,8 +384346,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -380609,7 +384537,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -380697,8 +384629,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -380766,7 +384698,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -380806,8 +384738,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -380841,8 +384773,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -380955,8 +384887,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -380994,7 +384926,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -381031,7 +384963,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -381070,8 +385006,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -381098,8 +385034,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -381134,8 +385070,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -381190,7 +385126,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -381219,8 +385155,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -381244,8 +385180,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -381432,7 +385368,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -381460,7 +385400,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -381580,8 +385520,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -381771,7 +385711,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -381859,8 +385803,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -381928,7 +385872,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -381968,8 +385912,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -382003,8 +385947,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -382117,8 +386061,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -382156,7 +386100,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -382193,7 +386137,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -382232,8 +386180,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -382260,8 +386208,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -382296,8 +386244,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -382352,7 +386300,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -382381,8 +386329,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -382406,8 +386354,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -382594,7 +386542,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -382622,7 +386574,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -382742,8 +386694,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -382933,7 +386885,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -383021,8 +386977,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -383090,7 +387046,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -383130,8 +387086,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -383165,8 +387121,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -383279,8 +387235,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -383318,7 +387274,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -383355,7 +387311,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -383394,8 +387354,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -383422,8 +387382,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -383458,8 +387418,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -383514,7 +387474,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -383543,8 +387503,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -383568,8 +387528,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -383756,7 +387716,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -383784,7 +387748,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -383904,8 +387868,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -384095,7 +388059,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -384183,8 +388151,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -384252,7 +388220,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -384292,8 +388260,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -384327,8 +388295,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -384441,8 +388409,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -384480,7 +388448,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -384517,7 +388485,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -384556,8 +388528,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -384584,8 +388556,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -384620,8 +388592,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -384676,7 +388648,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -384705,8 +388677,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -384730,8 +388702,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -384918,7 +388890,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -384946,7 +388922,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -385066,8 +389042,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -385257,7 +389233,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -385345,8 +389325,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -385414,7 +389394,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -385454,8 +389434,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -385489,8 +389469,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -385603,8 +389583,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -385642,7 +389622,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -385679,7 +389659,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -385718,8 +389702,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -385746,8 +389730,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -385782,8 +389766,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -385838,7 +389822,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -385867,8 +389851,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -385892,8 +389876,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -386080,7 +390064,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -386108,7 +390096,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -386228,8 +390216,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -386419,7 +390407,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -386507,8 +390499,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -386576,7 +390568,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -386616,8 +390608,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -386651,8 +390643,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -386765,8 +390757,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -386804,7 +390796,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -386841,7 +390833,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -386880,8 +390876,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -386908,8 +390904,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -386944,8 +390940,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -387000,7 +390996,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -387029,8 +391025,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -387054,8 +391050,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -387242,7 +391238,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -387270,7 +391270,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -387390,8 +391390,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -387581,7 +391581,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -387669,8 +391673,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -387738,7 +391742,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -387778,8 +391782,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -387813,8 +391817,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -387927,8 +391931,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -387966,7 +391970,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -388003,7 +392007,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -388042,8 +392050,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -388070,8 +392078,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -388106,8 +392114,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -388162,7 +392170,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -388191,8 +392199,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -388216,8 +392224,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -388404,7 +392412,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -388432,7 +392444,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -388552,8 +392564,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -388743,7 +392755,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -388831,8 +392847,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -388900,7 +392916,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -388940,8 +392956,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -388975,8 +392991,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -389089,8 +393105,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -389128,7 +393144,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -389165,7 +393181,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -389204,8 +393224,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -389232,8 +393252,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -389268,8 +393288,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -389324,7 +393344,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -389353,8 +393373,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -389378,8 +393398,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -389566,7 +393586,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -389594,7 +393618,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -389714,8 +393738,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -389905,7 +393929,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -389993,8 +394021,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -390062,7 +394090,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -390102,8 +394130,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -390137,8 +394165,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -390251,8 +394279,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -390290,7 +394318,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -390327,7 +394355,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -390366,8 +394398,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -390394,8 +394426,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -390430,8 +394462,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -390486,7 +394518,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -390515,8 +394547,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -390540,8 +394572,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -390728,7 +394760,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -390756,7 +394792,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -390876,8 +394912,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -391067,7 +395103,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -391155,8 +395195,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -391224,7 +395264,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -391264,8 +395304,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -391299,8 +395339,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -391413,8 +395453,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -391452,7 +395492,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -391489,7 +395529,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -391528,8 +395572,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -391556,8 +395600,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -391592,8 +395636,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -391648,7 +395692,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -391677,8 +395721,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -391702,8 +395746,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -391890,7 +395934,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -391918,7 +395966,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -392038,8 +396086,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -392229,7 +396277,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -392317,8 +396369,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -392386,7 +396438,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -392426,8 +396478,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -392461,8 +396513,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -392575,8 +396627,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -392614,7 +396666,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -392651,7 +396703,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -392690,8 +396746,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -392718,8 +396774,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -392754,8 +396810,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -392810,7 +396866,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -392839,8 +396895,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -392864,8 +396920,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -393052,7 +397108,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -393080,7 +397140,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -393200,8 +397260,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -393391,7 +397451,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -393479,8 +397543,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -393548,7 +397612,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -393588,8 +397652,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -393623,8 +397687,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -393737,8 +397801,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -393776,7 +397840,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -393813,7 +397877,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -393852,8 +397920,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -393880,8 +397948,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -393916,8 +397984,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -393972,7 +398040,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -394001,8 +398069,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -394026,8 +398094,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -394214,7 +398282,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -394242,7 +398314,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -394362,8 +398434,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -394553,7 +398625,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -394641,8 +398717,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -394710,7 +398786,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -394750,8 +398826,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -394785,8 +398861,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -394899,8 +398975,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -394938,7 +399014,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -394975,7 +399051,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -395014,8 +399094,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -395042,8 +399122,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -395078,8 +399158,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -395134,7 +399214,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -395163,8 +399243,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -395188,8 +399268,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -395376,7 +399456,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -395404,7 +399488,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -395524,8 +399608,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -395715,7 +399799,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -395803,8 +399891,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -395872,7 +399960,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -395912,8 +400000,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -395947,8 +400035,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -396061,8 +400149,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -396100,7 +400188,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -396137,7 +400225,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -396176,8 +400268,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -396204,8 +400296,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -396240,8 +400332,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -396296,7 +400388,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -396325,8 +400417,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -396350,8 +400442,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -396538,7 +400630,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -396566,7 +400662,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -396686,8 +400782,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -396877,7 +400973,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -396965,8 +401065,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -397034,7 +401134,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -397074,8 +401174,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -397109,8 +401209,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -397223,8 +401323,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -397262,7 +401362,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -397299,7 +401399,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -397338,8 +401442,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -397366,8 +401470,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -397402,8 +401506,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -397458,7 +401562,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -397487,8 +401591,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -397512,8 +401616,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -397700,7 +401804,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -397728,7 +401836,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -397848,8 +401956,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -398039,7 +402147,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -398127,8 +402239,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -398196,7 +402308,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -398236,8 +402348,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -398271,8 +402383,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -398385,8 +402497,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -398424,7 +402536,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -398461,7 +402573,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -398500,8 +402616,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -398528,8 +402644,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -398564,8 +402680,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -398620,7 +402736,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -398649,8 +402765,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -398674,8 +402790,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -398862,7 +402978,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -398890,7 +403010,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -399010,8 +403130,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -399201,7 +403321,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -399289,8 +403413,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -399358,7 +403482,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -399398,8 +403522,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -399433,8 +403557,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -399547,8 +403671,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -399586,7 +403710,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -399623,7 +403747,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -399662,8 +403790,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -399690,8 +403818,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -399726,8 +403854,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -399782,7 +403910,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -399811,8 +403939,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -399836,8 +403964,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -400024,7 +404152,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -400052,7 +404184,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -400172,8 +404304,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -400363,7 +404495,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -400451,8 +404587,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -400520,7 +404656,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -400560,8 +404696,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -400595,8 +404731,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -400709,8 +404845,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -400748,7 +404884,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -400785,7 +404921,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -400824,8 +404964,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -400852,8 +404992,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -400888,8 +405028,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -400944,7 +405084,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -400973,8 +405113,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -400998,8 +405138,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -401186,7 +405326,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -401214,7 +405358,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -401334,8 +405478,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -401525,7 +405669,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -401613,8 +405761,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -401682,7 +405830,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -401722,8 +405870,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -401757,8 +405905,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -401871,8 +406019,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -401910,7 +406058,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -401947,7 +406095,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -401986,8 +406138,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -402014,8 +406166,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -402050,8 +406202,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -402106,7 +406258,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -402135,8 +406287,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -402160,8 +406312,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -402348,7 +406500,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -402376,7 +406532,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -402496,8 +406652,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -402687,7 +406843,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -402775,8 +406935,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -402844,7 +407004,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -402884,8 +407044,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -402919,8 +407079,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -403033,8 +407193,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -403072,7 +407232,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -403109,7 +407269,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -403148,8 +407312,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -403176,8 +407340,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -403212,8 +407376,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -403268,7 +407432,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -403297,8 +407461,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -403322,8 +407486,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -403510,7 +407674,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -403538,7 +407706,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -403658,8 +407826,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -403849,7 +408017,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -403937,8 +408109,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -404006,7 +408178,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -404046,8 +408218,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -404081,8 +408253,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -404195,8 +408367,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -404234,7 +408406,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -404271,7 +408443,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -404310,8 +408486,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -404338,8 +408514,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -404374,8 +408550,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -404430,7 +408606,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -404459,8 +408635,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -404484,8 +408660,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -404672,7 +408848,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -404700,7 +408880,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -404820,8 +409000,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -405011,7 +409191,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -405099,8 +409283,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -405168,7 +409352,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -405208,8 +409392,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -405243,8 +409427,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -405357,8 +409541,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -405396,7 +409580,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -405433,7 +409617,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -405472,8 +409660,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -405500,8 +409688,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -405536,8 +409724,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -405592,7 +409780,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -405621,8 +409809,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -405646,8 +409834,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -405834,7 +410022,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -405862,7 +410054,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -405982,8 +410174,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -406173,7 +410365,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -406261,8 +410457,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -406330,7 +410526,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -406370,8 +410566,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -406405,8 +410601,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -406519,8 +410715,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -406558,7 +410754,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -406595,7 +410791,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -406634,8 +410834,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -406662,8 +410862,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -406698,8 +410898,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -406754,7 +410954,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -406783,8 +410983,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -406808,8 +411008,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -406996,7 +411196,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -407024,7 +411228,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -407144,8 +411348,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -407335,7 +411539,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -407423,8 +411631,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -407492,7 +411700,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -407532,8 +411740,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -407567,8 +411775,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -407681,8 +411889,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -407720,7 +411928,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -407757,7 +411965,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -407796,8 +412008,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -407824,8 +412036,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -407860,8 +412072,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, @@ -407916,7 +412128,7 @@ {}, { "techniqueID": "T1003", - "score": 28, + "score": 29, "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, {}, @@ -407945,8 +412157,8 @@ }, { "techniqueID": "T1543", - "score": 5, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_ransomware_known_service_name.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_process_service_hijacking_via_mimikatz_modules.yml" }, {}, {}, @@ -407970,8 +412182,8 @@ }, { "techniqueID": "T1003.002", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, {}, {}, @@ -408158,7 +412370,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1140", + "score": 1, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, {}, {}, {}, @@ -408186,7 +412402,7 @@ {}, { "techniqueID": "T1036", - "score": 9, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___system_process_running_unexpected_location.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml" }, { @@ -408306,8 +412522,8 @@ {}, { "techniqueID": "T1505.003", - "score": 1, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, {}, {}, @@ -408497,7 +412713,11 @@ {}, {}, {}, - {}, + { + "techniqueID": "T1204", + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clop_common_exec_parameter.yml" + }, {}, {}, {}, @@ -408585,8 +412805,8 @@ }, { "techniqueID": "T1136.003", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_createaccesskey.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_createloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_updateloginprofile.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_add_app_role_assignment_grant_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_added_service_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/o365_new_federated_domain_added.yml" }, {}, {}, @@ -408654,7 +412874,7 @@ {}, { "techniqueID": "T1078", - "score": 42, + "score": 44, "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_saml_access_by_provider_user_and_principal.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_saml_update_identity_provider.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_api_calls_from_previously_unseen_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_city.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_country.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_ip_address.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_provisioning_from_previously_unseen_region.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_accounts_with_high_risk_roles_by_project.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_high_risk_permissions_by_resource_and_account.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/gcp_detect_oauth_token_abuse.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_policies_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_accounts_groups_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, {}, @@ -408694,8 +412914,8 @@ {}, { "techniqueID": "T1486", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "score": 6, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, {}, {}, @@ -408729,8 +412949,8 @@ {}, { "techniqueID": "T1036.003", - "score": 6, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "score": 7, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, {}, { @@ -408843,8 +413063,8 @@ {}, { "techniqueID": "T1485", - "score": 2, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "score": 3, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, {}, {}, @@ -408882,7 +413102,7 @@ {}, { "techniqueID": "T1136", - "score": 7, + "score": 10, "comment": "https://github.com/splunk/security_content/blob/develop/detections/web_fraud___account_harvesting.yml" }, {}, @@ -408919,7 +413139,11 @@ }, {}, {}, - {}, + { + "techniqueID": "T1105", + "score": 2, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" + }, {}, {}, {}, @@ -408958,8 +413182,8 @@ {}, { "techniqueID": "T1078.004", - "score": 15, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "score": 17, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, {}, {}, @@ -408986,8 +413210,8 @@ {}, { "techniqueID": "T1490", - "score": 3, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" + "score": 4, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/bcdedit_failure_recovery_modification.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/deleting_shadow_copies.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/resize_shadowstorage_volume.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/wbadmin_delete_system_backups.yml" }, {}, { @@ -409022,8 +413246,8 @@ {}, { "techniqueID": "T1127", - "score": 4, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" + "score": 5, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_usage.yml" }, {}, {}, diff --git a/docs/mitre-map/detections.csv b/docs/mitre-map/detections.csv index f599cb017b..d503881f9e 100644 --- a/docs/mitre-map/detections.csv +++ b/docs/mitre-map/detections.csv @@ -7743,358 +7743,710 @@ T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,38 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,38 T1059.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_wake_on_lan_command.yml,38 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 -T1105,No,-,42 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml,40 +T1105,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml,40 T1060,No,-,40 T1547.001,Yes,https://github.com/splunk/security_content/blob/develop/detections/registry_keys_used_for_persistence.yml,39 T1060,No,-,40 @@ -31680,7 +32032,7 @@ T1055,Yes,https://github.com/splunk/security_content/blob/develop/detections/sus T1076,No,-,21 T1021.001,No,-,21 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31688,7 +32040,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31696,7 +32048,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31704,7 +32056,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31712,7 +32064,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31720,7 +32072,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31728,7 +32080,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31736,7 +32088,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31744,7 +32096,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31752,7 +32104,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31760,7 +32112,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31768,7 +32120,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31776,7 +32128,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31784,7 +32136,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31792,7 +32144,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31800,7 +32152,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31808,7 +32160,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31816,7 +32168,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31824,7 +32176,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31832,7 +32184,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31840,7 +32192,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31848,7 +32200,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31856,7 +32208,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31864,7 +32216,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31872,7 +32224,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31880,7 +32232,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31888,7 +32240,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31896,7 +32248,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31904,7 +32256,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31912,7 +32264,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31920,7 +32272,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31928,7 +32280,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31936,7 +32288,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31944,7 +32296,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31952,7 +32304,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31960,7 +32312,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31968,7 +32320,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31976,7 +32328,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31984,7 +32336,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -31992,7 +32344,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32000,7 +32352,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32008,7 +32360,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32016,7 +32368,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32024,7 +32376,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32032,7 +32384,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32040,7 +32392,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32048,7 +32400,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32056,7 +32408,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32064,7 +32416,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32072,7 +32424,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32080,7 +32432,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32088,7 +32440,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32096,7 +32448,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32104,7 +32456,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32112,7 +32464,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32120,7 +32472,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32128,7 +32480,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32136,7 +32488,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32144,7 +32496,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32152,7 +32504,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32160,7 +32512,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32168,7 +32520,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32176,7 +32528,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32184,7 +32536,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32192,7 +32544,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32200,7 +32552,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32208,7 +32560,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32216,7 +32568,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32224,7 +32576,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32232,7 +32584,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32240,7 +32592,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32248,7 +32600,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32256,7 +32608,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32264,7 +32616,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32272,7 +32624,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32280,7 +32632,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32288,7 +32640,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32296,7 +32648,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32304,7 +32656,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32312,7 +32664,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32320,7 +32672,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32328,7 +32680,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32336,7 +32688,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32344,7 +32696,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32352,7 +32704,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32360,7 +32712,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32368,7 +32720,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32376,7 +32728,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32384,7 +32736,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32392,7 +32744,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32400,7 +32752,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32408,7 +32760,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32416,7 +32768,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32424,7 +32776,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32432,7 +32784,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32440,7 +32792,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32448,7 +32800,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32456,7 +32808,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32464,7 +32816,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32472,7 +32824,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32480,7 +32832,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32488,7 +32840,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32496,7 +32848,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32504,7 +32856,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32512,7 +32864,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32520,7 +32872,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32528,7 +32880,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32536,7 +32888,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32544,7 +32896,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32552,7 +32904,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32560,7 +32912,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32568,7 +32920,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32576,7 +32928,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32584,7 +32936,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32592,7 +32944,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32600,7 +32952,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32608,7 +32960,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32616,7 +32968,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32624,7 +32976,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32632,7 +32984,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32640,7 +32992,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32648,7 +33000,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32656,7 +33008,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32664,7 +33016,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32672,7 +33024,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32680,7 +33032,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32688,7 +33040,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32696,7 +33048,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32704,7 +33056,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32712,7 +33064,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32720,7 +33072,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32728,7 +33080,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32736,7 +33088,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32744,7 +33096,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32752,7 +33104,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32760,7 +33112,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32768,7 +33120,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32776,7 +33128,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32784,7 +33136,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32792,7 +33144,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32800,7 +33152,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32808,7 +33160,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32816,7 +33168,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32824,7 +33176,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32832,7 +33184,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32840,7 +33192,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32848,7 +33200,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32856,7 +33208,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32864,7 +33216,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32872,7 +33224,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32880,7 +33232,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32888,7 +33240,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32896,7 +33248,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32904,7 +33256,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32912,7 +33264,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32920,7 +33272,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32928,7 +33280,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32936,7 +33288,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32944,7 +33296,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32952,7 +33304,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32960,7 +33312,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32968,7 +33320,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32976,7 +33328,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32984,7 +33336,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -32992,7 +33344,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33000,7 +33352,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33008,7 +33360,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33016,7 +33368,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33024,7 +33376,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33032,7 +33384,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33040,7 +33392,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33048,7 +33400,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33056,7 +33408,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33064,7 +33416,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33072,7 +33424,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33080,7 +33432,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33088,7 +33440,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33096,7 +33448,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33104,7 +33456,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33112,7 +33464,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33120,7 +33472,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33128,7 +33480,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33136,7 +33488,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33144,7 +33496,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33152,7 +33504,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33160,7 +33512,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33168,7 +33520,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33176,7 +33528,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33184,7 +33536,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33192,7 +33544,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33200,7 +33552,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33208,7 +33560,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33216,7 +33568,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33224,7 +33576,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33232,7 +33584,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33240,7 +33592,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33248,7 +33600,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33256,7 +33608,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33264,7 +33616,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33272,7 +33624,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33280,7 +33632,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33288,7 +33640,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33296,7 +33648,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33304,7 +33656,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33312,7 +33664,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33320,7 +33672,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33328,7 +33680,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33336,7 +33688,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33344,7 +33696,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33352,7 +33704,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33360,7 +33712,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33368,7 +33720,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33376,7 +33728,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33384,7 +33736,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33392,7 +33744,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33400,7 +33752,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33408,7 +33760,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33416,7 +33768,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33424,7 +33776,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33432,7 +33784,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33440,7 +33792,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33448,7 +33800,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33456,7 +33808,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33464,7 +33816,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33472,7 +33824,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33480,7 +33832,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33488,7 +33840,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33496,7 +33848,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33504,7 +33856,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33512,7 +33864,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33520,7 +33872,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33528,7 +33880,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33536,7 +33888,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33544,7 +33896,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33552,7 +33904,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33560,7 +33912,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33568,7 +33920,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33576,7 +33928,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33584,7 +33936,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33592,7 +33944,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33600,7 +33952,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33608,7 +33960,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33616,7 +33968,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33624,7 +33976,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33632,7 +33984,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33640,7 +33992,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33648,7 +34000,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33656,7 +34008,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33664,7 +34016,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33672,7 +34024,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33680,7 +34032,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33688,7 +34040,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33696,7 +34048,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33704,7 +34056,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33712,7 +34064,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33720,7 +34072,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33728,7 +34080,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33736,7 +34088,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33744,7 +34096,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33752,7 +34104,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33760,7 +34112,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33768,7 +34120,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33776,7 +34128,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33784,7 +34136,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33792,7 +34144,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33800,7 +34152,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33808,7 +34160,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33816,7 +34168,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33824,7 +34176,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33832,7 +34184,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33840,7 +34192,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33848,7 +34200,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33856,7 +34208,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33864,7 +34216,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33872,7 +34224,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33880,7 +34232,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33888,7 +34240,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33896,7 +34248,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33904,7 +34256,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33912,7 +34264,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33920,7 +34272,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33928,7 +34280,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33936,7 +34288,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33944,7 +34296,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33952,7 +34304,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33960,7 +34312,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33968,7 +34320,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33976,7 +34328,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33984,7 +34336,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -33992,7 +34344,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34000,7 +34352,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34008,7 +34360,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34016,7 +34368,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34024,7 +34376,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34032,7 +34384,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34040,7 +34392,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34048,7 +34400,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34056,7 +34408,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34064,7 +34416,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34072,7 +34424,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34080,7 +34432,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34088,7 +34440,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34096,7 +34448,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34104,7 +34456,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34112,7 +34464,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34120,7 +34472,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34128,7 +34480,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34136,7 +34488,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34144,7 +34496,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34152,7 +34504,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34160,7 +34512,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34168,7 +34520,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34176,7 +34528,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34184,7 +34536,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34192,7 +34544,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34200,7 +34552,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34208,7 +34560,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34216,7 +34568,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34224,7 +34576,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34232,7 +34584,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34240,7 +34592,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34248,7 +34600,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34256,7 +34608,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34264,7 +34616,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34272,7 +34624,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34280,7 +34632,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34288,7 +34640,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34296,7 +34648,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34304,7 +34656,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34312,7 +34664,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34320,7 +34672,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34328,7 +34680,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34336,7 +34688,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34344,7 +34696,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34352,7 +34704,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34360,7 +34712,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34368,7 +34720,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34376,7 +34728,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34384,7 +34736,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34392,7 +34744,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34400,7 +34752,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34408,7 +34760,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34416,7 +34768,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34424,7 +34776,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34432,7 +34784,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34440,7 +34792,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34448,7 +34800,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34456,7 +34808,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34464,7 +34816,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34472,7 +34824,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34480,7 +34832,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -34488,7 +34840,7 @@ T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1018,No,-,20 T1204.001,No,-,20 T1056.001,No,-,20 -T1140,No,-,20 +T1140,Yes,https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml,19 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml,16 T1059,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml,16 @@ -59488,1060 +59840,1412 @@ T1571,No,-,11 T1073,No,-,11 T1574.002,No,-,11 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1119,No,-,10 -T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,9 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml,8 +T1505.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml,8 T1100,No,-,10 T1143,No,-,9 T1559.002,No,-,9 @@ -76736,7 +77440,8 @@ T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml,4 T1048.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,4 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -76773,7 +77478,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -76810,7 +77516,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -76847,7 +77554,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -76884,7 +77592,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -76921,7 +77630,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -76958,7 +77668,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -76995,7 +77706,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -77032,7 +77744,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -77069,7 +77782,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -77106,7 +77820,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -77143,7 +77858,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -77180,7 +77896,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -77217,7 +77934,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -77254,7 +77972,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -77291,7 +78010,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -77328,7 +78048,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -77365,7 +78086,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -77402,7 +78124,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -77439,7 +78162,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -77476,7 +78200,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -77513,7 +78238,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -77550,7 +78276,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -77587,7 +78314,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -77624,7 +78352,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -77661,7 +78390,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -77698,7 +78428,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -77735,7 +78466,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -77772,7 +78504,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -77809,7 +78542,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -77846,7 +78580,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -77883,7 +78618,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -77920,7 +78656,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -77957,7 +78694,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -77994,7 +78732,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -78031,7 +78770,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -78068,7 +78808,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -78105,7 +78846,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -78142,7 +78884,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -78179,7 +78922,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -78216,7 +78960,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -78253,7 +78998,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -78290,7 +79036,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -78327,7 +79074,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -78364,7 +79112,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -78401,7 +79150,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -78438,7 +79188,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -78475,7 +79226,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -78512,7 +79264,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -78549,7 +79302,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -78586,7 +79340,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -78623,7 +79378,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -78660,7 +79416,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -78697,7 +79454,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -78734,7 +79492,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -78771,7 +79530,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -78808,7 +79568,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -78845,7 +79606,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -78882,7 +79644,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -78919,7 +79682,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -78956,7 +79720,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -78993,7 +79758,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -79030,7 +79796,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -79067,7 +79834,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -79104,7 +79872,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -79141,7 +79910,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -79178,7 +79948,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -79215,7 +79986,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -79252,7 +80024,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -79289,7 +80062,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -79326,7 +80100,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -79363,7 +80138,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -79400,7 +80176,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -79437,7 +80214,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -79474,7 +80252,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -79511,7 +80290,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -79548,7 +80328,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -79585,7 +80366,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -79622,7 +80404,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -79659,7 +80442,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -79696,7 +80480,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -79733,7 +80518,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -79770,7 +80556,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -79807,7 +80594,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -79844,7 +80632,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -79881,7 +80670,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -79918,7 +80708,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -79955,7 +80746,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -79992,7 +80784,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -80029,7 +80822,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -80066,7 +80860,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -80103,7 +80898,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -80140,7 +80936,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -80177,7 +80974,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -80214,7 +81012,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -80251,7 +81050,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -80288,7 +81088,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -80325,7 +81126,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -80362,7 +81164,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -80399,7 +81202,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -80436,7 +81240,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -80473,7 +81278,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -80510,7 +81316,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -80547,7 +81354,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -80584,7 +81392,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -80621,7 +81430,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -80658,7 +81468,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -80695,7 +81506,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -80732,7 +81544,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -80769,7 +81582,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -80806,7 +81620,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -80843,7 +81658,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -80880,7 +81696,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -80917,7 +81734,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -80954,7 +81772,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -80991,7 +81810,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -81028,7 +81848,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -81065,7 +81886,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -81102,7 +81924,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -81139,7 +81962,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -81176,7 +82000,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -81213,7 +82038,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -81250,7 +82076,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -81287,7 +82114,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -81324,7 +82152,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -81361,7 +82190,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -81398,7 +82228,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -81435,7 +82266,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -81472,7 +82304,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -81509,7 +82342,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -81546,7 +82380,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -81583,7 +82418,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -81620,7 +82456,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -81657,7 +82494,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -81694,7 +82532,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -81731,7 +82570,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -81768,7 +82608,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -81805,7 +82646,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -81842,7 +82684,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -81879,7 +82722,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -81916,7 +82760,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -81953,7 +82798,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -81990,7 +82836,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -82027,7 +82874,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -82064,7 +82912,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -82101,7 +82950,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -82138,7 +82988,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -82175,7 +83026,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -82212,7 +83064,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -82249,7 +83102,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -82286,7 +83140,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -82323,7 +83178,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -82360,7 +83216,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -82397,7 +83254,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -82434,7 +83292,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -82471,7 +83330,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -82508,7 +83368,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -82545,7 +83406,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -82582,7 +83444,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -82619,7 +83482,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -82656,7 +83520,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -82693,7 +83558,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -82730,7 +83596,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -82767,7 +83634,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -82804,7 +83672,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -82841,7 +83710,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -82878,7 +83748,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -82915,7 +83786,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -82952,7 +83824,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -82989,7 +83862,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -83026,7 +83900,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -83063,7 +83938,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -83100,7 +83976,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -83137,7 +84014,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -83174,7 +84052,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -83211,7 +84090,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -83248,7 +84128,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -83285,7 +84166,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -83322,7 +84204,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -83359,7 +84242,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -83396,7 +84280,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -83433,7 +84318,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -83470,7 +84356,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -83507,7 +84394,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -83544,7 +84432,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -83581,7 +84470,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -83618,7 +84508,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -83655,7 +84546,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -83692,7 +84584,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -83729,7 +84622,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -83766,7 +84660,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -83803,7 +84698,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -83840,7 +84736,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -83877,7 +84774,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -83914,7 +84812,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -83951,7 +84850,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -83988,7 +84888,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -84025,7 +84926,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -84062,7 +84964,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -84099,7 +85002,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -84136,7 +85040,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -84173,7 +85078,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -84210,7 +85116,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -84247,7 +85154,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -84284,7 +85192,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -84321,7 +85230,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -84358,7 +85268,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -84395,7 +85306,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -84432,7 +85344,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -84469,7 +85382,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -84506,7 +85420,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -84543,7 +85458,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -84580,7 +85496,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -84617,7 +85534,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -84654,7 +85572,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -84691,7 +85610,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -84728,7 +85648,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -84765,7 +85686,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -84802,7 +85724,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -84839,7 +85762,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -84876,7 +85800,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -84913,7 +85838,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -84950,7 +85876,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -84987,7 +85914,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -85024,7 +85952,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -85061,7 +85990,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -85098,7 +86028,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -85135,7 +86066,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -85172,7 +86104,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -85209,7 +86142,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -85246,7 +86180,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -85283,7 +86218,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -85320,7 +86256,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -85357,7 +86294,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -85394,7 +86332,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -85431,7 +86370,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -85468,7 +86408,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -85505,7 +86446,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -85542,7 +86484,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -85579,7 +86522,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -85616,7 +86560,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -85653,7 +86598,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -85690,7 +86636,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -85727,7 +86674,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -85764,7 +86712,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -85801,7 +86750,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -85838,7 +86788,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -85875,7 +86826,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -85912,7 +86864,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -85949,7 +86902,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -85986,7 +86940,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -86023,7 +86978,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -86060,7 +87016,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -86097,7 +87054,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -86134,7 +87092,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -86171,7 +87130,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -86208,7 +87168,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -86245,7 +87206,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -86282,7 +87244,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -86319,7 +87282,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -86356,7 +87320,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -86393,7 +87358,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -86430,7 +87396,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -86467,7 +87434,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -86504,7 +87472,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -86541,7 +87510,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -86578,7 +87548,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -86615,7 +87586,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -86652,7 +87624,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -86689,7 +87662,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -86726,7 +87700,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -86763,7 +87738,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -86800,7 +87776,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -86837,7 +87814,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -86874,7 +87852,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -86911,7 +87890,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -86948,7 +87928,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -86985,7 +87966,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -87022,7 +88004,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -87059,7 +88042,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -87096,7 +88080,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -87133,7 +88118,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -87170,7 +88156,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -87207,7 +88194,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -87244,7 +88232,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -87281,7 +88270,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -87318,7 +88308,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -87355,7 +88346,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -87392,7 +88384,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -87429,7 +88422,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -87466,7 +88460,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -87503,7 +88498,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -87540,7 +88536,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -87577,7 +88574,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -87614,7 +88612,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -87651,7 +88650,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -87688,7 +88688,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -87725,7 +88726,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -87762,7 +88764,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -87799,7 +88802,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -87836,7 +88840,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -87873,7 +88878,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -87910,7 +88916,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -87947,7 +88954,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -87984,7 +88992,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -88021,7 +89030,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -88058,7 +89068,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -88095,7 +89106,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -88132,7 +89144,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -88169,7 +89182,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -88206,7 +89220,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -88243,7 +89258,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -88280,7 +89296,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -88317,7 +89334,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -88354,7 +89372,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -88391,7 +89410,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -88428,7 +89448,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -88465,7 +89486,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -88502,7 +89524,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -88539,7 +89562,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -88576,7 +89600,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -88613,7 +89638,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -88650,7 +89676,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -88687,7 +89714,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -88724,7 +89752,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -88761,7 +89790,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -88798,7 +89828,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -88835,7 +89866,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -88872,7 +89904,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -88909,7 +89942,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -88946,7 +89980,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -88983,7 +90018,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -89020,7 +90056,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -89057,7 +90094,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -89094,7 +90132,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -89131,7 +90170,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -89168,7 +90208,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -89205,7 +90246,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -89242,7 +90284,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -89279,7 +90322,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -89316,7 +90360,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -89353,7 +90398,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -89390,7 +90436,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -89427,7 +90474,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -89464,7 +90512,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -89501,7 +90550,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -89538,7 +90588,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -89575,7 +90626,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -89612,7 +90664,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -89649,7 +90702,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -89686,7 +90740,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -89723,7 +90778,8 @@ T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml,3 T1134,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml,3 T1066,No,-,7 -T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,6 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,5 +T1003.002,Yes,https://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml,5 T1587.001,No,-,7 T1573.001,No,-,7 T1069.002,No,-,7 @@ -107731,12 +108787,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -107770,12 +108827,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -107809,12 +108867,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -107848,12 +108907,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -107887,12 +108947,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -107926,12 +108987,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -107965,12 +109027,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -108004,12 +109067,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -108043,12 +109107,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -108082,12 +109147,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -108121,12 +109187,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -108160,12 +109227,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -108199,12 +109267,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -108238,12 +109307,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -108277,12 +109347,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -108316,12 +109387,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -108355,12 +109427,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -108394,12 +109467,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -108433,12 +109507,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -108472,12 +109547,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -108511,12 +109587,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -108550,12 +109627,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -108589,12 +109667,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -108628,12 +109707,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -108667,12 +109747,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -108706,12 +109787,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -108745,12 +109827,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -108784,12 +109867,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -108823,12 +109907,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -108862,12 +109947,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -108901,12 +109987,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -108940,12 +110027,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -108979,12 +110067,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -109018,12 +110107,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -109057,12 +110147,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -109096,12 +110187,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -109135,12 +110227,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -109174,12 +110267,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -109213,12 +110307,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -109252,12 +110347,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -109291,12 +110387,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -109330,12 +110427,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -109369,12 +110467,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -109408,12 +110507,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -109447,12 +110547,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -109486,12 +110587,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -109525,12 +110627,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -109564,12 +110667,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -109603,12 +110707,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -109642,12 +110747,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -109681,12 +110787,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -109720,12 +110827,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -109759,12 +110867,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -109798,12 +110907,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -109837,12 +110947,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -109876,12 +110987,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -109915,12 +111027,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -109954,12 +111067,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -109993,12 +111107,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -110032,12 +111147,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -110071,12 +111187,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -110110,12 +111227,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -110149,12 +111267,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -110188,12 +111307,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -110227,12 +111347,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -110266,12 +111387,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -110305,12 +111427,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -110344,12 +111467,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -110383,12 +111507,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -110422,12 +111547,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -110461,12 +111587,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -110500,12 +111627,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -110539,12 +111667,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -110578,12 +111707,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -110617,12 +111747,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -110656,12 +111787,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -110695,12 +111827,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -110734,12 +111867,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -110773,12 +111907,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -110812,12 +111947,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -110851,12 +111987,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -110890,12 +112027,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -110929,12 +112067,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -110968,12 +112107,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -111007,12 +112147,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -111046,12 +112187,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -111085,12 +112227,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -111124,12 +112267,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -111163,12 +112307,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -111202,12 +112347,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -111241,12 +112387,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -111280,12 +112427,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -111319,12 +112467,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -111358,12 +112507,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -111397,12 +112547,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -111436,12 +112587,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -111475,12 +112627,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -111514,12 +112667,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -111553,12 +112707,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -111592,12 +112747,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -111631,12 +112787,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -111670,12 +112827,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -111709,12 +112867,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -111748,12 +112907,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -111787,12 +112947,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -111826,12 +112987,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -111865,12 +113027,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -111904,12 +113067,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -111943,12 +113107,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -111982,12 +113147,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -112021,12 +113187,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -112060,12 +113227,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -112099,12 +113267,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -112138,12 +113307,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -112177,12 +113347,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -112216,12 +113387,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -112255,12 +113427,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -112294,12 +113467,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -112333,12 +113507,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -112372,12 +113547,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -112411,12 +113587,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -112450,12 +113627,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -112489,12 +113667,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -112528,12 +113707,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -112567,12 +113747,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -112606,12 +113787,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -112645,12 +113827,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -112684,12 +113867,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -112723,12 +113907,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -112762,12 +113947,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -112801,12 +113987,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -112840,12 +114027,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -112879,12 +114067,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -112918,12 +114107,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -112957,12 +114147,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -112996,12 +114187,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -113035,12 +114227,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -113074,12 +114267,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -113113,12 +114307,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -113152,12 +114347,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -113191,12 +114387,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -113230,12 +114427,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -113269,12 +114467,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -113308,12 +114507,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -113347,12 +114547,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -113386,12 +114587,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -113425,12 +114627,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -113464,12 +114667,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -113503,12 +114707,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -113542,12 +114747,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -113581,12 +114787,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -113620,12 +114827,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -113659,12 +114867,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -113698,12 +114907,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -113737,12 +114947,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -113776,12 +114987,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -113815,12 +115027,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -113854,12 +115067,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -113893,12 +115107,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -113932,12 +115147,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -113971,12 +115187,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -114010,12 +115227,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -114049,12 +115267,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -114088,12 +115307,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -114127,12 +115347,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -114166,12 +115387,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -114205,12 +115427,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -114244,12 +115467,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -114283,12 +115507,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -114322,12 +115547,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -114361,12 +115587,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -114400,12 +115627,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -114439,12 +115667,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -114478,12 +115707,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -114517,12 +115747,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -114556,12 +115787,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -114595,12 +115827,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -114634,12 +115867,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -114673,12 +115907,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -114712,12 +115947,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -114751,12 +115987,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -114790,12 +116027,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -114829,12 +116067,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -114868,12 +116107,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -114907,12 +116147,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -114946,12 +116187,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -114985,12 +116227,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -115024,12 +116267,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -115063,12 +116307,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -115102,12 +116347,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -115141,12 +116387,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -115180,12 +116427,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -115219,12 +116467,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -115258,12 +116507,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -115297,12 +116547,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -115336,12 +116587,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -115375,12 +116627,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -115414,12 +116667,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -115453,12 +116707,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -115492,12 +116747,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -115531,12 +116787,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -115570,12 +116827,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -115609,12 +116867,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -115648,12 +116907,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -115687,12 +116947,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -115726,12 +116987,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -115765,12 +117027,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -115804,12 +117067,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -115843,12 +117107,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -115882,12 +117147,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -115921,12 +117187,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -115960,12 +117227,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -115999,12 +117267,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -116038,12 +117307,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -116077,12 +117347,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -116116,12 +117387,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -116155,12 +117427,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -116194,12 +117467,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -116233,12 +117507,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -116272,12 +117547,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -116311,12 +117587,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -116350,12 +117627,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -116389,12 +117667,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -116428,12 +117707,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -116467,12 +117747,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -116506,12 +117787,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -116545,12 +117827,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -116584,12 +117867,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -116623,12 +117907,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -116662,12 +117947,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -116701,12 +117987,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -116740,12 +118027,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -116779,12 +118067,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -116818,12 +118107,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -116857,12 +118147,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -116896,12 +118187,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -116935,12 +118227,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -116974,12 +118267,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -117013,12 +118307,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -117052,12 +118347,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -117091,12 +118387,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -117130,12 +118427,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -117169,12 +118467,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -117208,12 +118507,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -117247,12 +118547,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -117286,12 +118587,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -117325,12 +118627,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -117364,12 +118667,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -117403,12 +118707,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -117442,12 +118747,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -117481,12 +118787,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -117520,12 +118827,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -117559,12 +118867,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -117598,12 +118907,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -117637,12 +118947,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -117676,12 +118987,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -117715,12 +119027,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -117754,12 +119067,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -117793,12 +119107,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -117832,12 +119147,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -117871,12 +119187,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -117910,12 +119227,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -117949,12 +119267,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -117988,12 +119307,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -118027,12 +119347,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -118066,12 +119387,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -118105,12 +119427,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -118144,12 +119467,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -118183,12 +119507,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -118222,12 +119547,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -118261,12 +119587,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -118300,12 +119627,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -118339,12 +119667,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -118378,12 +119707,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -118417,12 +119747,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -118456,12 +119787,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -118495,12 +119827,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -118534,12 +119867,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -118573,12 +119907,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -118612,12 +119947,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -118651,12 +119987,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -118690,12 +120027,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -118729,12 +120067,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -118768,12 +120107,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -118807,12 +120147,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -118846,12 +120187,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -118885,12 +120227,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -118924,12 +120267,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -118963,12 +120307,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -119002,12 +120347,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -119041,12 +120387,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -119080,12 +120427,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -119119,12 +120467,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -119158,12 +120507,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -119197,12 +120547,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -119236,12 +120587,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -119275,12 +120627,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -119314,12 +120667,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -119353,12 +120707,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -119392,12 +120747,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -119431,12 +120787,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -119470,12 +120827,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -119509,12 +120867,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -119548,12 +120907,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -119587,12 +120947,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -119626,12 +120987,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -119665,12 +121027,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -119704,12 +121067,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -119743,12 +121107,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -119782,12 +121147,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -119821,12 +121187,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -119860,12 +121227,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -119899,12 +121267,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -119938,12 +121307,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -119977,12 +121347,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -120016,12 +121387,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -120055,12 +121427,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -120094,12 +121467,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -120133,12 +121507,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -120172,12 +121547,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -120211,12 +121587,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -120250,12 +121627,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -120289,12 +121667,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -120328,12 +121707,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -120367,12 +121747,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -120406,12 +121787,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -120445,12 +121827,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -120484,12 +121867,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -120523,12 +121907,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -120562,12 +121947,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -120601,12 +121987,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -120640,12 +122027,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -120679,12 +122067,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -120718,12 +122107,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -120757,12 +122147,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -120796,12 +122187,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -120835,12 +122227,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -120874,12 +122267,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -120913,12 +122307,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -120952,12 +122347,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -120991,12 +122387,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -121030,12 +122427,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -121069,12 +122467,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -121108,12 +122507,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -121147,12 +122547,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -121186,12 +122587,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -121225,12 +122627,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -121264,12 +122667,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -121303,12 +122707,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -121342,12 +122747,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -121381,12 +122787,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -121420,12 +122827,13 @@ T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml,1 T1039,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml,1 T1055.012,No,-,4 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-2 -T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-2 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml,-3 +T1036.003,Yes,https://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,-3 T1570,No,-,4 T1095,No,-,4 T1496,No,-,4 @@ -121462,18 +122870,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -121504,18 +122915,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -121546,18 +122960,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -121588,18 +123005,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -121630,18 +123050,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -121672,18 +123095,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -121714,18 +123140,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -121756,18 +123185,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -121798,18 +123230,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -121840,18 +123275,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -121882,18 +123320,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -121924,18 +123365,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -121966,18 +123410,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -122008,18 +123455,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -122050,18 +123500,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -122092,18 +123545,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -122134,18 +123590,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -122176,18 +123635,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -122218,18 +123680,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -122260,18 +123725,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -122302,18 +123770,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -122344,18 +123815,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -122386,18 +123860,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -122428,18 +123905,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -122470,18 +123950,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -122512,18 +123995,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -122554,18 +124040,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -122596,18 +124085,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -122638,18 +124130,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -122680,18 +124175,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -122722,18 +124220,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -122764,18 +124265,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -122806,18 +124310,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -122848,18 +124355,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -122890,18 +124400,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -122932,18 +124445,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -122974,18 +124490,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -123016,18 +124535,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -123058,18 +124580,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -123100,18 +124625,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -123142,18 +124670,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -123184,18 +124715,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -123226,18 +124760,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -123268,18 +124805,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -123310,18 +124850,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -123352,18 +124895,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -123394,18 +124940,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -123436,18 +124985,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -123478,18 +125030,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -123520,18 +125075,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -123562,18 +125120,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -123604,18 +125165,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -123646,18 +125210,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -123688,18 +125255,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -123730,18 +125300,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -123772,18 +125345,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -123814,18 +125390,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -123856,18 +125435,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -123898,18 +125480,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -123940,18 +125525,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -123982,18 +125570,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -124024,18 +125615,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -124066,18 +125660,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -124108,18 +125705,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -124150,18 +125750,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -124192,18 +125795,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -124234,18 +125840,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -124276,18 +125885,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -124318,18 +125930,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -124360,18 +125975,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -124402,18 +126020,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -124444,18 +126065,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -124486,18 +126110,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -124528,18 +126155,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -124570,18 +126200,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -124612,18 +126245,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -124654,18 +126290,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -124696,18 +126335,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -124738,18 +126380,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -124780,18 +126425,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -124822,18 +126470,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -124864,18 +126515,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -124906,18 +126560,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -124948,18 +126605,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -124990,18 +126650,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -125032,18 +126695,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -125074,18 +126740,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -125116,18 +126785,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -125158,18 +126830,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -125200,18 +126875,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -125242,18 +126920,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -125284,18 +126965,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -125326,18 +127010,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -125368,18 +127055,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -125410,18 +127100,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -125452,18 +127145,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -125494,18 +127190,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -125536,18 +127235,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -125578,18 +127280,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -125620,18 +127325,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -125662,18 +127370,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -125704,18 +127415,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -125746,18 +127460,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -125788,18 +127505,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -125830,18 +127550,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -125872,18 +127595,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -125914,18 +127640,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -125956,18 +127685,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -125998,18 +127730,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -126040,18 +127775,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -126082,18 +127820,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -126124,18 +127865,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -126166,18 +127910,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -126208,18 +127955,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -126250,18 +128000,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -126292,18 +128045,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -126334,18 +128090,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -126376,18 +128135,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -126418,18 +128180,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -126460,18 +128225,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -126502,18 +128270,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -126544,18 +128315,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -126586,18 +128360,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -126628,18 +128405,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -126670,18 +128450,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -126712,18 +128495,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -126754,18 +128540,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -126796,18 +128585,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -126838,18 +128630,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -126880,18 +128675,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -126922,18 +128720,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -126964,18 +128765,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -127006,18 +128810,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -127048,18 +128855,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -127090,18 +128900,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -127132,18 +128945,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -127174,18 +128990,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -127216,18 +129035,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -127258,18 +129080,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -127300,18 +129125,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -127342,18 +129170,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -127384,18 +129215,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -127426,18 +129260,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -127468,18 +129305,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -127510,18 +129350,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -127552,18 +129395,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -127594,18 +129440,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -127636,18 +129485,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -127678,18 +129530,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -127720,18 +129575,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -127762,18 +129620,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -127804,18 +129665,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -127846,18 +129710,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -127888,18 +129755,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -127930,18 +129800,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -127972,18 +129845,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -128014,18 +129890,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -128056,18 +129935,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -128098,18 +129980,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -128140,18 +130025,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -128182,18 +130070,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -128224,18 +130115,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -128266,18 +130160,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -128308,18 +130205,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -128350,18 +130250,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -128392,18 +130295,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -128434,18 +130340,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -128476,18 +130385,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -128518,18 +130430,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -128560,18 +130475,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -128602,18 +130520,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -128644,18 +130565,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -128686,18 +130610,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -128728,18 +130655,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -128770,18 +130700,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -128812,18 +130745,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -128854,18 +130790,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -128896,18 +130835,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -128938,18 +130880,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -128980,18 +130925,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -129022,18 +130970,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -129064,18 +131015,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -129106,18 +131060,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -129148,18 +131105,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -129190,18 +131150,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -129232,18 +131195,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -129274,18 +131240,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -129316,18 +131285,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -129358,18 +131330,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -129400,18 +131375,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -129442,18 +131420,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -129484,18 +131465,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -129526,18 +131510,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -129568,18 +131555,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -129610,18 +131600,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -129652,18 +131645,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -129694,18 +131690,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -129736,18 +131735,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -129778,18 +131780,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -129820,18 +131825,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -129862,18 +131870,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -129904,18 +131915,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -129946,18 +131960,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -129988,18 +132005,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -130030,18 +132050,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -130072,18 +132095,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -130114,18 +132140,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -130156,18 +132185,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -130198,18 +132230,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -130240,18 +132275,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -130282,18 +132320,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -130324,18 +132365,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -130366,18 +132410,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -130408,18 +132455,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -130450,18 +132500,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -130492,18 +132545,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -130534,18 +132590,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -130576,18 +132635,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -130618,18 +132680,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -130660,18 +132725,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -130702,18 +132770,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -130744,18 +132815,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -130786,18 +132860,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -130828,18 +132905,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -130870,18 +132950,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -130912,18 +132995,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -130954,18 +133040,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -130996,18 +133085,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -131038,18 +133130,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -131080,18 +133175,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -131122,18 +133220,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -131164,18 +133265,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -131206,18 +133310,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -131248,18 +133355,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -131290,18 +133400,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -131332,18 +133445,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -131374,18 +133490,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -131416,18 +133535,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -131458,18 +133580,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -131500,18 +133625,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -131542,18 +133670,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -131584,18 +133715,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -131626,18 +133760,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -131668,18 +133805,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -131710,18 +133850,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -131752,18 +133895,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -131794,18 +133940,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -131836,18 +133985,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -131878,18 +134030,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -131920,18 +134075,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -131962,18 +134120,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -132004,18 +134165,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -132046,18 +134210,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -132088,18 +134255,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -132130,18 +134300,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -132172,18 +134345,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -132214,18 +134390,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -132256,18 +134435,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -132298,18 +134480,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -132340,18 +134525,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -132382,18 +134570,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -132424,18 +134615,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -132466,18 +134660,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -132508,18 +134705,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -132550,18 +134750,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -132592,18 +134795,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -132634,18 +134840,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -132676,18 +134885,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -132718,18 +134930,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -132760,18 +134975,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -132802,18 +135020,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -132844,18 +135065,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -132886,18 +135110,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -132928,18 +135155,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -132970,18 +135200,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -133012,18 +135245,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -133054,18 +135290,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -133096,18 +135335,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -133138,18 +135380,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -133180,18 +135425,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -133222,18 +135470,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -133264,18 +135515,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -133306,18 +135560,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -133348,18 +135605,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -133390,18 +135650,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -133432,18 +135695,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -133474,18 +135740,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -133516,18 +135785,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -133558,18 +135830,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -133600,18 +135875,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -133642,18 +135920,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -133684,18 +135965,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -133726,18 +136010,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -133768,18 +136055,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -133810,18 +136100,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -133852,18 +136145,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -133894,18 +136190,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -133936,18 +136235,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -133978,18 +136280,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -134020,18 +136325,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -134062,18 +136370,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -134104,18 +136415,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -134146,18 +136460,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -134188,18 +136505,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -134230,18 +136550,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -134272,18 +136595,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -134314,18 +136640,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -134356,18 +136685,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -134398,18 +136730,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -134440,18 +136775,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -134482,18 +136820,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -134524,18 +136865,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -134566,18 +136910,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -134608,18 +136955,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -134650,18 +137000,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -134692,18 +137045,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -134734,18 +137090,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -134776,18 +137135,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -134818,18 +137180,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -134860,18 +137225,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -134902,18 +137270,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -134944,18 +137315,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -134986,18 +137360,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -135028,18 +137405,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -135070,18 +137450,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -135112,18 +137495,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -135154,18 +137540,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -135196,18 +137585,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -135238,18 +137630,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -135280,18 +137675,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -135322,18 +137720,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -135364,18 +137765,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -135406,18 +137810,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -135448,18 +137855,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -135490,18 +137900,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -135532,18 +137945,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -135574,18 +137990,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -135616,18 +138035,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -135658,18 +138080,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -135700,18 +138125,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -135742,18 +138170,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -135784,18 +138215,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -135826,18 +138260,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -135868,18 +138305,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -135910,18 +138350,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -135952,18 +138395,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -135994,18 +138440,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -136036,18 +138485,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -136078,18 +138530,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -136120,18 +138575,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -136162,18 +138620,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -136204,18 +138665,21 @@ T1069.001,No,-,3 T1097,No,-,3 T1090.003,No,-,3 T1584.006,No,-,3 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-1 -T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-1 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml,-3 +T1486,Yes,https://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml,-3 T1573,No,-,3 T1028,No,-,3 T1027.004,No,-,3 T1197,No,-,3 T1585,Yes,https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_creation_via_powersploit_modules.yml,2 T1500,No,-,3 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,1 -T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,1 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml,0 +T1485,Yes,https://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml,0 T1498,No,-,3 T1588.003,No,-,3 T1008,No,-,3 @@ -152153,21 +154617,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -152267,21 +154733,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -152381,21 +154849,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -152495,21 +154965,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -152609,21 +155081,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -152723,21 +155197,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -152837,21 +155313,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -152951,21 +155429,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -153065,21 +155545,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -153179,21 +155661,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -153293,21 +155777,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -153407,21 +155893,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -153521,21 +156009,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -153635,21 +156125,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -153749,21 +156241,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -153863,21 +156357,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -153977,21 +156473,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -154091,21 +156589,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -154205,21 +156705,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -154319,21 +156821,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -154433,21 +156937,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -154547,21 +157053,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -154661,21 +157169,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -154775,21 +157285,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -154889,21 +157401,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -155003,21 +157517,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -155117,21 +157633,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -155231,21 +157749,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -155345,21 +157865,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -155459,21 +157981,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -155573,21 +158097,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -155687,21 +158213,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -155801,21 +158329,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -155915,21 +158445,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -156029,21 +158561,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -156143,21 +158677,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -156257,21 +158793,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -156371,21 +158909,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -156485,21 +159025,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -156599,21 +159141,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -156713,21 +159257,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -156827,21 +159373,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -156941,21 +159489,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -157055,21 +159605,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -157169,21 +159721,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -157283,21 +159837,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -157397,21 +159953,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -157511,21 +160069,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -157625,21 +160185,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -157739,21 +160301,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -157853,21 +160417,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -157967,21 +160533,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -158081,21 +160649,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -158195,21 +160765,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -158309,21 +160881,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -158423,21 +160997,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -158537,21 +161113,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -158651,21 +161229,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -158765,21 +161345,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -158879,21 +161461,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -158993,21 +161577,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -159107,21 +161693,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -159221,21 +161809,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -159335,21 +161925,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -159449,21 +162041,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -159563,21 +162157,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -159677,21 +162273,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -159791,21 +162389,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -159905,21 +162505,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -160019,21 +162621,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -160133,21 +162737,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -160247,21 +162853,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -160361,21 +162969,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -160475,21 +163085,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -160589,21 +163201,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -160703,21 +163317,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -160817,21 +163433,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -160931,21 +163549,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -161045,21 +163665,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -161159,21 +163781,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -161273,21 +163897,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -161387,21 +164013,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -161501,21 +164129,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -161615,21 +164245,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -161729,21 +164361,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -161843,21 +164477,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -161957,21 +164593,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -162071,21 +164709,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -162185,21 +164825,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -162299,21 +164941,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -162413,21 +165057,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -162527,21 +165173,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -162641,21 +165289,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -162755,21 +165405,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -162869,21 +165521,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -162983,21 +165637,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -163097,21 +165753,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -163211,21 +165869,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -163325,21 +165985,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -163439,21 +166101,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -163553,21 +166217,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -163667,21 +166333,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -163781,21 +166449,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -163895,21 +166565,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -164009,21 +166681,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -164123,21 +166797,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -164237,21 +166913,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -164351,21 +167029,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -164465,21 +167145,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -164579,21 +167261,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -164693,21 +167377,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -164807,21 +167493,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -164921,21 +167609,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -165035,21 +167725,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -165149,21 +167841,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -165263,21 +167957,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -165377,21 +168073,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -165491,21 +168189,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -165605,21 +168305,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -165719,21 +168421,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -165833,21 +168537,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -165947,21 +168653,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -166061,21 +168769,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -166175,21 +168885,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -166289,21 +169001,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -166403,21 +169117,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -166517,21 +169233,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -166631,21 +169349,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -166745,21 +169465,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -166859,21 +169581,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -166973,21 +169697,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -167087,21 +169813,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -167201,21 +169929,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -167315,21 +170045,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -167429,21 +170161,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -167543,21 +170277,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -167657,21 +170393,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -167771,21 +170509,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -167885,21 +170625,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -167999,21 +170741,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -168113,21 +170857,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -168227,21 +170973,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -168341,21 +171089,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -168455,21 +171205,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -168569,21 +171321,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -168683,21 +171437,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -168797,21 +171553,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -168911,21 +171669,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -169025,21 +171785,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -169139,21 +171901,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -169253,21 +172017,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -169367,21 +172133,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -169481,21 +172249,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -169595,21 +172365,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -169709,21 +172481,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -169823,21 +172597,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -169937,21 +172713,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -170051,21 +172829,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -170165,21 +172945,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -170279,21 +173061,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -170393,21 +173177,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -170507,21 +173293,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -170621,21 +173409,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -170735,21 +173525,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -170849,21 +173641,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -170963,21 +173757,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -171077,21 +173873,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -171191,21 +173989,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -171305,21 +174105,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -171419,21 +174221,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -171533,21 +174337,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -171647,21 +174453,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -171761,21 +174569,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -171875,21 +174685,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -171989,21 +174801,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -172103,21 +174917,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -172217,21 +175033,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -172331,21 +175149,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -172445,21 +175265,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -172559,21 +175381,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -172673,21 +175497,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -172787,21 +175613,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -172901,21 +175729,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -173015,21 +175845,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -173129,21 +175961,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -173243,21 +176077,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -173357,21 +176193,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -173471,21 +176309,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -173585,21 +176425,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -173699,21 +176541,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -173813,21 +176657,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -173927,21 +176773,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -174041,21 +176889,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -174155,21 +177005,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -174269,21 +177121,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -174383,21 +177237,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -174497,21 +177353,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -174611,21 +177469,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -174725,21 +177585,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -174839,21 +177701,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -174953,21 +177817,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -175067,21 +177933,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -175181,21 +178049,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -175295,21 +178165,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -175409,21 +178281,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -175523,21 +178397,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -175637,21 +178513,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -175751,21 +178629,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -175865,21 +178745,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -175979,21 +178861,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -176093,21 +178977,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -176207,21 +179093,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -176321,21 +179209,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -176435,21 +179325,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -176549,21 +179441,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -176663,21 +179557,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -176777,21 +179673,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -176891,21 +179789,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -177005,21 +179905,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -177119,21 +180021,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -177233,21 +180137,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -177347,21 +180253,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -177461,21 +180369,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -177575,21 +180485,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -177689,21 +180601,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -177803,21 +180717,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -177917,21 +180833,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -178031,21 +180949,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -178145,21 +181065,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -178259,21 +181181,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -178373,21 +181297,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -178487,21 +181413,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -178601,21 +181529,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -178715,21 +181645,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -178829,21 +181761,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -178943,21 +181877,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -179057,21 +181993,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -179171,21 +182109,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -179285,21 +182225,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -179399,21 +182341,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -179513,21 +182457,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -179627,21 +182573,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -179741,21 +182689,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -179855,21 +182805,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -179969,21 +182921,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -180083,21 +183037,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -180197,21 +183153,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -180311,21 +183269,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -180425,21 +183385,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -180539,21 +183501,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -180653,21 +183617,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -180767,21 +183733,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -180881,21 +183849,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -180995,21 +183965,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -181109,21 +184081,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -181223,21 +184197,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -181337,21 +184313,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -181451,21 +184429,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -181565,21 +184545,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -181679,21 +184661,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -181793,21 +184777,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -181907,21 +184893,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -182021,21 +185009,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -182135,21 +185125,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -182249,21 +185241,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -182363,21 +185357,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -182477,21 +185473,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -182591,21 +185589,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -182705,21 +185705,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -182819,21 +185821,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -182933,21 +185937,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -183047,21 +186053,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -183161,21 +186169,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -183275,21 +186285,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -183389,21 +186401,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -183503,21 +186517,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -183617,21 +186633,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -183731,21 +186749,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -183845,21 +186865,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -183959,21 +186981,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -184073,21 +187097,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -184187,21 +187213,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -184301,21 +187329,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -184415,21 +187445,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -184529,21 +187561,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -184643,21 +187677,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -184757,21 +187793,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -184871,21 +187909,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -184985,21 +188025,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -185099,21 +188141,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -185213,21 +188257,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -185327,21 +188373,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -185441,21 +188489,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -185555,21 +188605,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -185669,21 +188721,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -185783,21 +188837,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -185897,21 +188953,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -186011,21 +189069,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -186125,21 +189185,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -186239,21 +189301,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -186353,21 +189417,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -186467,21 +189533,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -186581,21 +189649,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -186695,21 +189765,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -186809,21 +189881,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -186923,21 +189997,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -187037,21 +190113,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -187151,21 +190229,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -187265,21 +190345,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -187379,21 +190461,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -187493,21 +190577,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -187607,21 +190693,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -187721,21 +190809,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -187835,21 +190925,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -187949,21 +191041,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -188063,21 +191157,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -188177,21 +191273,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -188291,21 +191389,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -188405,21 +191505,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -188519,21 +191621,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -188633,21 +191737,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -188747,21 +191853,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -188861,21 +191969,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -188975,21 +192085,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -189089,21 +192201,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -189203,21 +192317,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -189317,21 +192433,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -189431,21 +192549,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -189545,21 +192665,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -189659,21 +192781,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -189773,21 +192897,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -189887,21 +193013,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -190001,21 +193129,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -190115,21 +193245,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -190229,21 +193361,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -190343,21 +193477,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -190457,21 +193593,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -190571,21 +193709,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -190685,21 +193825,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -190799,21 +193941,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -190913,21 +194057,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -191027,21 +194173,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -191141,21 +194289,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -191255,21 +194405,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -191369,21 +194521,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -191483,21 +194637,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -191597,21 +194753,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -191711,21 +194869,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -191825,21 +194985,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -191939,21 +195101,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -192053,21 +195217,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 @@ -192167,21 +195333,23 @@ T1126,No,-,1 T1220,No,-,1 T1137.002,No,-,1 T1550.001,No,-,1 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-14 -T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-14 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,-16 +T1078.004,Yes,https://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,-16 T1564.004,No,-,1 T1096,No,-,1 T1003.006,No,-,1 diff --git a/docs/mitre-map/detections.json b/docs/mitre-map/detections.json index 183d476228..9415627bba 100644 --- a/docs/mitre-map/detections.json +++ b/docs/mitre-map/detections.json @@ -15494,1763 +15494,2115 @@ }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1105", - "score": 42, - "showSubtechniques": false + "score": 40, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_urlcache_and_split_arguments.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/certutil_download_with_verifyctl_and_split_arguments.yml" }, { "techniqueID": "T1060", @@ -60203,8 +60555,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -60229,8 +60582,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -60255,8 +60609,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -60281,8 +60636,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -60307,8 +60663,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -60333,8 +60690,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -60359,8 +60717,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -60385,8 +60744,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -60411,8 +60771,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -60437,8 +60798,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -60463,8 +60825,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -60489,8 +60852,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -60515,8 +60879,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -60541,8 +60906,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -60567,8 +60933,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -60593,8 +60960,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -60619,8 +60987,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -60645,8 +61014,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -60671,8 +61041,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -60697,8 +61068,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -60723,8 +61095,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -60749,8 +61122,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -60775,8 +61149,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -60801,8 +61176,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -60827,8 +61203,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -60853,8 +61230,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -60879,8 +61257,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -60905,8 +61284,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -60931,8 +61311,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -60957,8 +61338,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -60983,8 +61365,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -61009,8 +61392,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -61035,8 +61419,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -61061,8 +61446,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -61087,8 +61473,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -61113,8 +61500,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -61139,8 +61527,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -61165,8 +61554,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -61191,8 +61581,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -61217,8 +61608,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -61243,8 +61635,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -61269,8 +61662,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -61295,8 +61689,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -61321,8 +61716,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -61347,8 +61743,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -61373,8 +61770,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -61399,8 +61797,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -61425,8 +61824,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -61451,8 +61851,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -61477,8 +61878,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -61503,8 +61905,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -61529,8 +61932,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -61555,8 +61959,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -61581,8 +61986,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -61607,8 +62013,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -61633,8 +62040,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -61659,8 +62067,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -61685,8 +62094,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -61711,9 +62121,37 @@ }, { "techniqueID": "T1140", + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, + { + "techniqueID": "T1059", + "score": 16, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" + }, + { + "techniqueID": "T1018", + "score": 20, + "showSubtechniques": false + }, + { + "techniqueID": "T1204.001", + "score": 20, + "showSubtechniques": false + }, + { + "techniqueID": "T1056.001", "score": 20, "showSubtechniques": false }, + { + "techniqueID": "T1140", + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, { "techniqueID": "T1059", "score": 16, @@ -61737,8 +62175,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -61763,8 +62202,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -61789,8 +62229,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -61815,8 +62256,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -61841,8 +62283,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -61867,8 +62310,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -61893,8 +62337,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -61919,8 +62364,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -61945,8 +62391,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -61971,8 +62418,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -61997,8 +62445,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -62023,8 +62472,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -62049,8 +62499,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -62075,8 +62526,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -62101,8 +62553,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -62127,8 +62580,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -62153,8 +62607,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -62179,8 +62634,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -62205,8 +62661,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -62231,8 +62688,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -62257,8 +62715,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -62283,8 +62742,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -62309,8 +62769,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -62335,8 +62796,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -62361,8 +62823,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -62387,8 +62850,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -62413,8 +62877,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -62439,8 +62904,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -62465,8 +62931,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -62491,8 +62958,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -62517,8 +62985,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -62543,8 +63012,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -62569,8 +63039,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -62595,8 +63066,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -62621,8 +63093,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -62647,8 +63120,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -62673,8 +63147,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -62699,8 +63174,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -62725,8 +63201,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -62751,8 +63228,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -62777,8 +63255,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -62803,8 +63282,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -62829,8 +63309,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -62855,8 +63336,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -62881,8 +63363,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -62907,8 +63390,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -62933,8 +63417,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -62959,8 +63444,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -62985,8 +63471,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -63011,8 +63498,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -63037,8 +63525,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -63063,8 +63552,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -63089,8 +63579,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -63115,8 +63606,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -63141,8 +63633,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -63167,8 +63660,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -63193,8 +63687,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -63219,8 +63714,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -63245,9 +63741,37 @@ }, { "techniqueID": "T1140", + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, + { + "techniqueID": "T1059", + "score": 16, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" + }, + { + "techniqueID": "T1018", + "score": 20, + "showSubtechniques": false + }, + { + "techniqueID": "T1204.001", + "score": 20, + "showSubtechniques": false + }, + { + "techniqueID": "T1056.001", "score": 20, "showSubtechniques": false }, + { + "techniqueID": "T1140", + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, { "techniqueID": "T1059", "score": 16, @@ -63271,8 +63795,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -63297,8 +63822,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -63323,8 +63849,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -63349,8 +63876,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -63375,8 +63903,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -63401,8 +63930,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -63427,8 +63957,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -63453,8 +63984,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -63479,8 +64011,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -63505,8 +64038,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -63531,8 +64065,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -63557,8 +64092,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -63583,8 +64119,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -63609,8 +64146,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -63635,8 +64173,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -63661,8 +64200,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -63687,8 +64227,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -63713,8 +64254,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -63739,8 +64281,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -63765,8 +64308,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -63791,8 +64335,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -63817,8 +64362,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -63843,8 +64389,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -63869,8 +64416,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -63895,8 +64443,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -63921,8 +64470,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -63947,8 +64497,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -63973,8 +64524,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -63999,8 +64551,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -64025,8 +64578,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -64051,8 +64605,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -64077,8 +64632,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -64103,8 +64659,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -64129,8 +64686,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -64155,8 +64713,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -64181,8 +64740,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -64207,8 +64767,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -64233,8 +64794,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -64259,8 +64821,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -64285,8 +64848,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -64311,8 +64875,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -64337,8 +64902,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -64363,8 +64929,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -64389,8 +64956,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -64415,8 +64983,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -64441,8 +65010,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -64467,8 +65037,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -64493,8 +65064,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -64519,8 +65091,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -64545,8 +65118,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -64571,8 +65145,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -64597,8 +65172,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -64623,8 +65199,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -64649,8 +65226,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -64675,8 +65253,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -64701,8 +65280,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -64727,8 +65307,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -64753,8 +65334,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -64779,9 +65361,37 @@ }, { "techniqueID": "T1140", + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, + { + "techniqueID": "T1059", + "score": 16, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" + }, + { + "techniqueID": "T1018", + "score": 20, + "showSubtechniques": false + }, + { + "techniqueID": "T1204.001", + "score": 20, + "showSubtechniques": false + }, + { + "techniqueID": "T1056.001", "score": 20, "showSubtechniques": false }, + { + "techniqueID": "T1140", + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, { "techniqueID": "T1059", "score": 16, @@ -64805,8 +65415,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -64831,8 +65442,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -64857,8 +65469,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -64883,8 +65496,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -64909,8 +65523,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -64935,8 +65550,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -64961,8 +65577,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -64987,8 +65604,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -65013,8 +65631,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -65039,8 +65658,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -65065,8 +65685,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -65091,8 +65712,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -65117,8 +65739,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -65143,8 +65766,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -65169,8 +65793,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -65195,8 +65820,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -65221,8 +65847,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -65247,8 +65874,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -65273,8 +65901,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -65299,8 +65928,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -65325,8 +65955,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -65351,8 +65982,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -65377,8 +66009,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -65403,8 +66036,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -65429,8 +66063,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -65455,8 +66090,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -65481,8 +66117,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -65507,8 +66144,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -65533,8 +66171,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -65559,8 +66198,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -65585,8 +66225,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -65611,8 +66252,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -65637,8 +66279,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -65663,8 +66306,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -65689,8 +66333,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -65715,8 +66360,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -65741,8 +66387,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -65767,8 +66414,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -65793,8 +66441,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -65819,8 +66468,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -65845,8 +66495,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -65871,8 +66522,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -65897,8 +66549,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -65923,8 +66576,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -65949,8 +66603,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -65975,8 +66630,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -66001,8 +66657,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -66027,8 +66684,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -66053,8 +66711,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -66079,8 +66738,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -66105,8 +66765,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -66131,8 +66792,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -66157,8 +66819,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -66183,8 +66846,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -66209,8 +66873,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -66235,8 +66900,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -66261,8 +66927,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -66287,8 +66954,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -66313,9 +66981,37 @@ }, { "techniqueID": "T1140", + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, + { + "techniqueID": "T1059", + "score": 16, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" + }, + { + "techniqueID": "T1018", + "score": 20, + "showSubtechniques": false + }, + { + "techniqueID": "T1204.001", + "score": 20, + "showSubtechniques": false + }, + { + "techniqueID": "T1056.001", "score": 20, "showSubtechniques": false }, + { + "techniqueID": "T1140", + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, { "techniqueID": "T1059", "score": 16, @@ -66339,8 +67035,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -66365,8 +67062,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -66391,8 +67089,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -66417,8 +67116,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -66443,8 +67143,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -66469,8 +67170,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -66495,8 +67197,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -66521,8 +67224,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -66547,8 +67251,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -66573,8 +67278,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -66599,8 +67305,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -66625,8 +67332,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -66651,8 +67359,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -66677,8 +67386,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -66703,8 +67413,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -66729,8 +67440,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -66755,8 +67467,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -66781,8 +67494,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -66807,8 +67521,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -66833,8 +67548,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -66859,8 +67575,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -66885,8 +67602,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -66911,8 +67629,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -66937,8 +67656,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -66963,8 +67683,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -66989,8 +67710,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -67015,8 +67737,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -67041,8 +67764,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -67067,8 +67791,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -67093,8 +67818,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -67119,8 +67845,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -67145,8 +67872,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -67171,8 +67899,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -67197,8 +67926,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -67223,8 +67953,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -67249,8 +67980,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -67275,8 +68007,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -67301,8 +68034,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -67327,8 +68061,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -67353,8 +68088,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -67379,8 +68115,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -67405,8 +68142,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -67431,8 +68169,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -67457,8 +68196,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -67483,8 +68223,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -67509,8 +68250,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -67535,8 +68277,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -67561,8 +68304,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -67587,8 +68331,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -67613,8 +68358,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -67639,8 +68385,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -67665,8 +68412,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -67691,8 +68439,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -67717,8 +68466,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -67743,8 +68493,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -67769,8 +68520,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -67795,8 +68547,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -67821,8 +68574,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -67847,9 +68601,37 @@ }, { "techniqueID": "T1140", + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, + { + "techniqueID": "T1059", + "score": 16, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" + }, + { + "techniqueID": "T1018", + "score": 20, + "showSubtechniques": false + }, + { + "techniqueID": "T1204.001", + "score": 20, + "showSubtechniques": false + }, + { + "techniqueID": "T1056.001", "score": 20, "showSubtechniques": false }, + { + "techniqueID": "T1140", + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, { "techniqueID": "T1059", "score": 16, @@ -67873,8 +68655,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -67899,8 +68682,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -67925,8 +68709,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -67951,8 +68736,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -67977,8 +68763,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68003,8 +68790,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68029,8 +68817,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68055,8 +68844,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68081,8 +68871,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68107,8 +68898,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68133,8 +68925,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68159,8 +68952,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68185,8 +68979,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68211,8 +69006,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68237,8 +69033,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68263,8 +69060,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68289,8 +69087,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68315,8 +69114,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68341,8 +69141,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68367,8 +69168,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68393,8 +69195,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68419,8 +69222,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68445,8 +69249,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68471,8 +69276,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68497,8 +69303,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68523,8 +69330,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68549,8 +69357,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68575,8 +69384,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68601,8 +69411,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68627,8 +69438,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68653,8 +69465,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68679,8 +69492,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68705,8 +69519,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68731,8 +69546,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68757,8 +69573,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68783,8 +69600,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68809,8 +69627,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68835,8 +69654,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68861,8 +69681,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68887,8 +69708,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68913,8 +69735,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68939,8 +69762,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68965,8 +69789,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -68991,8 +69816,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -69017,8 +69843,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -69043,9 +69870,37 @@ }, { "techniqueID": "T1140", + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, + { + "techniqueID": "T1059", + "score": 16, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" + }, + { + "techniqueID": "T1018", "score": 20, "showSubtechniques": false }, + { + "techniqueID": "T1204.001", + "score": 20, + "showSubtechniques": false + }, + { + "techniqueID": "T1056.001", + "score": 20, + "showSubtechniques": false + }, + { + "techniqueID": "T1140", + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, { "techniqueID": "T1059", "score": 16, @@ -69069,9 +69924,37 @@ }, { "techniqueID": "T1140", + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, + { + "techniqueID": "T1059", + "score": 16, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" + }, + { + "techniqueID": "T1018", + "score": 20, + "showSubtechniques": false + }, + { + "techniqueID": "T1204.001", + "score": 20, + "showSubtechniques": false + }, + { + "techniqueID": "T1056.001", "score": 20, "showSubtechniques": false }, + { + "techniqueID": "T1140", + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, { "techniqueID": "T1059", "score": 16, @@ -69095,9 +69978,37 @@ }, { "techniqueID": "T1140", + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, + { + "techniqueID": "T1059", + "score": 16, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" + }, + { + "techniqueID": "T1018", + "score": 20, + "showSubtechniques": false + }, + { + "techniqueID": "T1204.001", + "score": 20, + "showSubtechniques": false + }, + { + "techniqueID": "T1056.001", "score": 20, "showSubtechniques": false }, + { + "techniqueID": "T1140", + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" + }, { "techniqueID": "T1059", "score": 16, @@ -69121,8 +70032,9 @@ }, { "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "score": 19, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/certutil_with_decode_argument.yml" }, { "techniqueID": "T1059", @@ -69141,213 +70053,260 @@ "showSubtechniques": false }, { - "techniqueID": "T1056.001", - "score": 20, - "showSubtechniques": false + "techniqueID": "T1047", + "score": 14, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { - "techniqueID": "T1140", - "score": 20, + "techniqueID": "T1033", + "score": 19, "showSubtechniques": false }, { - "techniqueID": "T1059", - "score": 16, + "techniqueID": "T1189", + "score": 18, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" - }, - { - "techniqueID": "T1018", - "score": 20, - "showSubtechniques": false + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { - "techniqueID": "T1204.001", - "score": 20, - "showSubtechniques": false + "techniqueID": "T1047", + "score": 14, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { - "techniqueID": "T1056.001", - "score": 20, + "techniqueID": "T1033", + "score": 19, "showSubtechniques": false }, { - "techniqueID": "T1140", - "score": 20, - "showSubtechniques": false + "techniqueID": "T1189", + "score": 18, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { - "techniqueID": "T1059", - "score": 16, + "techniqueID": "T1047", + "score": 14, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { - "techniqueID": "T1018", - "score": 20, + "techniqueID": "T1033", + "score": 19, "showSubtechniques": false }, { - "techniqueID": "T1204.001", - "score": 20, - "showSubtechniques": false + "techniqueID": "T1189", + "score": 18, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { - "techniqueID": "T1056.001", - "score": 20, - "showSubtechniques": false + "techniqueID": "T1047", + "score": 14, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { - "techniqueID": "T1140", - "score": 20, + "techniqueID": "T1033", + "score": 19, "showSubtechniques": false }, { - "techniqueID": "T1059", - "score": 16, + "techniqueID": "T1189", + "score": 18, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { - "techniqueID": "T1018", - "score": 20, - "showSubtechniques": false + "techniqueID": "T1047", + "score": 14, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { - "techniqueID": "T1204.001", - "score": 20, + "techniqueID": "T1033", + "score": 19, "showSubtechniques": false }, { - "techniqueID": "T1056.001", - "score": 20, - "showSubtechniques": false + "techniqueID": "T1189", + "score": 18, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { - "techniqueID": "T1140", - "score": 20, + "techniqueID": "T1047", + "score": 14, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" + }, + { + "techniqueID": "T1033", + "score": 19, "showSubtechniques": false }, { - "techniqueID": "T1059", - "score": 16, + "techniqueID": "T1189", + "score": 18, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { - "techniqueID": "T1018", - "score": 20, - "showSubtechniques": false + "techniqueID": "T1047", + "score": 14, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { - "techniqueID": "T1204.001", - "score": 20, + "techniqueID": "T1033", + "score": 19, "showSubtechniques": false }, { - "techniqueID": "T1056.001", - "score": 20, - "showSubtechniques": false + "techniqueID": "T1189", + "score": 18, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { - "techniqueID": "T1140", - "score": 20, + "techniqueID": "T1047", + "score": 14, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" + }, + { + "techniqueID": "T1033", + "score": 19, "showSubtechniques": false }, { - "techniqueID": "T1059", - "score": 16, + "techniqueID": "T1189", + "score": 18, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { - "techniqueID": "T1018", - "score": 20, - "showSubtechniques": false + "techniqueID": "T1047", + "score": 14, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { - "techniqueID": "T1204.001", - "score": 20, + "techniqueID": "T1033", + "score": 19, "showSubtechniques": false }, { - "techniqueID": "T1056.001", - "score": 20, - "showSubtechniques": false + "techniqueID": "T1189", + "score": 18, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { - "techniqueID": "T1140", - "score": 20, + "techniqueID": "T1047", + "score": 14, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" + }, + { + "techniqueID": "T1033", + "score": 19, "showSubtechniques": false }, { - "techniqueID": "T1059", - "score": 16, + "techniqueID": "T1189", + "score": 18, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { - "techniqueID": "T1018", - "score": 20, - "showSubtechniques": false + "techniqueID": "T1047", + "score": 14, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { - "techniqueID": "T1204.001", - "score": 20, + "techniqueID": "T1033", + "score": 19, "showSubtechniques": false }, { - "techniqueID": "T1056.001", - "score": 20, - "showSubtechniques": false + "techniqueID": "T1189", + "score": 18, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { - "techniqueID": "T1140", - "score": 20, + "techniqueID": "T1047", + "score": 14, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" + }, + { + "techniqueID": "T1033", + "score": 19, "showSubtechniques": false }, { - "techniqueID": "T1059", - "score": 16, + "techniqueID": "T1189", + "score": 18, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { - "techniqueID": "T1018", - "score": 20, - "showSubtechniques": false + "techniqueID": "T1047", + "score": 14, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { - "techniqueID": "T1204.001", - "score": 20, + "techniqueID": "T1033", + "score": 19, "showSubtechniques": false }, { - "techniqueID": "T1056.001", - "score": 20, - "showSubtechniques": false + "techniqueID": "T1189", + "score": 18, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { - "techniqueID": "T1140", - "score": 20, + "techniqueID": "T1047", + "score": 14, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" + }, + { + "techniqueID": "T1033", + "score": 19, "showSubtechniques": false }, { - "techniqueID": "T1059", - "score": 16, + "techniqueID": "T1189", + "score": 18, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___prohibited_apps_spawning_cmdprompt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___rare_parent_process_relationship_lolbas.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___unusual_lolbas_in_short_period_of_time.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { - "techniqueID": "T1018", - "score": 20, - "showSubtechniques": false + "techniqueID": "T1047", + "score": 14, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" }, { - "techniqueID": "T1204.001", - "score": 20, + "techniqueID": "T1033", + "score": 19, "showSubtechniques": false }, + { + "techniqueID": "T1189", + "score": 18, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" + }, { "techniqueID": "T1047", "score": 14, @@ -75078,260 +76037,15 @@ "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" }, { - "techniqueID": "T1047", - "score": 14, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1033", - "score": 19, - "showSubtechniques": false - }, - { - "techniqueID": "T1189", - "score": 18, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" - }, - { - "techniqueID": "T1047", - "score": 14, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1033", - "score": 19, - "showSubtechniques": false - }, - { - "techniqueID": "T1189", - "score": 18, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" - }, - { - "techniqueID": "T1047", - "score": 14, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1033", - "score": 19, - "showSubtechniques": false - }, - { - "techniqueID": "T1189", - "score": 18, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" - }, - { - "techniqueID": "T1047", - "score": 14, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1033", - "score": 19, - "showSubtechniques": false - }, - { - "techniqueID": "T1189", - "score": 18, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" - }, - { - "techniqueID": "T1047", - "score": 14, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1033", - "score": 19, - "showSubtechniques": false - }, - { - "techniqueID": "T1189", - "score": 18, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" - }, - { - "techniqueID": "T1047", - "score": 14, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1033", - "score": 19, - "showSubtechniques": false - }, - { - "techniqueID": "T1189", - "score": 18, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" - }, - { - "techniqueID": "T1047", - "score": 14, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1033", - "score": 19, - "showSubtechniques": false - }, - { - "techniqueID": "T1189", - "score": 18, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" - }, - { - "techniqueID": "T1047", - "score": 14, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1033", - "score": 19, - "showSubtechniques": false - }, - { - "techniqueID": "T1189", - "score": 18, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" - }, - { - "techniqueID": "T1047", - "score": 14, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1033", - "score": 19, - "showSubtechniques": false - }, - { - "techniqueID": "T1189", - "score": 18, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" - }, - { - "techniqueID": "T1047", - "score": 14, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1033", - "score": 19, - "showSubtechniques": false - }, - { - "techniqueID": "T1189", - "score": 18, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" - }, - { - "techniqueID": "T1047", - "score": 14, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1033", - "score": 19, - "showSubtechniques": false - }, - { - "techniqueID": "T1189", - "score": 18, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" - }, - { - "techniqueID": "T1047", - "score": 14, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1033", - "score": 19, - "showSubtechniques": false - }, - { - "techniqueID": "T1189", + "techniqueID": "T1560.001", "score": 18, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" - }, - { - "techniqueID": "T1047", - "score": 14, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1033", - "score": 19, "showSubtechniques": false }, { - "techniqueID": "T1189", + "techniqueID": "T1560.001", "score": 18, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" - }, - { - "techniqueID": "T1047", - "score": 14, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1033", - "score": 19, "showSubtechniques": false }, - { - "techniqueID": "T1189", - "score": 18, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" - }, - { - "techniqueID": "T1047", - "score": 14, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/remote_wmi_command_attempt.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/remote_process_instantiation_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/script_execution_via_wmi.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1033", - "score": 19, - "showSubtechniques": false - }, - { - "techniqueID": "T1189", - "score": 18, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_hosts_connecting_to_dynamic_domain_providers.yml" - }, { "techniqueID": "T1560.001", "score": 18, @@ -77083,26 +77797,16 @@ "showSubtechniques": false }, { - "techniqueID": "T1560.001", - "score": 18, - "showSubtechniques": false + "techniqueID": "T1003", + "score": 6, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" }, { - "techniqueID": "T1560.001", - "score": 18, - "showSubtechniques": false - }, - { - "techniqueID": "T1003", - "score": 6, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_conversion_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_s_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_fgdump_cachedump_v_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_getaddbaccount_from_dump.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_lazagne_command_options.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_kernel_peek.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_ms_debuggers_z_option.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___credential_extraction_powersploit_modules.yml" - }, - { - "techniqueID": "T1543.003", - "score": 16, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" + "techniqueID": "T1543.003", + "score": 16, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/sc_exe_manipulating_windows_services.yml" }, { "techniqueID": "T1003", @@ -139403,9 +140107,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -139419,9 +140123,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -139435,9 +140139,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -139451,9 +140155,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -139467,9 +140171,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -139483,9 +140187,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -139499,9 +140203,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -139515,9 +140219,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -139531,9 +140235,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -139547,9 +140251,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -139563,9 +140267,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -139579,9 +140283,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -139595,9 +140299,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -139611,9 +140315,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -139627,9 +140331,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -139643,9 +140347,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -139659,9 +140363,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -139675,9 +140379,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -139691,9 +140395,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -139707,9 +140411,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -139723,9 +140427,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -139739,9 +140443,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -139755,9 +140459,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -139771,9 +140475,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -139787,9 +140491,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -139803,9 +140507,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -139819,9 +140523,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -139835,9 +140539,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -139851,9 +140555,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -139867,9 +140571,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -139883,9 +140587,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -139899,9 +140603,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -139915,9 +140619,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -139931,9 +140635,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -139947,9 +140651,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -139963,9 +140667,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -139979,9 +140683,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -139995,9 +140699,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140011,9 +140715,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140027,9 +140731,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140043,9 +140747,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140059,9 +140763,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140075,9 +140779,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140091,9 +140795,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140107,9 +140811,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140123,9 +140827,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140139,9 +140843,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140155,9 +140859,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140171,9 +140875,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140187,9 +140891,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140203,9 +140907,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140219,9 +140923,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140235,9 +140939,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140251,9 +140955,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140267,9 +140971,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140283,9 +140987,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140299,9 +141003,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140315,9 +141019,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140331,9 +141035,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140347,9 +141051,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140363,9 +141067,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140379,9 +141083,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140395,9 +141099,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140411,9 +141115,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140427,9 +141131,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140443,9 +141147,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140459,9 +141163,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140475,9 +141179,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140491,9 +141195,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140507,9 +141211,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140523,9 +141227,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140539,9 +141243,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140555,9 +141259,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140571,9 +141275,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140587,9 +141291,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140603,9 +141307,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140619,9 +141323,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140635,9 +141339,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140651,9 +141355,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140667,9 +141371,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140683,9 +141387,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140699,9 +141403,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140715,9 +141419,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140731,9 +141435,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140747,9 +141451,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140763,9 +141467,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140779,9 +141483,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140795,9 +141499,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140811,9 +141515,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140827,9 +141531,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140843,9 +141547,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140859,9 +141563,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140875,9 +141579,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140891,9 +141595,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140907,9 +141611,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140923,9 +141627,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140939,9 +141643,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140955,9 +141659,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140971,9 +141675,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -140987,9 +141691,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141003,9 +141707,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141019,9 +141723,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141035,9 +141739,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141051,9 +141755,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141067,9 +141771,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141083,9 +141787,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141099,9 +141803,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141115,9 +141819,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141131,9 +141835,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141147,9 +141851,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141163,9 +141867,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141179,9 +141883,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141195,9 +141899,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141211,9 +141915,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141227,9 +141931,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141243,9 +141947,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141259,9 +141963,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141275,9 +141979,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141291,9 +141995,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141307,9 +142011,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141323,9 +142027,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141339,9 +142043,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141355,9 +142059,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141371,9 +142075,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141387,9 +142091,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141403,9 +142107,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141419,9 +142123,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141435,9 +142139,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141451,9 +142155,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141467,9 +142171,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141483,9 +142187,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141499,9 +142203,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141515,9 +142219,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141531,9 +142235,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141547,9 +142251,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141563,9 +142267,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141579,9 +142283,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141595,9 +142299,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141611,9 +142315,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141627,9 +142331,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141643,9 +142347,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141659,9 +142363,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141675,9 +142379,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141691,9 +142395,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141707,9 +142411,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141723,9 +142427,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141739,9 +142443,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141755,9 +142459,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141771,9 +142475,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141787,9 +142491,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141803,9 +142507,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141819,9 +142523,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141835,9 +142539,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141851,9 +142555,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141867,9 +142571,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141883,9 +142587,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141899,9 +142603,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141915,9 +142619,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141931,9 +142635,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141947,9 +142651,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141963,9 +142667,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141979,9 +142683,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -141995,9 +142699,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142011,9 +142715,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142027,9 +142731,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142043,9 +142747,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142059,9 +142763,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142075,9 +142779,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142091,9 +142795,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142107,9 +142811,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142123,9 +142827,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142139,9 +142843,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142155,9 +142859,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142171,9 +142875,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142187,9 +142891,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142203,9 +142907,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142219,9 +142923,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142235,9 +142939,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142251,9 +142955,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142267,9 +142971,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142283,9 +142987,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142299,9 +143003,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142315,9 +143019,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142331,9 +143035,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142347,9 +143051,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142363,9 +143067,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142379,9 +143083,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142395,9 +143099,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142411,9 +143115,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142427,9 +143131,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142443,9 +143147,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142459,9 +143163,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142475,9 +143179,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142491,9 +143195,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142507,9 +143211,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142523,9 +143227,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142539,9 +143243,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142555,9 +143259,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142571,9 +143275,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142587,9 +143291,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142603,9 +143307,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142619,9 +143323,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142635,9 +143339,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142651,9 +143355,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142667,9 +143371,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142683,9 +143387,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142699,9 +143403,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142715,9 +143419,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142731,9 +143435,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142747,9 +143451,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142763,9 +143467,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142779,9 +143483,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142795,9 +143499,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142811,9 +143515,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142827,9 +143531,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142843,9 +143547,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142859,9 +143563,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142875,9 +143579,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142891,9 +143595,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142907,9 +143611,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142923,9 +143627,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142939,9 +143643,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142955,9 +143659,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142971,9 +143675,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -142987,9 +143691,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143003,9 +143707,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143019,9 +143723,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143035,9 +143739,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143051,9 +143755,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143067,9 +143771,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143083,9 +143787,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143099,9 +143803,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143115,9 +143819,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143131,9 +143835,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143147,9 +143851,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143163,9 +143867,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143179,9 +143883,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143195,9 +143899,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143211,9 +143915,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143227,9 +143931,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143243,9 +143947,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143259,9 +143963,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143275,9 +143979,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143291,9 +143995,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143307,9 +144011,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143323,9 +144027,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143339,9 +144043,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143355,9 +144059,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143371,9 +144075,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143387,9 +144091,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143403,9 +144107,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143419,9 +144123,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143435,9 +144139,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143451,9 +144155,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143467,9 +144171,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143483,9 +144187,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143499,9 +144203,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143515,9 +144219,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143531,9 +144235,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143547,9 +144251,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143563,9 +144267,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143579,9 +144283,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143595,9 +144299,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143611,9 +144315,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143627,9 +144331,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143643,9 +144347,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143659,9 +144363,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143675,9 +144379,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143691,9 +144395,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143707,9 +144411,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143723,9 +144427,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143739,9 +144443,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143755,9 +144459,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143771,9 +144475,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143787,9 +144491,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143803,9 +144507,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143819,9 +144523,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143835,9 +144539,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143851,9 +144555,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143867,9 +144571,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143883,9 +144587,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143899,9 +144603,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143915,9 +144619,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143931,9 +144635,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143947,9 +144651,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143963,9 +144667,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143979,9 +144683,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -143995,9 +144699,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144011,9 +144715,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144027,9 +144731,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144043,9 +144747,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144059,9 +144763,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144075,9 +144779,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144091,9 +144795,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144107,9 +144811,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144123,9 +144827,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144139,9 +144843,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144155,9 +144859,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144171,9 +144875,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144187,9 +144891,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144203,9 +144907,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144219,9 +144923,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144235,9 +144939,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144251,9 +144955,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144267,9 +144971,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144283,9 +144987,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144299,9 +145003,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144315,9 +145019,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144331,9 +145035,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144347,9 +145051,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144363,9 +145067,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144379,9 +145083,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144395,9 +145099,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144411,9 +145115,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144427,9 +145131,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144443,9 +145147,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144459,9 +145163,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144475,9 +145179,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144491,9 +145195,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144507,9 +145211,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144523,9 +145227,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144539,9 +145243,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144555,9 +145259,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144571,9 +145275,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144587,9 +145291,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144603,9 +145307,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144619,9 +145323,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144635,9 +145339,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144651,9 +145355,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144667,9 +145371,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144683,9 +145387,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144699,9 +145403,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144715,9 +145419,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144731,9 +145435,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144747,9 +145451,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144763,9 +145467,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144779,9 +145483,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144795,9 +145499,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144811,9 +145515,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144827,9 +145531,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144843,9 +145547,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144859,9 +145563,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144875,9 +145579,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144891,9 +145595,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144907,9 +145611,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144923,9 +145627,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144939,9 +145643,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144955,9 +145659,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144971,9 +145675,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -144987,9 +145691,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -145003,9 +145707,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -145019,9 +145723,9 @@ }, { "techniqueID": "T1505.003", - "score": 9, + "score": 8, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_exchange_web_shell.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/w3wp_spawning_shell.yml" }, { "techniqueID": "T1100", @@ -166764,1047 +167468,445 @@ "showSubtechniques": false }, { - "techniqueID": "T1143", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1559.002", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1135", - "score": 6, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1090.002", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1036.004", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1110", - "score": 8, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" - }, - { - "techniqueID": "T1068", - "score": 0, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1102.002", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1564.003", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1173", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1569.002", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1035", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1143", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1559.002", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1135", - "score": 6, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1090.002", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1036.004", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1110", - "score": 8, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" - }, - { - "techniqueID": "T1068", - "score": 0, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1102.002", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1564.003", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1173", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1569.002", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1035", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1143", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1559.002", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1135", - "score": 6, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1090.002", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1036.004", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1110", - "score": 8, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" - }, - { - "techniqueID": "T1068", - "score": 0, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1102.002", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1564.003", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1173", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1569.002", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1035", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1143", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1559.002", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1135", - "score": 6, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1090.002", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1036.004", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1110", - "score": 8, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" - }, - { - "techniqueID": "T1068", - "score": 0, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1102.002", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1564.003", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1173", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1569.002", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1035", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1143", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1559.002", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1135", - "score": 6, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1090.002", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1036.004", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1110", - "score": 8, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" - }, - { - "techniqueID": "T1068", - "score": 0, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1102.002", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1564.003", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1173", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1569.002", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1035", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1143", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1559.002", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1135", - "score": 6, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1090.002", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1036.004", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1110", - "score": 8, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" - }, - { - "techniqueID": "T1068", - "score": 0, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1102.002", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1564.003", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1173", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1569.002", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1035", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1143", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1559.002", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1135", - "score": 6, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1090.002", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1036.004", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1110", - "score": 8, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" - }, - { - "techniqueID": "T1068", - "score": 0, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1102.002", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1564.003", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1173", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1569.002", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1035", - "score": 9, - "showSubtechniques": false - }, - { - "techniqueID": "T1132.001", - "score": 8, - "showSubtechniques": false - }, - { - "techniqueID": "T1059.007", - "score": 8, + "techniqueID": "T1143", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1590.002", - "score": 8, + "techniqueID": "T1559.002", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1548.002", - "score": 5, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" - }, - { - "techniqueID": "T1071.004", + "techniqueID": "T1135", "score": 6, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { - "techniqueID": "T1003.004", - "score": 8, + "techniqueID": "T1090.002", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1137", - "score": 8, + "techniqueID": "T1036.004", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1106", - "score": 6, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1219", + "techniqueID": "T1110", "score": 8, - "showSubtechniques": false + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, { - "techniqueID": "T1117", - "score": 7, + "techniqueID": "T1068", + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, { - "techniqueID": "T1090", - "score": 8, + "techniqueID": "T1102.002", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1102", - "score": 8, + "techniqueID": "T1564.003", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1218.010", - "score": 6, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" - }, - { - "techniqueID": "T1065", - "score": 8, + "techniqueID": "T1173", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1088", - "score": 8, + "techniqueID": "T1569.002", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1048.003", - "score": 4, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" - }, - { - "techniqueID": "T1132.001", - "score": 8, + "techniqueID": "T1035", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1059.007", - "score": 8, + "techniqueID": "T1143", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1590.002", - "score": 8, + "techniqueID": "T1559.002", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1548.002", - "score": 5, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" - }, - { - "techniqueID": "T1071.004", + "techniqueID": "T1135", "score": 6, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { - "techniqueID": "T1003.004", - "score": 8, + "techniqueID": "T1090.002", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1137", - "score": 8, + "techniqueID": "T1036.004", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1106", - "score": 6, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1219", + "techniqueID": "T1110", "score": 8, - "showSubtechniques": false + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, { - "techniqueID": "T1117", - "score": 7, + "techniqueID": "T1068", + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, { - "techniqueID": "T1090", - "score": 8, + "techniqueID": "T1102.002", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1102", - "score": 8, + "techniqueID": "T1564.003", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1218.010", - "score": 6, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" - }, - { - "techniqueID": "T1065", - "score": 8, + "techniqueID": "T1173", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1088", - "score": 8, + "techniqueID": "T1569.002", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1048.003", - "score": 4, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" - }, - { - "techniqueID": "T1132.001", - "score": 8, + "techniqueID": "T1035", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1059.007", - "score": 8, + "techniqueID": "T1143", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1590.002", - "score": 8, + "techniqueID": "T1559.002", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1548.002", - "score": 5, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" - }, - { - "techniqueID": "T1071.004", + "techniqueID": "T1135", "score": 6, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { - "techniqueID": "T1003.004", - "score": 8, + "techniqueID": "T1090.002", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1137", - "score": 8, + "techniqueID": "T1036.004", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1106", - "score": 6, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1219", + "techniqueID": "T1110", "score": 8, - "showSubtechniques": false + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, { - "techniqueID": "T1117", - "score": 7, + "techniqueID": "T1068", + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, { - "techniqueID": "T1090", - "score": 8, + "techniqueID": "T1102.002", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1102", - "score": 8, + "techniqueID": "T1564.003", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1218.010", - "score": 6, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" - }, - { - "techniqueID": "T1065", - "score": 8, + "techniqueID": "T1173", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1088", - "score": 8, + "techniqueID": "T1569.002", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1048.003", - "score": 4, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" - }, - { - "techniqueID": "T1132.001", - "score": 8, + "techniqueID": "T1035", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1059.007", - "score": 8, + "techniqueID": "T1143", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1590.002", - "score": 8, + "techniqueID": "T1559.002", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1548.002", - "score": 5, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" - }, - { - "techniqueID": "T1071.004", + "techniqueID": "T1135", "score": 6, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { - "techniqueID": "T1003.004", - "score": 8, + "techniqueID": "T1090.002", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1137", - "score": 8, + "techniqueID": "T1036.004", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1106", - "score": 6, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1219", + "techniqueID": "T1110", "score": 8, - "showSubtechniques": false + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, { - "techniqueID": "T1117", - "score": 7, + "techniqueID": "T1068", + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, { - "techniqueID": "T1090", - "score": 8, + "techniqueID": "T1102.002", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1102", - "score": 8, + "techniqueID": "T1564.003", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1218.010", - "score": 6, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" - }, - { - "techniqueID": "T1065", - "score": 8, + "techniqueID": "T1173", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1088", - "score": 8, + "techniqueID": "T1569.002", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1048.003", - "score": 4, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" - }, - { - "techniqueID": "T1132.001", - "score": 8, + "techniqueID": "T1035", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1059.007", - "score": 8, + "techniqueID": "T1143", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1590.002", - "score": 8, + "techniqueID": "T1559.002", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1548.002", - "score": 5, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" - }, - { - "techniqueID": "T1071.004", + "techniqueID": "T1135", "score": 6, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { - "techniqueID": "T1003.004", - "score": 8, + "techniqueID": "T1090.002", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1137", - "score": 8, + "techniqueID": "T1036.004", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1106", - "score": 6, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1219", + "techniqueID": "T1110", "score": 8, - "showSubtechniques": false + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, { - "techniqueID": "T1117", - "score": 7, + "techniqueID": "T1068", + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, { - "techniqueID": "T1090", - "score": 8, + "techniqueID": "T1102.002", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1102", - "score": 8, + "techniqueID": "T1564.003", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1218.010", - "score": 6, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" - }, - { - "techniqueID": "T1065", - "score": 8, + "techniqueID": "T1173", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1088", - "score": 8, + "techniqueID": "T1569.002", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1048.003", - "score": 4, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" - }, - { - "techniqueID": "T1132.001", - "score": 8, + "techniqueID": "T1035", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1059.007", - "score": 8, + "techniqueID": "T1143", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1590.002", - "score": 8, + "techniqueID": "T1559.002", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1548.002", - "score": 5, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" - }, - { - "techniqueID": "T1071.004", + "techniqueID": "T1135", "score": 6, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { - "techniqueID": "T1003.004", - "score": 8, + "techniqueID": "T1090.002", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1137", - "score": 8, + "techniqueID": "T1036.004", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1106", - "score": 6, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1219", + "techniqueID": "T1110", "score": 8, - "showSubtechniques": false + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, { - "techniqueID": "T1117", - "score": 7, + "techniqueID": "T1068", + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, { - "techniqueID": "T1090", - "score": 8, + "techniqueID": "T1102.002", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1102", - "score": 8, + "techniqueID": "T1564.003", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1218.010", - "score": 6, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" - }, - { - "techniqueID": "T1065", - "score": 8, + "techniqueID": "T1173", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1088", - "score": 8, + "techniqueID": "T1569.002", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1048.003", - "score": 4, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" - }, - { - "techniqueID": "T1132.001", - "score": 8, + "techniqueID": "T1035", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1059.007", - "score": 8, + "techniqueID": "T1143", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1590.002", - "score": 8, + "techniqueID": "T1559.002", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1548.002", - "score": 5, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" - }, - { - "techniqueID": "T1071.004", + "techniqueID": "T1135", "score": 6, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_shares_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_connectivity_via_powersploit_modules.yml" }, { - "techniqueID": "T1003.004", - "score": 8, + "techniqueID": "T1090.002", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1137", - "score": 8, + "techniqueID": "T1036.004", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1106", - "score": 6, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1219", + "techniqueID": "T1110", "score": 8, - "showSubtechniques": false + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_excessive_authentication_failures_alert.yml" }, { - "techniqueID": "T1117", - "score": 7, + "techniqueID": "T1068", + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_access_and_persistence_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" }, { - "techniqueID": "T1090", - "score": 8, + "techniqueID": "T1102.002", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1102", - "score": 8, + "techniqueID": "T1564.003", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1218.010", - "score": 6, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" - }, - { - "techniqueID": "T1065", - "score": 8, + "techniqueID": "T1173", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1088", - "score": 8, + "techniqueID": "T1569.002", + "score": 9, "showSubtechniques": false }, { - "techniqueID": "T1048.003", - "score": 4, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" + "techniqueID": "T1035", + "score": 9, + "showSubtechniques": false }, { "techniqueID": "T1132.001", @@ -197477,868 +197579,606 @@ "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, { - "techniqueID": "T1066", - "score": 7, - "showSubtechniques": false - }, - { - "techniqueID": "T1003.002", - "score": 6, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" - }, - { - "techniqueID": "T1587.001", - "score": 7, - "showSubtechniques": false - }, - { - "techniqueID": "T1573.001", - "score": 7, - "showSubtechniques": false - }, - { - "techniqueID": "T1069.002", - "score": 7, - "showSubtechniques": false - }, - { - "techniqueID": "T1021.004", - "score": 7, - "showSubtechniques": false - }, - { - "techniqueID": "T1007", - "score": 5, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" - }, - { - "techniqueID": "T1071", - "score": 7, + "techniqueID": "T1132.001", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1547.009", - "score": 7, + "techniqueID": "T1059.007", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1070.001", - "score": 5, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" - }, - { - "techniqueID": "T1588.001", - "score": 7, + "techniqueID": "T1590.002", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1070", + "techniqueID": "T1548.002", "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" - }, - { - "techniqueID": "T1552.001", - "score": 7, - "showSubtechniques": false - }, - { - "techniqueID": "T1023", - "score": 7, - "showSubtechniques": false - }, - { - "techniqueID": "T1098", - "score": -5, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1027.005", - "score": 7, - "showSubtechniques": false - }, - { - "techniqueID": "T1114.002", - "score": 6, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, { - "techniqueID": "T1012", + "techniqueID": "T1071.004", "score": 6, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, { - "techniqueID": "T1221", - "score": 7, + "techniqueID": "T1003.004", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1134", - "score": 3, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" - }, - { - "techniqueID": "T1066", - "score": 7, + "techniqueID": "T1137", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1003.002", + "techniqueID": "T1106", "score": 6, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { - "techniqueID": "T1587.001", - "score": 7, + "techniqueID": "T1219", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1573.001", + "techniqueID": "T1117", "score": 7, - "showSubtechniques": false + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, { - "techniqueID": "T1069.002", - "score": 7, + "techniqueID": "T1090", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1021.004", - "score": 7, + "techniqueID": "T1102", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1007", - "score": 5, + "techniqueID": "T1218.010", + "score": 6, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" - }, - { - "techniqueID": "T1071", - "score": 7, - "showSubtechniques": false + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, { - "techniqueID": "T1547.009", - "score": 7, + "techniqueID": "T1065", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1070.001", - "score": 5, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" - }, - { - "techniqueID": "T1588.001", - "score": 7, + "techniqueID": "T1088", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1070", - "score": 5, + "techniqueID": "T1048.003", + "score": 4, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, { - "techniqueID": "T1552.001", - "score": 7, + "techniqueID": "T1132.001", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1023", - "score": 7, + "techniqueID": "T1059.007", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1098", - "score": -5, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1027.005", - "score": 7, + "techniqueID": "T1590.002", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1114.002", - "score": 6, + "techniqueID": "T1548.002", + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, { - "techniqueID": "T1012", + "techniqueID": "T1071.004", "score": 6, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, { - "techniqueID": "T1221", - "score": 7, + "techniqueID": "T1003.004", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1134", - "score": 3, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" - }, - { - "techniqueID": "T1066", - "score": 7, + "techniqueID": "T1137", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1003.002", + "techniqueID": "T1106", "score": 6, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { - "techniqueID": "T1587.001", - "score": 7, + "techniqueID": "T1219", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1573.001", + "techniqueID": "T1117", "score": 7, - "showSubtechniques": false + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, { - "techniqueID": "T1069.002", - "score": 7, + "techniqueID": "T1090", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1021.004", - "score": 7, + "techniqueID": "T1102", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1007", - "score": 5, + "techniqueID": "T1218.010", + "score": 6, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" - }, - { - "techniqueID": "T1071", - "score": 7, - "showSubtechniques": false + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, { - "techniqueID": "T1547.009", - "score": 7, + "techniqueID": "T1065", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1070.001", - "score": 5, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" - }, - { - "techniqueID": "T1588.001", - "score": 7, + "techniqueID": "T1088", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1070", - "score": 5, + "techniqueID": "T1048.003", + "score": 4, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, { - "techniqueID": "T1552.001", - "score": 7, + "techniqueID": "T1132.001", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1023", - "score": 7, + "techniqueID": "T1059.007", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1098", - "score": -5, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1027.005", - "score": 7, + "techniqueID": "T1590.002", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1114.002", - "score": 6, + "techniqueID": "T1548.002", + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, { - "techniqueID": "T1012", + "techniqueID": "T1071.004", "score": 6, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, { - "techniqueID": "T1221", - "score": 7, + "techniqueID": "T1003.004", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1134", - "score": 3, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" - }, - { - "techniqueID": "T1066", - "score": 7, + "techniqueID": "T1137", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1003.002", + "techniqueID": "T1106", "score": 6, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { - "techniqueID": "T1587.001", - "score": 7, + "techniqueID": "T1219", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1573.001", + "techniqueID": "T1117", "score": 7, - "showSubtechniques": false + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, { - "techniqueID": "T1069.002", - "score": 7, + "techniqueID": "T1090", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1021.004", - "score": 7, + "techniqueID": "T1102", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1007", - "score": 5, + "techniqueID": "T1218.010", + "score": 6, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" - }, - { - "techniqueID": "T1071", - "score": 7, - "showSubtechniques": false + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, { - "techniqueID": "T1547.009", - "score": 7, + "techniqueID": "T1065", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1070.001", - "score": 5, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" - }, - { - "techniqueID": "T1588.001", - "score": 7, + "techniqueID": "T1088", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1070", - "score": 5, + "techniqueID": "T1048.003", + "score": 4, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, { - "techniqueID": "T1552.001", - "score": 7, + "techniqueID": "T1132.001", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1023", - "score": 7, + "techniqueID": "T1059.007", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1098", - "score": -5, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1027.005", - "score": 7, + "techniqueID": "T1590.002", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1114.002", - "score": 6, + "techniqueID": "T1548.002", + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, { - "techniqueID": "T1012", + "techniqueID": "T1071.004", "score": 6, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, { - "techniqueID": "T1221", - "score": 7, + "techniqueID": "T1003.004", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1134", - "score": 3, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" - }, - { - "techniqueID": "T1066", - "score": 7, + "techniqueID": "T1137", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1003.002", + "techniqueID": "T1106", "score": 6, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { - "techniqueID": "T1587.001", - "score": 7, + "techniqueID": "T1219", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1573.001", + "techniqueID": "T1117", "score": 7, - "showSubtechniques": false + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, { - "techniqueID": "T1069.002", - "score": 7, + "techniqueID": "T1090", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1021.004", - "score": 7, + "techniqueID": "T1102", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1007", - "score": 5, + "techniqueID": "T1218.010", + "score": 6, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" - }, - { - "techniqueID": "T1071", - "score": 7, - "showSubtechniques": false + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, { - "techniqueID": "T1547.009", - "score": 7, + "techniqueID": "T1065", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1070.001", - "score": 5, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" - }, - { - "techniqueID": "T1588.001", - "score": 7, + "techniqueID": "T1088", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1070", - "score": 5, + "techniqueID": "T1048.003", + "score": 4, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, { - "techniqueID": "T1552.001", - "score": 7, + "techniqueID": "T1132.001", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1023", - "score": 7, + "techniqueID": "T1059.007", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1098", - "score": -5, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1027.005", - "score": 7, + "techniqueID": "T1590.002", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1114.002", - "score": 6, + "techniqueID": "T1548.002", + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, { - "techniqueID": "T1012", + "techniqueID": "T1071.004", "score": 6, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, { - "techniqueID": "T1221", - "score": 7, + "techniqueID": "T1003.004", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1134", - "score": 3, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" - }, - { - "techniqueID": "T1066", - "score": 7, + "techniqueID": "T1137", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1003.002", + "techniqueID": "T1106", "score": 6, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { - "techniqueID": "T1587.001", - "score": 7, + "techniqueID": "T1219", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1573.001", + "techniqueID": "T1117", "score": 7, - "showSubtechniques": false + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, { - "techniqueID": "T1069.002", - "score": 7, + "techniqueID": "T1090", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1021.004", - "score": 7, + "techniqueID": "T1102", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1007", - "score": 5, + "techniqueID": "T1218.010", + "score": 6, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" - }, - { - "techniqueID": "T1071", - "score": 7, - "showSubtechniques": false + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, { - "techniqueID": "T1547.009", - "score": 7, + "techniqueID": "T1065", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1070.001", - "score": 5, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" - }, - { - "techniqueID": "T1588.001", - "score": 7, + "techniqueID": "T1088", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1070", - "score": 5, + "techniqueID": "T1048.003", + "score": 4, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, { - "techniqueID": "T1552.001", - "score": 7, + "techniqueID": "T1132.001", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1023", - "score": 7, + "techniqueID": "T1059.007", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1098", - "score": -5, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1027.005", - "score": 7, + "techniqueID": "T1590.002", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1114.002", - "score": 6, + "techniqueID": "T1548.002", + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, { - "techniqueID": "T1012", + "techniqueID": "T1071.004", "score": 6, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, { - "techniqueID": "T1221", - "score": 7, + "techniqueID": "T1003.004", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1134", - "score": 3, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" - }, - { - "techniqueID": "T1066", - "score": 7, + "techniqueID": "T1137", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1003.002", + "techniqueID": "T1106", "score": 6, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { - "techniqueID": "T1587.001", - "score": 7, + "techniqueID": "T1219", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1573.001", + "techniqueID": "T1117", "score": 7, - "showSubtechniques": false + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, { - "techniqueID": "T1069.002", - "score": 7, + "techniqueID": "T1090", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1021.004", - "score": 7, + "techniqueID": "T1102", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1007", - "score": 5, + "techniqueID": "T1218.010", + "score": 6, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" - }, - { - "techniqueID": "T1071", - "score": 7, - "showSubtechniques": false + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, { - "techniqueID": "T1547.009", - "score": 7, + "techniqueID": "T1065", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1070.001", - "score": 5, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" - }, - { - "techniqueID": "T1588.001", - "score": 7, + "techniqueID": "T1088", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1070", - "score": 5, + "techniqueID": "T1048.003", + "score": 4, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, { - "techniqueID": "T1552.001", - "score": 7, + "techniqueID": "T1132.001", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1023", - "score": 7, + "techniqueID": "T1059.007", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1098", - "score": -5, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1027.005", - "score": 7, + "techniqueID": "T1590.002", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1114.002", - "score": 6, + "techniqueID": "T1548.002", + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/disabling_remote_user_account_control.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/eventvwr_uac_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/fodhelper_uac_bypass.yml" }, { - "techniqueID": "T1012", + "techniqueID": "T1071.004", "score": 6, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_record_changed.yml" }, { - "techniqueID": "T1221", - "score": 7, + "techniqueID": "T1003.004", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1134", - "score": 3, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" - }, - { - "techniqueID": "T1066", - "score": 7, + "techniqueID": "T1137", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1003.002", + "techniqueID": "T1106", "score": 6, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" - }, - { - "techniqueID": "T1587.001", - "score": 7, - "showSubtechniques": false - }, - { - "techniqueID": "T1573.001", - "score": 7, - "showSubtechniques": false - }, - { - "techniqueID": "T1069.002", - "score": 7, - "showSubtechniques": false - }, - { - "techniqueID": "T1021.004", - "score": 7, - "showSubtechniques": false - }, - { - "techniqueID": "T1007", - "score": 5, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" - }, - { - "techniqueID": "T1071", - "score": 7, - "showSubtechniques": false + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_service_and_process_control_via_powersploit_modules.yml" }, { - "techniqueID": "T1547.009", - "score": 7, + "techniqueID": "T1219", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1070.001", - "score": 5, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" - }, - { - "techniqueID": "T1588.001", + "techniqueID": "T1117", "score": 7, - "showSubtechniques": false - }, - { - "techniqueID": "T1070", - "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" - }, - { - "techniqueID": "T1552.001", - "score": 7, - "showSubtechniques": false + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___first_time_seen_cmd_line.yml" }, { - "techniqueID": "T1023", - "score": 7, + "techniqueID": "T1090", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1098", - "score": -5, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" - }, - { - "techniqueID": "T1027.005", - "score": 7, + "techniqueID": "T1102", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1114.002", + "techniqueID": "T1218.010", "score": 6, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/detect_regsvr32_application_control_bypass.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_regsvr32_register_suspicious_path.yml" }, { - "techniqueID": "T1012", - "score": 6, - "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" + "techniqueID": "T1065", + "score": 8, + "showSubtechniques": false }, { - "techniqueID": "T1221", - "score": 7, + "techniqueID": "T1088", + "score": 8, "showSubtechniques": false }, { - "techniqueID": "T1134", - "score": 3, + "techniqueID": "T1048.003", + "score": 4, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_long_dns_txt_record_response.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detection_of_dns_tunnels.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml" }, { "techniqueID": "T1066", @@ -198347,9 +198187,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -198455,9 +198295,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -198563,9 +198403,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -198671,9 +198511,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -198779,9 +198619,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -198887,9 +198727,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -198995,9 +198835,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -199103,9 +198943,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -199211,9 +199051,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -199319,9 +199159,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -199427,9 +199267,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -199535,9 +199375,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -199643,9 +199483,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -199751,9 +199591,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -199859,9 +199699,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -199967,9 +199807,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -200075,9 +199915,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -200183,9 +200023,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -200291,9 +200131,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -200399,9 +200239,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -200507,9 +200347,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -200615,9 +200455,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -200723,9 +200563,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -200831,9 +200671,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -200939,9 +200779,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -201047,9 +200887,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -201155,9 +200995,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -201263,9 +201103,117 @@ }, { "techniqueID": "T1003.002", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" + }, + { + "techniqueID": "T1587.001", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1573.001", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1069.002", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1021.004", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1007", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" + }, + { + "techniqueID": "T1071", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1547.009", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1070.001", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" + }, + { + "techniqueID": "T1588.001", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1070", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" + }, + { + "techniqueID": "T1552.001", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1023", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1098", + "score": -5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" + }, + { + "techniqueID": "T1027.005", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1114.002", + "score": 6, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" + }, + { + "techniqueID": "T1012", "score": 6, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" + }, + { + "techniqueID": "T1221", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1134", + "score": 3, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" + }, + { + "techniqueID": "T1066", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1003.002", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -201371,9 +201319,117 @@ }, { "techniqueID": "T1003.002", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" + }, + { + "techniqueID": "T1587.001", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1573.001", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1069.002", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1021.004", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1007", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" + }, + { + "techniqueID": "T1071", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1547.009", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1070.001", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" + }, + { + "techniqueID": "T1588.001", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1070", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" + }, + { + "techniqueID": "T1552.001", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1023", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1098", + "score": -5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" + }, + { + "techniqueID": "T1027.005", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1114.002", + "score": 6, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" + }, + { + "techniqueID": "T1012", "score": 6, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" + }, + { + "techniqueID": "T1221", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1134", + "score": 3, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" + }, + { + "techniqueID": "T1066", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1003.002", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -201479,9 +201535,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -201587,9 +201643,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -201695,9 +201751,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -201803,9 +201859,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -201911,9 +201967,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -202019,9 +202075,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -202127,9 +202183,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -202235,9 +202291,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -202343,9 +202399,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -202451,9 +202507,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -202559,9 +202615,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -202667,9 +202723,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -202775,9 +202831,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -202883,9 +202939,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -202991,9 +203047,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -203099,9 +203155,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -203207,9 +203263,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -203315,9 +203371,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -203423,9 +203479,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -203531,9 +203587,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -203639,9 +203695,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -203747,9 +203803,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -203855,9 +203911,117 @@ }, { "techniqueID": "T1003.002", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" + }, + { + "techniqueID": "T1587.001", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1573.001", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1069.002", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1021.004", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1007", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" + }, + { + "techniqueID": "T1071", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1547.009", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1070.001", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" + }, + { + "techniqueID": "T1588.001", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1070", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" + }, + { + "techniqueID": "T1552.001", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1023", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1098", + "score": -5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" + }, + { + "techniqueID": "T1027.005", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1114.002", + "score": 6, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" + }, + { + "techniqueID": "T1012", "score": 6, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" + }, + { + "techniqueID": "T1221", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1134", + "score": 3, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" + }, + { + "techniqueID": "T1066", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1003.002", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -203963,9 +204127,117 @@ }, { "techniqueID": "T1003.002", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" + }, + { + "techniqueID": "T1587.001", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1573.001", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1069.002", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1021.004", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1007", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" + }, + { + "techniqueID": "T1071", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1547.009", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1070.001", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" + }, + { + "techniqueID": "T1588.001", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1070", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" + }, + { + "techniqueID": "T1552.001", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1023", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1098", + "score": -5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" + }, + { + "techniqueID": "T1027.005", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1114.002", + "score": 6, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" + }, + { + "techniqueID": "T1012", "score": 6, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" + }, + { + "techniqueID": "T1221", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1134", + "score": 3, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" + }, + { + "techniqueID": "T1066", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1003.002", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -204071,9 +204343,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -204179,9 +204451,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -204287,9 +204559,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -204395,9 +204667,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -204503,9 +204775,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -204611,9 +204883,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -204719,9 +204991,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -204827,9 +205099,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -204935,9 +205207,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -205043,9 +205315,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -205151,9 +205423,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -205259,9 +205531,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -205367,9 +205639,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -205475,9 +205747,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -205583,9 +205855,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -205691,9 +205963,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -205799,9 +206071,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -205907,9 +206179,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -206015,9 +206287,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -206123,9 +206395,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -206231,9 +206503,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -206339,9 +206611,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -206447,9 +206719,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -206555,9 +206827,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -206663,9 +206935,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -206771,9 +207043,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -206879,9 +207151,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -206987,9 +207259,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -207095,9 +207367,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -207203,9 +207475,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -207311,9 +207583,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -207419,9 +207691,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -207527,9 +207799,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -207635,9 +207907,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -207743,9 +208015,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -207851,9 +208123,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -207959,9 +208231,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -208067,9 +208339,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -208175,9 +208447,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -208283,9 +208555,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -208391,9 +208663,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -208499,9 +208771,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -208607,9 +208879,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -208715,9 +208987,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -208823,9 +209095,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -208931,9 +209203,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -209039,9 +209311,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -209147,9 +209419,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -209255,9 +209527,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -209363,9 +209635,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -209471,9 +209743,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -209579,9 +209851,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -209687,9 +209959,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -209795,9 +210067,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -209903,9 +210175,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -210011,9 +210283,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -210119,9 +210391,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -210227,9 +210499,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -210335,9 +210607,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -210443,9 +210715,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -210551,9 +210823,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -210659,9 +210931,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -210767,9 +211039,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -210875,9 +211147,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -210983,9 +211255,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -211091,9 +211363,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -211199,9 +211471,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -211307,9 +211579,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -211415,9 +211687,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -211523,9 +211795,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -211631,9 +211903,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -211739,9 +212011,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -211847,9 +212119,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -211955,9 +212227,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -212063,9 +212335,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -212171,9 +212443,117 @@ }, { "techniqueID": "T1003.002", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" + }, + { + "techniqueID": "T1587.001", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1573.001", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1069.002", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1021.004", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1007", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" + }, + { + "techniqueID": "T1071", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1547.009", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1070.001", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" + }, + { + "techniqueID": "T1588.001", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1070", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" + }, + { + "techniqueID": "T1552.001", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1023", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1098", + "score": -5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" + }, + { + "techniqueID": "T1027.005", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1114.002", + "score": 6, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" + }, + { + "techniqueID": "T1012", "score": 6, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" + }, + { + "techniqueID": "T1221", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1134", + "score": 3, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" + }, + { + "techniqueID": "T1066", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1003.002", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -212279,9 +212659,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -212387,9 +212767,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -212495,9 +212875,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -212603,9 +212983,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -212711,9 +213091,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -212819,9 +213199,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -212927,9 +213307,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -213035,9 +213415,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -213143,9 +213523,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -213251,9 +213631,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -213359,9 +213739,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -213467,9 +213847,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -213575,9 +213955,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -213683,9 +214063,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -213791,9 +214171,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -213899,9 +214279,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -214007,9 +214387,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -214115,9 +214495,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -214223,9 +214603,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -214331,9 +214711,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -214439,9 +214819,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -214547,9 +214927,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -214655,9 +215035,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -214763,9 +215143,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -214871,9 +215251,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -214979,9 +215359,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -215087,9 +215467,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -215195,9 +215575,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -215303,9 +215683,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -215411,9 +215791,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -215519,9 +215899,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -215627,9 +216007,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -215735,9 +216115,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -215843,9 +216223,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -215951,9 +216331,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -216059,9 +216439,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -216167,9 +216547,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -216275,9 +216655,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -216383,9 +216763,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -216491,9 +216871,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -216599,9 +216979,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -216707,9 +217087,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -216815,9 +217195,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -216923,9 +217303,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -217031,9 +217411,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -217139,9 +217519,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -217247,9 +217627,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -217355,9 +217735,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -217463,9 +217843,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -217571,9 +217951,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -217679,9 +218059,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -217787,9 +218167,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -217895,9 +218275,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -218003,9 +218383,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -218111,9 +218491,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -218219,9 +218599,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -218327,9 +218707,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -218435,9 +218815,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -218543,9 +218923,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -218651,9 +219031,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -218759,9 +219139,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -218867,9 +219247,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -218975,9 +219355,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -219083,9 +219463,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -219191,9 +219571,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -219299,9 +219679,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -219407,9 +219787,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -219515,9 +219895,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -219623,9 +220003,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -219731,9 +220111,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -219839,9 +220219,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -219947,9 +220327,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -220055,9 +220435,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -220163,9 +220543,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -220271,9 +220651,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -220379,9 +220759,117 @@ }, { "techniqueID": "T1003.002", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" + }, + { + "techniqueID": "T1587.001", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1573.001", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1069.002", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1021.004", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1007", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" + }, + { + "techniqueID": "T1071", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1547.009", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1070.001", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" + }, + { + "techniqueID": "T1588.001", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1070", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" + }, + { + "techniqueID": "T1552.001", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1023", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1098", + "score": -5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" + }, + { + "techniqueID": "T1027.005", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1114.002", + "score": 6, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" + }, + { + "techniqueID": "T1012", "score": 6, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" + }, + { + "techniqueID": "T1221", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1134", + "score": 3, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" + }, + { + "techniqueID": "T1066", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1003.002", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -220487,9 +220975,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -220595,9 +221083,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -220703,9 +221191,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -220811,9 +221299,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -220919,9 +221407,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -221027,9 +221515,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -221135,9 +221623,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -221243,9 +221731,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -221351,9 +221839,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -221459,9 +221947,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -221567,9 +222055,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -221675,9 +222163,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -221783,9 +222271,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -221891,9 +222379,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -221999,9 +222487,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -222107,9 +222595,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -222215,9 +222703,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -222323,9 +222811,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -222431,9 +222919,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -222539,9 +223027,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -222647,9 +223135,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -222755,9 +223243,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -222863,9 +223351,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -222971,9 +223459,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -223079,9 +223567,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -223187,9 +223675,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -223295,9 +223783,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -223403,9 +223891,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -223511,9 +223999,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -223619,9 +224107,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -223727,9 +224215,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -223835,9 +224323,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -223943,9 +224431,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -224051,9 +224539,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -224159,9 +224647,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -224267,9 +224755,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -224375,9 +224863,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -224483,9 +224971,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -224591,9 +225079,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -224699,9 +225187,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -224807,9 +225295,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -224915,9 +225403,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -225023,9 +225511,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -225131,9 +225619,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -225239,9 +225727,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -225347,9 +225835,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -225455,9 +225943,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -225563,9 +226051,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -225671,9 +226159,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -225779,9 +226267,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -225887,9 +226375,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -225995,9 +226483,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -226103,9 +226591,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -226211,9 +226699,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -226319,9 +226807,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -226427,9 +226915,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -226535,9 +227023,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -226643,9 +227131,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -226751,9 +227239,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -226859,9 +227347,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -226967,9 +227455,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -227075,9 +227563,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -227183,9 +227671,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -227291,9 +227779,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -227399,9 +227887,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -227507,9 +227995,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -227615,9 +228103,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -227723,9 +228211,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -227831,9 +228319,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -227939,9 +228427,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -228047,9 +228535,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -228155,9 +228643,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -228263,9 +228751,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -228371,9 +228859,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -228479,9 +228967,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -228587,9 +229075,117 @@ }, { "techniqueID": "T1003.002", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" + }, + { + "techniqueID": "T1587.001", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1573.001", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1069.002", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1021.004", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1007", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" + }, + { + "techniqueID": "T1071", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1547.009", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1070.001", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" + }, + { + "techniqueID": "T1588.001", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1070", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" + }, + { + "techniqueID": "T1552.001", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1023", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1098", + "score": -5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" + }, + { + "techniqueID": "T1027.005", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1114.002", + "score": 6, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" + }, + { + "techniqueID": "T1012", "score": 6, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" + }, + { + "techniqueID": "T1221", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1134", + "score": 3, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" + }, + { + "techniqueID": "T1066", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1003.002", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -228695,9 +229291,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -228803,9 +229399,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -228911,9 +229507,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -229019,9 +229615,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -229127,9 +229723,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -229235,9 +229831,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -229343,9 +229939,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -229451,9 +230047,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -229559,9 +230155,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -229667,9 +230263,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -229775,9 +230371,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -229883,9 +230479,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -229991,9 +230587,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -230099,9 +230695,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -230207,9 +230803,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -230315,9 +230911,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -230423,9 +231019,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -230531,9 +231127,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -230639,9 +231235,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -230747,9 +231343,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -230855,9 +231451,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -230963,9 +231559,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -231071,9 +231667,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -231179,9 +231775,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -231287,9 +231883,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -231395,9 +231991,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -231503,9 +232099,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -231611,9 +232207,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -231719,9 +232315,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -231827,9 +232423,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -231935,9 +232531,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -232043,9 +232639,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -232151,9 +232747,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -232259,9 +232855,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -232367,9 +232963,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -232475,9 +233071,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -232583,9 +233179,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -232691,9 +233287,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -232799,9 +233395,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -232907,9 +233503,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -233015,9 +233611,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -233123,9 +233719,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -233231,9 +233827,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -233339,9 +233935,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -233447,9 +234043,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -233555,9 +234151,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -233663,9 +234259,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -233771,9 +234367,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -233879,9 +234475,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -233987,9 +234583,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -234095,9 +234691,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -234203,9 +234799,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -234311,9 +234907,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -234419,9 +235015,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -234527,9 +235123,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -234635,9 +235231,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -234743,9 +235339,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -234851,9 +235447,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -234959,9 +235555,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -235067,9 +235663,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -235175,9 +235771,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -235283,9 +235879,9 @@ }, { "techniqueID": "T1003.002", - "score": 6, + "score": 5, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -235391,9 +235987,117 @@ }, { "techniqueID": "T1003.002", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" + }, + { + "techniqueID": "T1587.001", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1573.001", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1069.002", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1021.004", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1007", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_processes_and_services_via_mimikatz_modules.yml" + }, + { + "techniqueID": "T1071", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1547.009", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1070.001", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/suspicious_wevtutil_usage.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/windows_event_log_cleared.yml" + }, + { + "techniqueID": "T1588.001", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1070", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_log_deletion_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/usn_journal_deletion.yml" + }, + { + "techniqueID": "T1552.001", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1023", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1098", + "score": -5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___assess_credential_strength_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_account_enable_disable_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_AD_elements_and_policies_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_management_computers_and_AD_elements_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___probing_access_with_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_credential_stores_and_services_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___recon_privilege_escalation_opportunities_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_dsinternals_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___setting_credentials_via_powersploit_modules.yml" + }, + { + "techniqueID": "T1027.005", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1114.002", + "score": 6, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/o365_suspicious_rights_delegation.yml" + }, + { + "techniqueID": "T1012", "score": 6, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___recon_and_use_operating_system_elements_via_powersploit_modules.yml" + }, + { + "techniqueID": "T1221", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1134", + "score": 3, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_mimikatz_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___applying_stolen_credentials_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_and_persistence_via_powersploit_modules.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ssa___illegal_privilege_elevation_via_mimikatz_modules.yml" + }, + { + "techniqueID": "T1066", + "score": 7, + "showSubtechniques": false + }, + { + "techniqueID": "T1003.002", + "score": 5, + "showSubtechniques": false, + "comment": "https://github.com/splunk/security_content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/process_deleting_its_process_file_path.yml" }, { "techniqueID": "T1587.001", @@ -304929,9 +305633,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -305068,9 +305772,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -305207,9 +305911,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -305346,9 +306050,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -305485,9 +306189,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -305624,9 +306328,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -305763,9 +306467,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -305902,9 +306606,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -306041,9 +306745,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -306180,9 +306884,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -306319,9 +307023,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -306458,9 +307162,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -306597,9 +307301,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -306736,9 +307440,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -306875,9 +307579,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -307014,9 +307718,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -307153,9 +307857,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -307292,9 +307996,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -307431,9 +308135,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -307570,9 +308274,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -307709,9 +308413,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -307848,9 +308552,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -307987,9 +308691,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -308126,9 +308830,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -308265,9 +308969,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -308404,9 +309108,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -308543,9 +309247,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -308682,9 +309386,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -308821,9 +309525,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -308960,9 +309664,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -309099,9 +309803,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -309238,9 +309942,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -309377,9 +310081,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -309516,9 +310220,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -309655,9 +310359,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -309794,9 +310498,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -309933,9 +310637,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -310072,9 +310776,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -310211,9 +310915,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -310350,9 +311054,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -310489,9 +311193,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -310628,9 +311332,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -310767,9 +311471,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -310906,9 +311610,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -311045,9 +311749,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -311184,9 +311888,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -311323,9 +312027,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -311462,9 +312166,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -311601,9 +312305,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -311740,9 +312444,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -311879,9 +312583,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -312018,9 +312722,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -312157,9 +312861,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -312296,9 +313000,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -312435,9 +313139,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -312574,9 +313278,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -312713,9 +313417,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -312852,9 +313556,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -312991,9 +313695,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -313130,9 +313834,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -313269,9 +313973,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -313408,9 +314112,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -313547,9 +314251,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -313686,9 +314390,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -313825,9 +314529,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -313964,9 +314668,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -314103,9 +314807,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -314242,9 +314946,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -314381,9 +315085,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -314520,9 +315224,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -314659,9 +315363,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -314798,9 +315502,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -314937,9 +315641,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -315076,9 +315780,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -315215,9 +315919,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -315354,9 +316058,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -315493,9 +316197,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -315632,9 +316336,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -315771,9 +316475,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -315910,9 +316614,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -316049,9 +316753,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -316188,9 +316892,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -316327,9 +317031,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -316466,9 +317170,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -316605,9 +317309,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -316744,9 +317448,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -316883,9 +317587,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -317022,9 +317726,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -317161,9 +317865,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -317300,9 +318004,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -317439,9 +318143,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -317578,9 +318282,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -317717,9 +318421,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -317856,9 +318560,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -317995,9 +318699,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -318134,9 +318838,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -318273,9 +318977,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -318412,9 +319116,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -318551,9 +319255,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -318690,9 +319394,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -318829,9 +319533,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -318968,9 +319672,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -319107,9 +319811,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -319246,9 +319950,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -319385,9 +320089,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -319524,9 +320228,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -319663,9 +320367,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -319802,9 +320506,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -319941,9 +320645,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -320080,9 +320784,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -320219,9 +320923,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -320358,9 +321062,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -320497,9 +321201,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -320636,9 +321340,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -320775,9 +321479,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -320914,9 +321618,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -321053,9 +321757,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -321192,9 +321896,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -321331,9 +322035,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -321470,9 +322174,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -321609,9 +322313,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -321748,9 +322452,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -321887,9 +322591,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -322026,9 +322730,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -322165,9 +322869,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -322304,9 +323008,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -322443,9 +323147,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -322582,9 +323286,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -322721,9 +323425,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -322860,9 +323564,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -322999,9 +323703,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -323138,9 +323842,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -323277,9 +323981,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -323416,9 +324120,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -323555,9 +324259,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -323694,9 +324398,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -323833,9 +324537,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -323972,9 +324676,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -324111,9 +324815,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -324250,9 +324954,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -324389,9 +325093,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -324528,9 +325232,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -324667,9 +325371,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -324806,9 +325510,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -324945,9 +325649,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -325084,9 +325788,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -325223,9 +325927,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -325362,9 +326066,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -325501,9 +326205,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -325640,9 +326344,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -325779,9 +326483,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -325918,9 +326622,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -326057,9 +326761,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -326196,9 +326900,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -326335,9 +327039,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -326474,9 +327178,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -326613,9 +327317,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -326752,9 +327456,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -326891,9 +327595,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -327030,9 +327734,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -327169,9 +327873,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -327308,9 +328012,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -327447,9 +328151,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -327586,9 +328290,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -327725,9 +328429,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -327864,9 +328568,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -328003,9 +328707,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -328142,9 +328846,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -328281,9 +328985,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -328420,9 +329124,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -328559,9 +329263,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -328698,9 +329402,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -328837,9 +329541,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -328976,9 +329680,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -329115,9 +329819,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -329254,9 +329958,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -329393,9 +330097,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -329532,9 +330236,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -329671,9 +330375,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -329810,9 +330514,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -329949,9 +330653,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -330088,9 +330792,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -330227,9 +330931,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -330366,9 +331070,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -330505,9 +331209,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -330644,9 +331348,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -330783,9 +331487,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -330922,9 +331626,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -331061,9 +331765,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -331200,9 +331904,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -331339,9 +332043,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -331478,9 +332182,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -331617,9 +332321,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -331756,9 +332460,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -331895,9 +332599,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -332034,9 +332738,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -332173,9 +332877,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -332312,9 +333016,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -332451,9 +333155,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -332590,9 +333294,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -332729,9 +333433,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -332868,9 +333572,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -333007,9 +333711,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -333146,9 +333850,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -333285,9 +333989,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -333424,9 +334128,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -333563,9 +334267,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -333702,9 +334406,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -333841,9 +334545,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -333980,9 +334684,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -334119,9 +334823,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -334258,9 +334962,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -334397,9 +335101,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -334536,9 +335240,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -334675,9 +335379,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -334814,9 +335518,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -334953,9 +335657,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -335092,9 +335796,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -335231,9 +335935,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -335370,9 +336074,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -335509,9 +336213,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -335648,9 +336352,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -335787,9 +336491,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -335926,9 +336630,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -336065,9 +336769,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -336204,9 +336908,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -336343,9 +337047,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -336482,9 +337186,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -336621,9 +337325,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -336760,9 +337464,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -336899,9 +337603,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -337038,9 +337742,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -337177,9 +337881,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -337316,9 +338020,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -337455,9 +338159,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -337594,9 +338298,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -337733,9 +338437,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -337872,9 +338576,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -338011,9 +338715,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -338150,9 +338854,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -338289,9 +338993,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -338428,9 +339132,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -338567,9 +339271,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -338706,9 +339410,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -338845,9 +339549,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -338984,9 +339688,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -339123,9 +339827,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -339262,9 +339966,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -339401,9 +340105,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -339540,9 +340244,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -339679,9 +340383,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -339818,9 +340522,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -339957,9 +340661,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -340096,9 +340800,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -340235,9 +340939,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -340374,9 +341078,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -340513,9 +341217,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -340652,9 +341356,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -340791,9 +341495,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -340930,9 +341634,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -341069,9 +341773,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -341208,9 +341912,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -341347,9 +342051,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -341486,9 +342190,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -341625,9 +342329,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -341764,9 +342468,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -341903,9 +342607,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -342042,9 +342746,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -342181,9 +342885,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -342320,9 +343024,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -342459,9 +343163,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -342598,9 +343302,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -342737,9 +343441,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -342876,9 +343580,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -343015,9 +343719,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -343154,9 +343858,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -343293,9 +343997,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -343432,9 +344136,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -343571,9 +344275,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -343710,9 +344414,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -343849,9 +344553,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -343988,9 +344692,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -344127,9 +344831,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -344266,9 +344970,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -344405,9 +345109,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -344544,9 +345248,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -344683,9 +345387,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -344822,9 +345526,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -344961,9 +345665,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -345100,9 +345804,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -345239,9 +345943,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -345378,9 +346082,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -345517,9 +346221,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -345656,9 +346360,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -345795,9 +346499,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -345934,9 +346638,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -346073,9 +346777,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -346212,9 +346916,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -346351,9 +347055,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -346490,9 +347194,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -346629,9 +347333,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -346768,9 +347472,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -346907,9 +347611,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -347046,9 +347750,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -347185,9 +347889,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -347324,9 +348028,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -347463,9 +348167,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -347602,9 +348306,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -347741,9 +348445,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -347880,9 +348584,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -348019,9 +348723,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -348158,9 +348862,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -348297,9 +349001,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -348436,9 +349140,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -348575,9 +349279,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -348714,9 +349418,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -348853,9 +349557,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -348992,9 +349696,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -349131,9 +349835,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -349270,9 +349974,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -349409,9 +350113,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -349548,9 +350252,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -349687,9 +350391,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -349826,9 +350530,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -349965,9 +350669,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -350104,9 +350808,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -350243,9 +350947,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -350382,9 +351086,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -350521,9 +351225,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -350660,9 +351364,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -350799,9 +351503,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -350938,9 +351642,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -351077,9 +351781,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -351216,9 +351920,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -351355,9 +352059,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -351494,9 +352198,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -351633,9 +352337,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -351772,9 +352476,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -351911,9 +352615,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -352050,9 +352754,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -352189,9 +352893,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -352328,9 +353032,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -352467,9 +353171,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -352606,9 +353310,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -352745,9 +353449,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -352884,9 +353588,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -353023,9 +353727,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -353162,9 +353866,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -353301,9 +354005,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -353440,9 +354144,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -353579,9 +354283,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -353718,9 +354422,9 @@ }, { "techniqueID": "T1036.003", - "score": -2, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_path.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_microsoft_workflow_compiler_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_msbuild_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/suspicious_rundll32_rename.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml" }, { "techniqueID": "T1570", @@ -353884,9 +354588,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -353921,9 +354625,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -354080,9 +354784,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -354117,9 +354821,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -354276,9 +354980,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -354313,9 +355017,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -354472,9 +355176,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -354509,9 +355213,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -354668,9 +355372,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -354705,9 +355409,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -354864,9 +355568,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -354901,9 +355605,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -355060,9 +355764,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -355097,9 +355801,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -355256,9 +355960,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -355293,9 +355997,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -355452,9 +356156,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -355489,9 +356193,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -355648,9 +356352,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -355685,9 +356389,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -355844,9 +356548,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -355881,9 +356585,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -356040,9 +356744,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -356077,9 +356781,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -356236,9 +356940,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -356273,9 +356977,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -356432,9 +357136,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -356469,9 +357173,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -356628,9 +357332,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -356665,9 +357369,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -356824,9 +357528,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -356861,9 +357565,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -357020,9 +357724,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -357057,9 +357761,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -357216,9 +357920,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -357253,9 +357957,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -357412,9 +358116,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -357449,9 +358153,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -357608,9 +358312,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -357645,9 +358349,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -357804,9 +358508,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -357841,9 +358545,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -358000,9 +358704,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -358037,9 +358741,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -358196,9 +358900,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -358233,9 +358937,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -358392,9 +359096,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -358429,9 +359133,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -358588,9 +359292,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -358625,9 +359329,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -358784,9 +359488,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -358821,9 +359525,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -358980,9 +359684,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -359017,9 +359721,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -359176,9 +359880,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -359213,9 +359917,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -359372,9 +360076,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -359409,9 +360113,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -359568,9 +360272,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -359605,9 +360309,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -359764,9 +360468,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -359801,9 +360505,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -359960,9 +360664,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -359997,9 +360701,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -360156,9 +360860,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -360193,9 +360897,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -360352,9 +361056,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -360389,9 +361093,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -360548,9 +361252,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -360585,9 +361289,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -360744,9 +361448,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -360781,9 +361485,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -360940,9 +361644,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -360977,9 +361681,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -361136,9 +361840,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -361173,9 +361877,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -361332,9 +362036,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -361369,9 +362073,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -361528,9 +362232,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -361565,9 +362269,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -361724,9 +362428,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -361761,9 +362465,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -361920,9 +362624,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -361957,9 +362661,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -362116,9 +362820,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -362153,9 +362857,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -362312,9 +363016,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -362349,9 +363053,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -362508,9 +363212,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -362545,9 +363249,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -362704,9 +363408,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -362741,9 +363445,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -362900,9 +363604,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -362937,9 +363641,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -363096,9 +363800,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -363133,9 +363837,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -363292,9 +363996,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -363329,9 +364033,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -363488,9 +364192,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -363525,9 +364229,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -363684,9 +364388,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -363721,9 +364425,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -363880,9 +364584,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -363917,9 +364621,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -364076,9 +364780,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -364113,9 +364817,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -364272,9 +364976,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -364309,9 +365013,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -364468,9 +365172,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -364505,9 +365209,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -364664,9 +365368,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -364701,9 +365405,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -364860,9 +365564,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -364897,9 +365601,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -365056,9 +365760,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -365093,9 +365797,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -365252,9 +365956,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -365289,9 +365993,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -365448,9 +366152,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -365485,9 +366189,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -365644,9 +366348,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -365681,9 +366385,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -365840,9 +366544,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -365877,9 +366581,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -366036,9 +366740,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -366073,9 +366777,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -366232,9 +366936,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -366269,9 +366973,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -366428,9 +367132,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -366465,9 +367169,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -366624,9 +367328,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -366661,9 +367365,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -366820,9 +367524,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -366857,9 +367561,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -367016,9 +367720,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -367053,9 +367757,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -367212,9 +367916,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -367249,9 +367953,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -367408,9 +368112,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -367445,9 +368149,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -367604,9 +368308,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -367641,9 +368345,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -367800,9 +368504,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -367837,9 +368541,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -367996,9 +368700,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -368033,9 +368737,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -368192,9 +368896,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -368229,9 +368933,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -368388,9 +369092,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -368425,9 +369129,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -368584,9 +369288,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -368621,9 +369325,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -368780,9 +369484,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -368817,9 +369521,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -368976,9 +369680,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -369013,9 +369717,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -369172,9 +369876,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -369209,9 +369913,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -369368,9 +370072,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -369405,9 +370109,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -369564,9 +370268,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -369601,9 +370305,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -369760,9 +370464,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -369797,9 +370501,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -369956,9 +370660,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -369993,9 +370697,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -370152,9 +370856,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -370189,9 +370893,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -370348,9 +371052,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -370385,9 +371089,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -370544,9 +371248,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -370581,9 +371285,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -370740,9 +371444,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -370777,9 +371481,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -370936,9 +371640,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -370973,9 +371677,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -371132,9 +371836,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -371169,9 +371873,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -371328,9 +372032,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -371365,9 +372069,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -371524,9 +372228,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -371561,9 +372265,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -371720,9 +372424,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -371757,9 +372461,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -371916,9 +372620,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -371953,9 +372657,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -372112,9 +372816,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -372149,9 +372853,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -372308,9 +373012,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -372345,9 +373049,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -372504,9 +373208,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -372541,9 +373245,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -372700,9 +373404,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -372737,9 +373441,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -372896,9 +373600,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -372933,9 +373637,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -373092,9 +373796,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -373129,9 +373833,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -373288,9 +373992,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -373325,9 +374029,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -373484,9 +374188,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -373521,9 +374225,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -373680,9 +374384,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -373717,9 +374421,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -373876,9 +374580,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -373913,9 +374617,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -374072,9 +374776,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -374109,9 +374813,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -374268,9 +374972,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -374305,9 +375009,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -374464,9 +375168,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -374501,9 +375205,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -374660,9 +375364,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -374697,9 +375401,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -374856,9 +375560,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -374893,9 +375597,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -375052,9 +375756,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -375089,9 +375793,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -375248,9 +375952,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -375285,9 +375989,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -375444,9 +376148,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -375481,9 +376185,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -375640,9 +376344,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -375677,9 +376381,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -375836,9 +376540,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -375873,9 +376577,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -376032,9 +376736,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -376069,9 +376773,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -376228,9 +376932,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -376265,9 +376969,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -376424,9 +377128,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -376461,9 +377165,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -376620,9 +377324,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -376657,9 +377361,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -376816,9 +377520,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -376853,9 +377557,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -377012,9 +377716,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -377049,9 +377753,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -377208,9 +377912,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -377245,9 +377949,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -377404,9 +378108,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -377441,9 +378145,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -377600,9 +378304,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -377637,9 +378341,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -377796,9 +378500,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -377833,9 +378537,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -377992,9 +378696,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -378029,9 +378733,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -378188,9 +378892,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -378225,9 +378929,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -378384,9 +379088,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -378421,9 +379125,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -378580,9 +379284,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -378617,9 +379321,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -378776,9 +379480,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -378813,9 +379517,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -378972,9 +379676,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -379009,9 +379713,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -379168,9 +379872,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -379205,9 +379909,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -379364,9 +380068,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -379401,9 +380105,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -379560,9 +380264,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -379597,9 +380301,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -379756,9 +380460,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -379793,9 +380497,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -379952,9 +380656,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -379989,9 +380693,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -380148,9 +380852,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -380185,9 +380889,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -380344,9 +381048,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -380381,9 +381085,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -380540,9 +381244,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -380577,9 +381281,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -380736,9 +381440,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -380773,9 +381477,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -380932,9 +381636,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -380969,9 +381673,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -381128,9 +381832,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -381165,9 +381869,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -381324,9 +382028,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -381361,9 +382065,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -381520,9 +382224,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -381557,9 +382261,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -381716,9 +382420,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -381753,9 +382457,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -381912,9 +382616,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -381949,9 +382653,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -382108,9 +382812,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -382145,9 +382849,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -382304,9 +383008,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -382341,9 +383045,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -382500,9 +383204,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -382537,9 +383241,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -382696,9 +383400,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -382733,9 +383437,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -382892,9 +383596,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -382929,9 +383633,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -383088,9 +383792,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -383125,9 +383829,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -383284,9 +383988,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -383321,9 +384025,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -383480,9 +384184,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -383517,9 +384221,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -383676,9 +384380,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -383713,9 +384417,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -383872,9 +384576,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -383909,9 +384613,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -384068,9 +384772,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -384105,9 +384809,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -384264,9 +384968,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -384301,9 +385005,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -384460,9 +385164,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -384497,9 +385201,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -384656,9 +385360,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -384693,9 +385397,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -384852,9 +385556,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -384889,9 +385593,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -385048,9 +385752,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -385085,9 +385789,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -385244,9 +385948,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -385281,9 +385985,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -385440,9 +386144,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -385477,9 +386181,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -385636,9 +386340,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -385673,9 +386377,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -385832,9 +386536,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -385869,9 +386573,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -386028,9 +386732,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -386065,9 +386769,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -386224,9 +386928,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -386261,9 +386965,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -386420,9 +387124,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -386457,9 +387161,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -386616,9 +387320,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -386653,9 +387357,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -386812,9 +387516,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -386849,9 +387553,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -387008,9 +387712,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -387045,9 +387749,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -387204,9 +387908,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -387241,9 +387945,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -387400,9 +388104,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -387437,9 +388141,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -387596,9 +388300,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -387633,9 +388337,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -387792,9 +388496,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -387829,9 +388533,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -387988,9 +388692,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -388025,9 +388729,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -388184,9 +388888,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -388221,9 +388925,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -388380,9 +389084,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -388417,9 +389121,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -388576,9 +389280,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -388613,9 +389317,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -388772,9 +389476,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -388809,9 +389513,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -388968,9 +389672,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -389005,9 +389709,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -389164,9 +389868,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -389201,9 +389905,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -389360,9 +390064,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -389397,9 +390101,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -389556,9 +390260,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -389593,9 +390297,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -389752,9 +390456,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -389789,9 +390493,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -389948,9 +390652,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -389985,9 +390689,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -390144,9 +390848,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -390181,9 +390885,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -390340,9 +391044,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -390377,9 +391081,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -390536,9 +391240,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -390573,9 +391277,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -390732,9 +391436,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -390769,9 +391473,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -390928,9 +391632,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -390965,9 +391669,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -391124,9 +391828,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -391161,9 +391865,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -391320,9 +392024,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -391357,9 +392061,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -391516,9 +392220,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -391553,9 +392257,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -391712,9 +392416,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -391749,9 +392453,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -391908,9 +392612,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -391945,9 +392649,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -392104,9 +392808,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -392141,9 +392845,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -392300,9 +393004,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -392337,9 +393041,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -392496,9 +393200,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -392533,9 +393237,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -392692,9 +393396,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -392729,9 +393433,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -392888,9 +393592,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -392925,9 +393629,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -393084,9 +393788,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -393121,9 +393825,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -393280,9 +393984,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -393317,9 +394021,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -393476,9 +394180,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -393513,9 +394217,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -393672,9 +394376,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -393709,9 +394413,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -393868,9 +394572,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -393905,9 +394609,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -394064,9 +394768,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -394101,9 +394805,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -394260,9 +394964,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -394297,9 +395001,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -394456,9 +395160,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -394493,9 +395197,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -394652,9 +395356,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -394689,9 +395393,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -394848,9 +395552,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -394885,9 +395589,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -395044,9 +395748,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -395081,9 +395785,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -395240,9 +395944,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -395277,9 +395981,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -395436,9 +396140,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -395473,9 +396177,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -395632,9 +396336,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -395669,9 +396373,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -395828,9 +396532,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -395865,9 +396569,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -396024,9 +396728,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -396061,9 +396765,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -396220,9 +396924,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -396257,9 +396961,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -396416,9 +397120,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -396453,9 +397157,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -396612,9 +397316,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -396649,9 +397353,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -396808,9 +397512,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -396845,9 +397549,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -397004,9 +397708,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -397041,9 +397745,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -397200,9 +397904,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -397237,9 +397941,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -397396,9 +398100,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -397433,9 +398137,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -397592,9 +398296,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -397629,9 +398333,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -397788,9 +398492,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -397825,9 +398529,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -397984,9 +398688,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -398021,9 +398725,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -398180,9 +398884,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -398217,9 +398921,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -398376,9 +399080,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -398413,9 +399117,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -398572,9 +399276,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -398609,9 +399313,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -398768,9 +399472,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -398805,9 +399509,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -398964,9 +399668,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -399001,9 +399705,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -399160,9 +399864,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -399197,9 +399901,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -399356,9 +400060,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -399393,9 +400097,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -399552,9 +400256,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -399589,9 +400293,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -399748,9 +400452,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -399785,9 +400489,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -399944,9 +400648,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -399981,9 +400685,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -400140,9 +400844,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -400177,9 +400881,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -400336,9 +401040,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -400373,9 +401077,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -400532,9 +401236,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -400569,9 +401273,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -400728,9 +401432,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -400765,9 +401469,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -400924,9 +401628,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -400961,9 +401665,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -401120,9 +401824,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -401157,9 +401861,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -401316,9 +402020,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -401353,9 +402057,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -401512,9 +402216,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -401549,9 +402253,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -401708,9 +402412,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -401745,9 +402449,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -401904,9 +402608,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -401941,9 +402645,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -402100,9 +402804,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -402137,9 +402841,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -402296,9 +403000,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -402333,9 +403037,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -402492,9 +403196,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -402529,9 +403233,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -402688,9 +403392,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -402725,9 +403429,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -402884,9 +403588,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -402921,9 +403625,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -403080,9 +403784,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -403117,9 +403821,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -403276,9 +403980,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -403313,9 +404017,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -403472,9 +404176,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -403509,9 +404213,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -403668,9 +404372,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -403705,9 +404409,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -403864,9 +404568,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -403901,9 +404605,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -404060,9 +404764,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -404097,9 +404801,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -404256,9 +404960,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -404293,9 +404997,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -404452,9 +405156,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -404489,9 +405193,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -404648,9 +405352,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -404685,9 +405389,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -404844,9 +405548,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -404881,9 +405585,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -405040,9 +405744,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -405077,9 +405781,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -405236,9 +405940,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -405273,9 +405977,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -405432,9 +406136,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -405469,9 +406173,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -405628,9 +406332,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -405665,9 +406369,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -405824,9 +406528,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -405861,9 +406565,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -406020,9 +406724,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -406057,9 +406761,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -406216,9 +406920,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -406253,9 +406957,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -406412,9 +407116,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -406449,9 +407153,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -406608,9 +407312,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -406645,9 +407349,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -406804,9 +407508,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -406841,9 +407545,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -407000,9 +407704,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -407037,9 +407741,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -407196,9 +407900,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -407233,9 +407937,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -407392,9 +408096,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -407429,9 +408133,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -407588,9 +408292,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -407625,9 +408329,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -407784,9 +408488,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -407821,9 +408525,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -407980,9 +408684,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -408017,9 +408721,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -408176,9 +408880,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -408213,9 +408917,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -408372,9 +409076,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -408409,9 +409113,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -408568,9 +409272,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -408605,9 +409309,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -408764,9 +409468,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -408801,9 +409505,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -408960,9 +409664,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -408997,9 +409701,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -409156,9 +409860,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -409193,9 +409897,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -409352,9 +410056,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -409389,9 +410093,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -409548,9 +410252,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -409585,9 +410289,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -409744,9 +410448,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -409781,9 +410485,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -409940,9 +410644,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -409977,9 +410681,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -410136,9 +410840,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -410173,9 +410877,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -410332,9 +411036,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -410369,9 +411073,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -410528,9 +411232,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -410565,9 +411269,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -410724,9 +411428,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -410761,9 +411465,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -410920,9 +411624,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -410957,9 +411661,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -411116,9 +411820,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -411153,9 +411857,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -411312,9 +412016,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -411349,9 +412053,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -411508,9 +412212,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -411545,9 +412249,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -411704,9 +412408,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -411741,9 +412445,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -411900,9 +412604,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -411937,9 +412641,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -412096,9 +412800,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -412133,9 +412837,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -412292,9 +412996,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -412329,9 +413033,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -412488,9 +413192,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -412525,9 +413229,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -412684,9 +413388,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -412721,9 +413425,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -412880,9 +413584,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -412917,9 +413621,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -413076,9 +413780,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -413113,9 +413817,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -413272,9 +413976,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -413309,9 +414013,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -413468,9 +414172,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -413505,9 +414209,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -413664,9 +414368,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -413701,9 +414405,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -413860,9 +414564,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -413897,9 +414601,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -414056,9 +414760,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -414093,9 +414797,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -414252,9 +414956,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -414289,9 +414993,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -414448,9 +415152,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -414485,9 +415189,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -414644,9 +415348,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -414681,9 +415385,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -414840,9 +415544,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -414877,9 +415581,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -415036,9 +415740,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -415073,9 +415777,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -415232,9 +415936,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -415269,9 +415973,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -415428,9 +416132,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -415465,9 +416169,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -415624,9 +416328,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -415661,9 +416365,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -415820,9 +416524,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -415857,9 +416561,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -416016,9 +416720,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -416053,9 +416757,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -416212,9 +416916,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -416249,9 +416953,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -416408,9 +417112,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -416445,9 +417149,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -416604,9 +417308,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -416641,9 +417345,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -416800,9 +417504,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -416837,9 +417541,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -416996,9 +417700,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -417033,9 +417737,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -417192,9 +417896,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -417229,9 +417933,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -417388,9 +418092,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -417425,9 +418129,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -417584,9 +418288,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -417621,9 +418325,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -417780,9 +418484,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -417817,9 +418521,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -417976,9 +418680,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -418013,9 +418717,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -418172,9 +418876,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -418209,9 +418913,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -418368,9 +419072,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -418405,9 +419109,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -418564,9 +419268,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -418601,9 +419305,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -418760,9 +419464,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -418797,9 +419501,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -418956,9 +419660,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -418993,9 +419697,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -419152,9 +419856,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -419189,9 +419893,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -419348,9 +420052,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -419385,9 +420089,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -419544,9 +420248,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -419581,9 +420285,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -419740,9 +420444,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -419777,9 +420481,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -419936,9 +420640,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -419973,9 +420677,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -420132,9 +420836,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -420169,9 +420873,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -420328,9 +421032,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -420365,9 +421069,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -420524,9 +421228,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -420561,9 +421265,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -420720,9 +421424,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -420757,9 +421461,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -420916,9 +421620,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -420953,9 +421657,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -421112,9 +421816,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -421149,9 +421853,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -421308,9 +422012,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -421345,9 +422049,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -421504,9 +422208,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -421541,9 +422245,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -421700,9 +422404,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -421737,9 +422441,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -421896,9 +422600,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -421933,9 +422637,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -422092,9 +422796,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -422129,9 +422833,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -422288,9 +422992,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -422325,9 +423029,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -422484,9 +423188,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -422521,9 +423225,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -422680,9 +423384,9 @@ }, { "techniqueID": "T1486", - "score": -1, + "score": -3, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_creating_keys_with_encrypt_policy_without_mfa.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_detect_users_with_kms_keys_performing_encryption_s3.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_process_termination_frequency.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ransomware_notes_bulk_creation.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ryuk_test_files_detected.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/samsam_test_file_write.yml" }, { "techniqueID": "T1573", @@ -422717,9 +423421,9 @@ }, { "techniqueID": "T1485", - "score": 1, + "score": 0, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/common_ransomware_extensions.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/common_ransomware_notes.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/high_file_deletion_frequency.yml" }, { "techniqueID": "T1498", @@ -500283,9 +500987,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -500771,9 +501475,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -501259,9 +501963,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -501747,9 +502451,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -502235,9 +502939,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -502723,9 +503427,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -503211,9 +503915,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -503699,9 +504403,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -504187,9 +504891,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -504675,9 +505379,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -505163,9 +505867,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -505651,9 +506355,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -506139,9 +506843,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -506627,9 +507331,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -507115,9 +507819,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -507603,9 +508307,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -508091,9 +508795,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -508579,9 +509283,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -509067,9 +509771,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -509555,9 +510259,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -510043,9 +510747,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -510531,9 +511235,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -511019,9 +511723,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -511507,9 +512211,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -511995,9 +512699,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -512483,9 +513187,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -512971,9 +513675,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -513459,9 +514163,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -513947,9 +514651,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -514435,9 +515139,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -514923,9 +515627,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -515411,9 +516115,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -515899,9 +516603,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -516387,9 +517091,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -516875,9 +517579,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -517363,9 +518067,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -517851,9 +518555,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -518339,9 +519043,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -518827,9 +519531,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -519315,9 +520019,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -519803,9 +520507,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -520291,9 +520995,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -520779,9 +521483,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -521267,9 +521971,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -521755,9 +522459,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -522243,9 +522947,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -522731,9 +523435,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -523219,9 +523923,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -523707,9 +524411,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -524195,9 +524899,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -524683,9 +525387,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -525171,9 +525875,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -525659,9 +526363,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -526147,9 +526851,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -526635,9 +527339,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -527123,9 +527827,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -527611,9 +528315,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -528099,9 +528803,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -528587,9 +529291,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -529075,9 +529779,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -529563,9 +530267,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -530051,9 +530755,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -530539,9 +531243,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -531027,9 +531731,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -531515,9 +532219,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -532003,9 +532707,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -532491,9 +533195,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -532979,9 +533683,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -533467,9 +534171,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -533955,9 +534659,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -534443,9 +535147,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -534931,9 +535635,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -535419,9 +536123,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -535907,9 +536611,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -536395,9 +537099,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -536883,9 +537587,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -537371,9 +538075,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -537859,9 +538563,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -538347,9 +539051,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -538835,9 +539539,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -539323,9 +540027,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -539811,9 +540515,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -540299,9 +541003,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -540787,9 +541491,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -541275,9 +541979,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -541763,9 +542467,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -542251,9 +542955,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -542739,9 +543443,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -543227,9 +543931,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -543715,9 +544419,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -544203,9 +544907,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -544691,9 +545395,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -545179,9 +545883,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -545667,9 +546371,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -546155,9 +546859,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -546643,9 +547347,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -547131,9 +547835,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -547619,9 +548323,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -548107,9 +548811,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -548595,9 +549299,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -549083,9 +549787,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -549571,9 +550275,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -550059,9 +550763,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -550547,9 +551251,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -551035,9 +551739,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -551523,9 +552227,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -552011,9 +552715,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -552499,9 +553203,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -552987,9 +553691,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -553475,9 +554179,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -553963,9 +554667,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -554451,9 +555155,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -554939,9 +555643,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -555427,9 +556131,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -555915,9 +556619,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -556403,9 +557107,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -556891,9 +557595,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -557379,9 +558083,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -557867,9 +558571,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -558355,9 +559059,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -558843,9 +559547,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -559331,9 +560035,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -559819,9 +560523,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -560307,9 +561011,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -560795,9 +561499,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -561283,9 +561987,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -561771,9 +562475,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -562259,9 +562963,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -562747,9 +563451,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -563235,9 +563939,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -563723,9 +564427,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -564211,9 +564915,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -564699,9 +565403,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -565187,9 +565891,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -565675,9 +566379,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -566163,9 +566867,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -566651,9 +567355,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -567139,9 +567843,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -567627,9 +568331,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -568115,9 +568819,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -568603,9 +569307,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -569091,9 +569795,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -569579,9 +570283,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -570067,9 +570771,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -570555,9 +571259,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -571043,9 +571747,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -571531,9 +572235,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -572019,9 +572723,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -572507,9 +573211,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -572995,9 +573699,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -573483,9 +574187,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -573971,9 +574675,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -574459,9 +575163,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -574947,9 +575651,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -575435,9 +576139,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -575923,9 +576627,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -576411,9 +577115,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -576899,9 +577603,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -577387,9 +578091,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -577875,9 +578579,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -578363,9 +579067,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -578851,9 +579555,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -579339,9 +580043,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -579827,9 +580531,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -580315,9 +581019,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -580803,9 +581507,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -581291,9 +581995,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -581779,9 +582483,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -582267,9 +582971,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -582755,9 +583459,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -583243,9 +583947,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -583731,9 +584435,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -584219,9 +584923,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -584707,9 +585411,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -585195,9 +585899,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -585683,9 +586387,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -586171,9 +586875,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -586659,9 +587363,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -587147,9 +587851,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -587635,9 +588339,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -588123,9 +588827,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -588611,9 +589315,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -589099,9 +589803,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -589587,9 +590291,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -590075,9 +590779,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -590563,9 +591267,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -591051,9 +591755,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -591539,9 +592243,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -592027,9 +592731,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -592515,9 +593219,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -593003,9 +593707,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -593491,9 +594195,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -593979,9 +594683,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -594467,9 +595171,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -594955,9 +595659,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -595443,9 +596147,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -595931,9 +596635,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -596419,9 +597123,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -596907,9 +597611,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -597395,9 +598099,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -597883,9 +598587,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -598371,9 +599075,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -598859,9 +599563,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -599347,9 +600051,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -599835,9 +600539,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -600323,9 +601027,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -600811,9 +601515,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -601299,9 +602003,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -601787,9 +602491,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -602275,9 +602979,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -602763,9 +603467,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -603251,9 +603955,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -603739,9 +604443,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -604227,9 +604931,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -604715,9 +605419,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -605203,9 +605907,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -605691,9 +606395,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -606179,9 +606883,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -606667,9 +607371,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -607155,9 +607859,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -607643,9 +608347,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -608131,9 +608835,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -608619,9 +609323,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -609107,9 +609811,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -609595,9 +610299,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -610083,9 +610787,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -610571,9 +611275,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -611059,9 +611763,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -611547,9 +612251,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -612035,9 +612739,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -612523,9 +613227,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -613011,9 +613715,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -613499,9 +614203,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -613987,9 +614691,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -614475,9 +615179,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -614963,9 +615667,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -615451,9 +616155,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -615939,9 +616643,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -616427,9 +617131,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -616915,9 +617619,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -617403,9 +618107,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -617891,9 +618595,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -618379,9 +619083,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -618867,9 +619571,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -619355,9 +620059,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -619843,9 +620547,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -620331,9 +621035,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -620819,9 +621523,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -621307,9 +622011,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -621795,9 +622499,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -622283,9 +622987,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -622771,9 +623475,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -623259,9 +623963,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -623747,9 +624451,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -624235,9 +624939,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -624723,9 +625427,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -625211,9 +625915,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -625699,9 +626403,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -626187,9 +626891,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -626675,9 +627379,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -627163,9 +627867,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -627651,9 +628355,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -628139,9 +628843,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -628627,9 +629331,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -629115,9 +629819,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -629603,9 +630307,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -630091,9 +630795,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -630579,9 +631283,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -631067,9 +631771,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -631555,9 +632259,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -632043,9 +632747,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -632531,9 +633235,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -633019,9 +633723,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -633507,9 +634211,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -633995,9 +634699,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -634483,9 +635187,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -634971,9 +635675,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -635459,9 +636163,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -635947,9 +636651,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -636435,9 +637139,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -636923,9 +637627,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -637411,9 +638115,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -637899,9 +638603,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -638387,9 +639091,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -638875,9 +639579,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -639363,9 +640067,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -639851,9 +640555,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -640339,9 +641043,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -640827,9 +641531,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -641315,9 +642019,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -641803,9 +642507,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -642291,9 +642995,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -642779,9 +643483,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -643267,9 +643971,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -643755,9 +644459,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -644243,9 +644947,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -644731,9 +645435,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -645219,9 +645923,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -645707,9 +646411,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -646195,9 +646899,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -646683,9 +647387,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -647171,9 +647875,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -647659,9 +648363,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -648147,9 +648851,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -648635,9 +649339,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -649123,9 +649827,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -649611,9 +650315,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -650099,9 +650803,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -650587,9 +651291,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -651075,9 +651779,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -651563,9 +652267,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -652051,9 +652755,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -652539,9 +653243,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -653027,9 +653731,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -653515,9 +654219,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -654003,9 +654707,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -654491,9 +655195,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -654979,9 +655683,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -655467,9 +656171,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -655955,9 +656659,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -656443,9 +657147,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -656931,9 +657635,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -657419,9 +658123,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -657907,9 +658611,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -658395,9 +659099,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -658883,9 +659587,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -659371,9 +660075,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -659859,9 +660563,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -660347,9 +661051,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -660835,9 +661539,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -661323,9 +662027,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -661811,9 +662515,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -662299,9 +663003,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -662787,9 +663491,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -663275,9 +663979,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -663763,9 +664467,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -664251,9 +664955,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -664739,9 +665443,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -665227,9 +665931,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -665715,9 +666419,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -666203,9 +666907,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -666691,9 +667395,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -667179,9 +667883,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -667667,9 +668371,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -668155,9 +668859,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -668643,9 +669347,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -669131,9 +669835,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -669619,9 +670323,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -670107,9 +670811,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -670595,9 +671299,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -671083,9 +671787,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", @@ -671571,9 +672275,9 @@ }, { "techniqueID": "T1078.004", - "score": -14, + "score": -16, "showSubtechniques": false, - "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" + "comment": "https://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_infrastructure_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_number_of_cloud_security_group_api_calls.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_create_policy_version_to_allow_all_resources.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/aws_setdefaultpolicyversion.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/cloud_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_new_user_aws_console_login.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_aws_api_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/detect_spike_in_security_group_activity.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml\n\nhttps://github.com/splunk/security_content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml" }, { "techniqueID": "T1564.004", diff --git a/docs/stories.md b/docs/stories.md index 20e5d8db0e..21605807d9 100644 --- a/docs/stories.md +++ b/docs/stories.md @@ -330,7 +330,7 @@ Cobalt Strike is threat emulation software. Red teams and penetration testers us - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: Endpoint -- **ATT&CK**: [T1218.011](https://attack.mitre.org/techniques/T1218.011/) +- **ATT&CK**: [T1036.003](https://attack.mitre.org/techniques/T1036.003/), [T1055](https://attack.mitre.org/techniques/T1055/), [T1127](https://attack.mitre.org/techniques/T1127/), [T1127.001](https://attack.mitre.org/techniques/T1127.001/), [T1218.010](https://attack.mitre.org/techniques/T1218.010/), [T1218.011](https://attack.mitre.org/techniques/T1218.011/) - **Last Updated**: 2021-02-16
@@ -338,21 +338,44 @@ Cobalt Strike is threat emulation software. Red teams and penetration testers us #### Detection Profile +* [Cobalt Strike Named Pipes](detections.md#cobalt-strike-named-pipes) + +* [Detect Regsvr32 Application Control Bypass](detections.md#detect-regsvr32-application-control-bypass) + +* [Suspicious DLLHost no Command Line Arguments](detections.md#suspicious-dllhost-no-command-line-arguments) + +* [Suspicious GPUpdate no Command Line Arguments](detections.md#suspicious-gpupdate-no-command-line-arguments) + +* [Suspicious MSBuild Rename](detections.md#suspicious-msbuild-rename) + * [Suspicious Rundll32 StartW](detections.md#suspicious-rundll32-startw) -* [Suspicious Rundll32 no CommandLine Arguments](detections.md#suspicious-rundll32-no-commandline-arguments) +* [Suspicious Rundll32 no Command Line Arguments](detections.md#suspicious-rundll32-no-command-line-arguments) + +* [Suspicious SearchProtocolHost no Command Line Arguments](detections.md#suspicious-searchprotocolhost-no-command-line-arguments) + +* [Suspicious microsoft workflow compiler rename](detections.md#suspicious-microsoft-workflow-compiler-rename) + +* [Suspicious msbuild path](detections.md#suspicious-msbuild-path) #### ATT&CK | ID | Technique | Tactic | | ----------- | ----------- |--------------| +| T1055 | Process Injection | Defense Evasion, Privilege Escalation | +| T1218.010 | Regsvr32 | Defense Evasion | +| T1127.001 | MSBuild | Defense Evasion | +| T1036.003 | Rename System Utilities | Defense Evasion | | T1218.011 | Rundll32 | Defense Evasion | +| T1127 | Trusted Developer Utilities Proxy Execution | Defense Evasion | #### Kill Chain Phase * Actions on Objectives +* Exploitation + #### Reference @@ -366,6 +389,10 @@ Cobalt Strike is threat emulation software. Red teams and penetration testers us * https://www.fireeye.com/blog/threat-research/2020/12/unauthorized-access-of-fireeye-red-team-tools.html +* https://github.com/MichaelKoczwara/Awesome-CobaltStrike-Defence + +* https://github.com/zer0yu/Awesome-CobaltStrike + _version_: 1
@@ -541,7 +568,7 @@ Uncover activity consistent with credential dumping, a technique wherein attacke - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: Endpoint -- **ATT&CK**: [T1003](https://attack.mitre.org/techniques/T1003/), [T1003.001](https://attack.mitre.org/techniques/T1003.001/), [T1003.002](https://attack.mitre.org/techniques/T1003.002/), [T1003.003](https://attack.mitre.org/techniques/T1003.003/), [T1059.001](https://attack.mitre.org/techniques/T1059.001/) +- **ATT&CK**: [T1003](https://attack.mitre.org/techniques/T1003/), [T1003.001](https://attack.mitre.org/techniques/T1003.001/), [T1003.002](https://attack.mitre.org/techniques/T1003.002/), [T1003.003](https://attack.mitre.org/techniques/T1003.003/), [T1055](https://attack.mitre.org/techniques/T1055/), [T1059.001](https://attack.mitre.org/techniques/T1059.001/), [T1068](https://attack.mitre.org/techniques/T1068/), [T1078](https://attack.mitre.org/techniques/T1078/), [T1087](https://attack.mitre.org/techniques/T1087/), [T1098](https://attack.mitre.org/techniques/T1098/), [T1134](https://attack.mitre.org/techniques/T1134/), [T1201](https://attack.mitre.org/techniques/T1201/), [T1543](https://attack.mitre.org/techniques/T1543/), [T1547](https://attack.mitre.org/techniques/T1547/), [T1548](https://attack.mitre.org/techniques/T1548/), [T1552](https://attack.mitre.org/techniques/T1552/), [T1554](https://attack.mitre.org/techniques/T1554/), [T1555](https://attack.mitre.org/techniques/T1555/), [T1556](https://attack.mitre.org/techniques/T1556/), [T1558](https://attack.mitre.org/techniques/T1558/), [T1558.003](https://attack.mitre.org/techniques/T1558.003/) - **Last Updated**: 2020-02-04
@@ -551,6 +578,12 @@ Uncover activity consistent with credential dumping, a technique wherein attacke * [Access LSASS Memory for Dump Creation](detections.md#access-lsass-memory-for-dump-creation) +* [Applying Stolen Credentials via Mimikatz modules](detections.md#applying-stolen-credentials-via-mimikatz-modules) + +* [Applying Stolen Credentials via PowerSploit modules](detections.md#applying-stolen-credentials-via-powersploit-modules) + +* [Assessment of Credential Strength via DSInternals modules](detections.md#assessment-of-credential-strength-via-dsinternals-modules) + * [Attempt To Set Default PowerShell Execution Policy To Unrestricted or Bypass](detections.md#attempt-to-set-default-powershell-execution-policy-to-unrestricted-or-bypass) * [Attempted Credential Dump From Registry via Reg exe](detections.md#attempted-credential-dump-from-registry-via-reg-exe) @@ -567,10 +600,32 @@ Uncover activity consistent with credential dumping, a technique wherein attacke * [Credential Dumping via Symlink to Shadow Copy](detections.md#credential-dumping-via-symlink-to-shadow-copy) +* [Credential Extraction indicative of FGDump and CacheDump with s option](detections.md#credential-extraction-indicative-of-fgdump-and-cachedump-with-s-option) + +* [Credential Extraction indicative of FGDump and CacheDump with v option](detections.md#credential-extraction-indicative-of-fgdump-and-cachedump-with-v-option) + +* [Credential Extraction indicative of Lazagne command line options](detections.md#credential-extraction-indicative-of-lazagne-command-line-options) + +* [Credential Extraction indicative of use of DSInternals credential conversion modules](detections.md#credential-extraction-indicative-of-use-of-dsinternals-credential-conversion-modules) + +* [Credential Extraction indicative of use of DSInternals modules](detections.md#credential-extraction-indicative-of-use-of-dsinternals-modules) + +* [Credential Extraction indicative of use of Mimikatz modules](detections.md#credential-extraction-indicative-of-use-of-mimikatz-modules) + +* [Credential Extraction indicative of use of PowerSploit modules](detections.md#credential-extraction-indicative-of-use-of-powersploit-modules) + +* [Credential Extraction native Microsoft debuggers peek into the kernel](detections.md#credential-extraction-native-microsoft-debuggers-peek-into-the-kernel) + +* [Credential Extraction native Microsoft debuggers via z command line option](detections.md#credential-extraction-native-microsoft-debuggers-via-z-command-line-option) + +* [Credential Extraction via Get-ADDBAccount module present in PowerSploit and DSInternals](detections.md#credential-extraction-via-get-addbaccount-module-present-in-powersploit-and-dsinternals) + * [Detect Credential Dumping through LSASS access](detections.md#detect-credential-dumping-through-lsass-access) * [Detect Dump LSASS Memory using comsvcs](detections.md#detect-dump-lsass-memory-using-comsvcs) +* [Detect Kerberoasting](detections.md#detect-kerberoasting) + * [Detect Mimikatz Using Loaded Images](detections.md#detect-mimikatz-using-loaded-images) * [Dump LSASS via comsvcs DLL](detections.md#dump-lsass-via-comsvcs-dll) @@ -579,7 +634,7 @@ Uncover activity consistent with credential dumping, a technique wherein attacke * [Dump LSASS via procdump Rename](detections.md#dump-lsass-via-procdump-rename) -* [Ntdsutil export ntds](detections.md#ntdsutil-export-ntds) +* [Ntdsutil Export NTDS](detections.md#ntdsutil-export-ntds) * [Unsigned Image Loaded by LSASS](detections.md#unsigned-image-loaded-by-lsass) @@ -589,10 +644,26 @@ Uncover activity consistent with credential dumping, a technique wherein attacke | ID | Technique | Tactic | | ----------- | ----------- |--------------| | T1003.001 | LSASS Memory | Credential Access | +| T1055 | Process Injection | Defense Evasion, Privilege Escalation | +| T1068 | Exploitation for Privilege Escalation | Privilege Escalation | +| T1078 | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | +| T1098 | Account Manipulation | Persistence | +| T1134 | Access Token Manipulation | Defense Evasion, Privilege Escalation | +| T1543 | Create or Modify System Process | Persistence, Privilege Escalation | +| T1547 | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | +| T1548 | Abuse Elevation Control Mechanism | Defense Evasion, Privilege Escalation | +| T1554 | Compromise Client Software Binary | Persistence | +| T1556 | Modify Authentication Process | Credential Access, Defense Evasion | +| T1558 | Steal or Forge Kerberos Tickets | Credential Access | +| T1555 | Credentials from Password Stores | Credential Access | +| T1087 | Account Discovery | Discovery | +| T1201 | Password Policy Discovery | Discovery | +| T1552 | Unsecured Credentials | Credential Access | | T1059.001 | PowerShell | Execution | | T1003.002 | Security Account Manager | Credential Access | | T1003 | OS Credential Dumping | Credential Access | | T1003.003 | NTDS | Credential Access | +| T1558.003 | Kerberoasting | Credential Access | #### Kill Chain Phase @@ -701,6 +772,43 @@ The stealing of data by an adversary. * https://attack.mitre.org/tactics/TA0010/ +_version_: 1 +
+ +--- + +### Deobfuscate-Decode Files or Information +Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: Endpoint +- **ATT&CK**: [T1140](https://attack.mitre.org/techniques/T1140/) +- **Last Updated**: 2021-03-24 + +
+ details + +#### Detection Profile + +* [CertUtil With Decode Argument](detections.md#certutil-with-decode-argument) + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1140 | Deobfuscate/Decode Files or Information | Defense Evasion | + +#### Kill Chain Phase + +* Exploitation + + +#### Reference + +* https://attack.mitre.org/techniques/T1140/ + + _version_: 1
@@ -852,6 +960,133 @@ Uncover activity consistent with CVE-2020-5902. Discovered by Positive Technolog * https://blog.cloudflare.com/cve-2020-5902-helping-to-protect-against-the-f5-tmui-rce-vulnerability/ +_version_: 1 + + +--- + +### HAFNIUM Group +HAFNIUM group was identified by Microsoft as exploiting 4 Microsoft Exchange CVEs in the wild - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: Endpoint, Network_Traffic +- **ATT&CK**: [T1003.001](https://attack.mitre.org/techniques/T1003.001/), [T1003.003](https://attack.mitre.org/techniques/T1003.003/), [T1021.002](https://attack.mitre.org/techniques/T1021.002/), [T1059.001](https://attack.mitre.org/techniques/T1059.001/), [T1114.002](https://attack.mitre.org/techniques/T1114.002/), [T1136.001](https://attack.mitre.org/techniques/T1136.001/), [T1190](https://attack.mitre.org/techniques/T1190/), [T1505.003](https://attack.mitre.org/techniques/T1505.003/) +- **Last Updated**: 2021-03-03 + +
+ details + +#### Detection Profile + +* [Any Powershell DownloadString](detections.md#any-powershell-downloadstring) + +* [Attempt To Set Default PowerShell Execution Policy To Unrestricted or Bypass](detections.md#attempt-to-set-default-powershell-execution-policy-to-unrestricted-or-bypass) + +* [Detect Exchange Web Shell](detections.md#detect-exchange-web-shell) + +* [Detect New Local Admin account](detections.md#detect-new-local-admin-account) + +* [Detect PsExec With accepteula Flag](detections.md#detect-psexec-with-accepteula-flag) + +* [Dump LSASS via comsvcs DLL](detections.md#dump-lsass-via-comsvcs-dll) + +* [Dump LSASS via procdump](detections.md#dump-lsass-via-procdump) + +* [Dump LSASS via procdump Rename](detections.md#dump-lsass-via-procdump-rename) + +* [Email servers sending high volume traffic to hosts](detections.md#email-servers-sending-high-volume-traffic-to-hosts) + +* [Malicious PowerShell Process - Connect To Internet With Hidden Window](detections.md#malicious-powershell-process---connect-to-internet-with-hidden-window) + +* [Malicious PowerShell Process - Execution Policy Bypass](detections.md#malicious-powershell-process---execution-policy-bypass) + +* [Nishang PowershellTCPOneLine](detections.md#nishang-powershelltcponeline) + +* [Ntdsutil Export NTDS](detections.md#ntdsutil-export-ntds) + +* [Unified Messaging Service Spawning a Process](detections.md#unified-messaging-service-spawning-a-process) + +* [W3WP Spawning Shell](detections.md#w3wp-spawning-shell) + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1059.001 | PowerShell | Execution | +| T1505.003 | Web Shell | Persistence | +| T1136.001 | Local Account | Persistence | +| T1021.002 | SMB/Windows Admin Shares | Lateral Movement | +| T1003.001 | LSASS Memory | Credential Access | +| T1114.002 | Remote Email Collection | Collection | +| T1003.003 | NTDS | Credential Access | +| T1190 | Exploit Public-Facing Application | Initial Access | + +#### Kill Chain Phase + +* Actions on Objectives + +* Command and Control + +* Exploitation + +* Installation + + +#### Reference + +* https://www.splunk.com/en_us/blog/security/detecting-hafnium-exchange-server-zero-day-activity-in-splunk.html + +* https://www.volexity.com/blog/2021/03/02/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities/ + +* https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/ + +* https://blog.rapid7.com/2021/03/03/rapid7s-insightidr-enables-detection-and-response-to-microsoft-exchange-0-day/ + + +_version_: 1 +
+ +--- + +### Ingress Tool Transfer +Adversaries may transfer tools or other files from an external system into a compromised environment. Files may be copied from an external adversary controlled system through the command and control channel to bring tools into the victim network or through alternate protocols with another tool such as FTP. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: Endpoint +- **ATT&CK**: [T1105](https://attack.mitre.org/techniques/T1105/) +- **Last Updated**: 2021-03-24 + +
+ details + +#### Detection Profile + +* [CertUtil Download With URLCache and Split Arguments](detections.md#certutil-download-with-urlcache-and-split-arguments) + +* [CertUtil Download With VerifyCtl and Split Arguments](detections.md#certutil-download-with-verifyctl-and-split-arguments) + +* [Suspicious Curl Network Connection](detections.md#suspicious-curl-network-connection) + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1105 | Ingress Tool Transfer | Command and Control | + +#### Kill Chain Phase + +* Actions on Objectives + +* Exploitation + + +#### Reference + +* https://attack.mitre.org/techniques/T1105/ + + _version_: 1
@@ -872,6 +1107,8 @@ Detect and investigate tactics, techniques, and procedures around how attackers * [Detect Activity Related to Pass the Hash Attacks](detections.md#detect-activity-related-to-pass-the-hash-attacks) +* [Detect Pass the Hash](detections.md#detect-pass-the-hash) + * [Kerberoasting spn request with RC4 encryption](detections.md#kerberoasting-spn-request-with-rc4-encryption) * [Remote Desktop Network Traffic](detections.md#remote-desktop-network-traffic) @@ -910,7 +1147,7 @@ Attackers are finding stealthy ways "live off the land," leveraging utilities an - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: Endpoint -- **ATT&CK**: [T1027](https://attack.mitre.org/techniques/T1027/), [T1059.001](https://attack.mitre.org/techniques/T1059.001/) +- **ATT&CK**: [T1003](https://attack.mitre.org/techniques/T1003/), [T1021](https://attack.mitre.org/techniques/T1021/), [T1027](https://attack.mitre.org/techniques/T1027/), [T1053](https://attack.mitre.org/techniques/T1053/), [T1055](https://attack.mitre.org/techniques/T1055/), [T1059.001](https://attack.mitre.org/techniques/T1059.001/), [T1106](https://attack.mitre.org/techniques/T1106/), [T1113](https://attack.mitre.org/techniques/T1113/), [T1123](https://attack.mitre.org/techniques/T1123/), [T1134](https://attack.mitre.org/techniques/T1134/), [T1548](https://attack.mitre.org/techniques/T1548/), [T1563](https://attack.mitre.org/techniques/T1563/), [T1569](https://attack.mitre.org/techniques/T1569/) - **Last Updated**: 2017-08-23
@@ -918,8 +1155,26 @@ Attackers are finding stealthy ways "live off the land," leveraging utilities an #### Detection Profile +* [Any Powershell DownloadFile](detections.md#any-powershell-downloadfile) + +* [Any Powershell DownloadString](detections.md#any-powershell-downloadstring) + * [Attempt To Set Default PowerShell Execution Policy To Unrestricted or Bypass](detections.md#attempt-to-set-default-powershell-execution-policy-to-unrestricted-or-bypass) +* [Credential Extraction indicative of use of DSInternals credential conversion modules](detections.md#credential-extraction-indicative-of-use-of-dsinternals-credential-conversion-modules) + +* [Credential Extraction indicative of use of DSInternals modules](detections.md#credential-extraction-indicative-of-use-of-dsinternals-modules) + +* [Credential Extraction indicative of use of PowerSploit modules](detections.md#credential-extraction-indicative-of-use-of-powersploit-modules) + +* [Credential Extraction via Get-ADDBAccount module present in PowerSploit and DSInternals](detections.md#credential-extraction-via-get-addbaccount-module-present-in-powersploit-and-dsinternals) + +* [Illegal Access To User Content via PowerSploit modules](detections.md#illegal-access-to-user-content-via-powersploit-modules) + +* [Illegal Privilege Elevation and Persistence via PowerSploit modules](detections.md#illegal-privilege-elevation-and-persistence-via-powersploit-modules) + +* [Illegal Service and Process Control via PowerSploit modules](detections.md#illegal-service-and-process-control-via-powersploit-modules) + * [Malicious PowerShell Process - Connect To Internet With Hidden Window](detections.md#malicious-powershell-process---connect-to-internet-with-hidden-window) * [Malicious PowerShell Process - Encoded Command](detections.md#malicious-powershell-process---encoded-command) @@ -934,6 +1189,17 @@ Attackers are finding stealthy ways "live off the land," leveraging utilities an | ID | Technique | Tactic | | ----------- | ----------- |--------------| | T1059.001 | PowerShell | Execution | +| T1003 | OS Credential Dumping | Credential Access | +| T1021 | Remote Services | Lateral Movement | +| T1113 | Screen Capture | Collection | +| T1123 | Audio Capture | Collection | +| T1563 | Remote Service Session Hijacking | Lateral Movement | +| T1053 | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | +| T1134 | Access Token Manipulation | Defense Evasion, Privilege Escalation | +| T1548 | Abuse Elevation Control Mechanism | Defense Evasion, Privilege Escalation | +| T1055 | Process Injection | Defense Evasion, Privilege Escalation | +| T1106 | Native API | Execution | +| T1569 | System Services | Execution | | T1027 | Obfuscated Files or Information | Defense Evasion | #### Kill Chain Phase @@ -942,6 +1208,8 @@ Attackers are finding stealthy ways "live off the land," leveraging utilities an * Command and Control +* Exploitation + * Installation @@ -957,6 +1225,87 @@ _version_: 4 --- +### NOBELIUM Group +Sunburst is a trojanized updates to SolarWinds Orion IT monitoring and management software. It was discovered by FireEye in December 2020. The actors behind this campaign gained access to numerous public and private organizations around the world. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: Endpoint, Network_Traffic, Web +- **ATT&CK**: [T1018](https://attack.mitre.org/techniques/T1018/), [T1027](https://attack.mitre.org/techniques/T1027/), [T1053.005](https://attack.mitre.org/techniques/T1053.005/), [T1059.003](https://attack.mitre.org/techniques/T1059.003/), [T1071.001](https://attack.mitre.org/techniques/T1071.001/), [T1071.002](https://attack.mitre.org/techniques/T1071.002/), [T1203](https://attack.mitre.org/techniques/T1203/), [T1218.005](https://attack.mitre.org/techniques/T1218.005/), [T1505.003](https://attack.mitre.org/techniques/T1505.003/), [T1543.003](https://attack.mitre.org/techniques/T1543.003/), [T1569.002](https://attack.mitre.org/techniques/T1569.002/) +- **Last Updated**: 2020-12-14 + +
+ details + +#### Detection Profile + +* [Detect Outbound SMB Traffic](detections.md#detect-outbound-smb-traffic) + +* [Detect Prohibited Applications Spawning cmd exe](detections.md#detect-prohibited-applications-spawning-cmd-exe) + +* [Detect Rundll32 Inline HTA Execution](detections.md#detect-rundll32-inline-hta-execution) + +* [First Time Seen Running Windows Service](detections.md#first-time-seen-running-windows-service) + +* [Malicious PowerShell Process - Encoded Command](detections.md#malicious-powershell-process---encoded-command) + +* [Sc exe Manipulating Windows Services](detections.md#sc-exe-manipulating-windows-services) + +* [Scheduled Task Deleted Or Created via CMD](detections.md#scheduled-task-deleted-or-created-via-cmd) + +* [Schtasks scheduling job on remote system](detections.md#schtasks-scheduling-job-on-remote-system) + +* [Sunburst Correlation DLL and Network Event](detections.md#sunburst-correlation-dll-and-network-event) + +* [Supernova Webshell](detections.md#supernova-webshell) + +* [TOR Traffic](detections.md#tor-traffic) + +* [Windows AdFind Exe](detections.md#windows-adfind-exe) + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1071.002 | File Transfer Protocols | Command and Control | +| T1059.003 | Windows Command Shell | Execution | +| T1218.005 | Mshta | Defense Evasion | +| T1569.002 | Service Execution | Execution | +| T1027 | Obfuscated Files or Information | Defense Evasion | +| T1543.003 | Windows Service | Persistence, Privilege Escalation | +| T1053.005 | Scheduled Task | Execution, Persistence, Privilege Escalation | +| T1203 | Exploitation for Client Execution | Execution | +| T1505.003 | Web Shell | Persistence | +| T1071.001 | Web Protocols | Command and Control | +| T1018 | Remote System Discovery | Discovery | + +#### Kill Chain Phase + +* Actions on Objectives + +* Command and Control + +* Exfiltration + +* Exploitation + +* Installation + + +#### Reference + +* https://www.microsoft.com/security/blog/2021/03/04/goldmax-goldfinder-sibot-analyzing-nobelium-malware/ + +* https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html + +* https://msrc-blog.microsoft.com/2020/12/13/customer-guidance-on-recent-nation-state-cyber-attacks/ + + +_version_: 2 +
+ +--- + ### Phishing Payloads Detect signs of malicious payloads that may indicate that your environment has been breached via a phishing attack. @@ -1089,75 +1438,46 @@ _version_: 1 --- -### Sunburst Malware -Sunburst is a trojanized updates to SolarWinds Orion IT monitoring and management software. It was discovered by FireEye in December 2020. The actors behind this campaign gained access to numerous public and private organizations around the world. +### Silver Sparrow +Silver Sparrow, identified by Red Canary Intelligence, is a new forward looking MacOS (Intel and M1) malicious software downloader utilizing JavaScript for execution and a launchAgent to establish persistence. - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -- **Datamodel**: Endpoint, Network_Traffic, Web -- **ATT&CK**: [T1018](https://attack.mitre.org/techniques/T1018/), [T1027](https://attack.mitre.org/techniques/T1027/), [T1053.005](https://attack.mitre.org/techniques/T1053.005/), [T1059.003](https://attack.mitre.org/techniques/T1059.003/), [T1071.001](https://attack.mitre.org/techniques/T1071.001/), [T1071.002](https://attack.mitre.org/techniques/T1071.002/), [T1203](https://attack.mitre.org/techniques/T1203/), [T1505.003](https://attack.mitre.org/techniques/T1505.003/), [T1543.003](https://attack.mitre.org/techniques/T1543.003/), [T1569.002](https://attack.mitre.org/techniques/T1569.002/) -- **Last Updated**: 2020-12-14 +- **Datamodel**: Endpoint +- **ATT&CK**: [T1074](https://attack.mitre.org/techniques/T1074/), [T1105](https://attack.mitre.org/techniques/T1105/), [T1543.001](https://attack.mitre.org/techniques/T1543.001/) +- **Last Updated**: 2021-02-24
details #### Detection Profile -* [Detect Outbound SMB Traffic](detections.md#detect-outbound-smb-traffic) +* [Suspicious Curl Network Connection](detections.md#suspicious-curl-network-connection) -* [Detect Prohibited Applications Spawning cmd exe](detections.md#detect-prohibited-applications-spawning-cmd-exe) +* [Suspicious PlistBuddy Usage](detections.md#suspicious-plistbuddy-usage) -* [First Time Seen Running Windows Service](detections.md#first-time-seen-running-windows-service) +* [Suspicious PlistBuddy Usage via OSquery](detections.md#suspicious-plistbuddy-usage-via-osquery) -* [Malicious PowerShell Process - Encoded Command](detections.md#malicious-powershell-process---encoded-command) - -* [Sc exe Manipulating Windows Services](detections.md#sc-exe-manipulating-windows-services) - -* [Scheduled Task Deleted Or Created via CMD](detections.md#scheduled-task-deleted-or-created-via-cmd) - -* [Schtasks scheduling job on remote system](detections.md#schtasks-scheduling-job-on-remote-system) - -* [Sunburst Correlation DLL and Network Event](detections.md#sunburst-correlation-dll-and-network-event) - -* [Supernova Webshell](detections.md#supernova-webshell) - -* [TOR Traffic](detections.md#tor-traffic) - -* [Windows AdFind Exe](detections.md#windows-adfind-exe) +* [Suspicious SQLite3 LSQuarantine Behavior](detections.md#suspicious-sqlite3-lsquarantine-behavior) #### ATT&CK | ID | Technique | Tactic | | ----------- | ----------- |--------------| -| T1071.002 | File Transfer Protocols | Command and Control | -| T1059.003 | Windows Command Shell | Execution | -| T1569.002 | Service Execution | Execution | -| T1027 | Obfuscated Files or Information | Defense Evasion | -| T1543.003 | Windows Service | Persistence, Privilege Escalation | -| T1053.005 | Scheduled Task | Execution, Persistence, Privilege Escalation | -| T1203 | Exploitation for Client Execution | Execution | -| T1505.003 | Web Shell | Persistence | -| T1071.001 | Web Protocols | Command and Control | -| T1018 | Remote System Discovery | Discovery | +| T1105 | Ingress Tool Transfer | Command and Control | +| T1543.001 | Launch Agent | Persistence, Privilege Escalation | +| T1074 | Data Staged | Collection | #### Kill Chain Phase * Actions on Objectives -* Command and Control - -* Exfiltration - -* Exploitation - -* Installation - #### Reference -* https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html +* https://redcanary.com/blog/clipping-silver-sparrows-wings/ -* https://msrc-blog.microsoft.com/2020/12/13/customer-guidance-on-recent-nation-state-cyber-attacks/ +* https://www.sentinelone.com/blog/5-things-you-need-to-know-about-silver-sparrow/ _version_: 1 @@ -1170,7 +1490,7 @@ Leveraging the Windows command-line interface (CLI) is one of the most common at - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: Endpoint -- **ATT&CK**: [T1036.003](https://attack.mitre.org/techniques/T1036.003/), [T1059.001](https://attack.mitre.org/techniques/T1059.001/), [T1059.003](https://attack.mitre.org/techniques/T1059.003/) +- **ATT&CK**: [T1036.003](https://attack.mitre.org/techniques/T1036.003/), [T1059](https://attack.mitre.org/techniques/T1059/), [T1059.001](https://attack.mitre.org/techniques/T1059.001/), [T1059.003](https://attack.mitre.org/techniques/T1059.003/) - **Last Updated**: 2020-02-03
@@ -1196,6 +1516,7 @@ Leveraging the Windows command-line interface (CLI) is one of the most common at | ID | Technique | Tactic | | ----------- | ----------- |--------------| | T1059.003 | Windows Command Shell | Execution | +| T1059 | Command and Scripting Interpreter | Execution | | T1068 | Exploitation for Privilege Escalation | Privilege Escalation | | T1059.001 | PowerShell | Execution | | T1036.003 | Rename System Utilities | Defense Evasion | @@ -1381,7 +1702,7 @@ Monitor and detect techniques used by attackers who leverage the mshta.exe proce - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: Endpoint -- **ATT&CK**: [T1059.003](https://attack.mitre.org/techniques/T1059.003/), [T1218.005](https://attack.mitre.org/techniques/T1218.005/), [T1547.001](https://attack.mitre.org/techniques/T1547.001/) +- **ATT&CK**: [T1059](https://attack.mitre.org/techniques/T1059/), [T1059.003](https://attack.mitre.org/techniques/T1059.003/), [T1218.005](https://attack.mitre.org/techniques/T1218.005/), [T1547.001](https://attack.mitre.org/techniques/T1547.001/) - **Last Updated**: 2021-01-20
@@ -1412,6 +1733,7 @@ Monitor and detect techniques used by attackers who leverage the mshta.exe proce | ----------- | ----------- |--------------| | T1218.005 | Mshta | Defense Evasion | | T1059.003 | Windows Command Shell | Execution | +| T1059 | Command and Scripting Interpreter | Execution | | T1547.001 | Registry Run Keys / Startup Folder | Persistence, Privilege Escalation | #### Kill Chain Phase @@ -1603,7 +1925,7 @@ Monitor and detect techniques used by attackers who leverage rundll32.exe to exe * [Suspicious Rundll32 dllregisterserver](detections.md#suspicious-rundll32-dllregisterserver) -* [Suspicious Rundll32 no CommandLine Arguments](detections.md#suspicious-rundll32-no-commandline-arguments) +* [Suspicious Rundll32 no Command Line Arguments](detections.md#suspicious-rundll32-no-command-line-arguments) #### ATT&CK @@ -1720,6 +2042,7 @@ Monitor and detect registry changes initiated from remote locations, which can b | ID | Technique | Tactic | | ----------- | ----------- |--------------| | T1548.002 | Bypass User Account Control | Defense Evasion, Privilege Escalation | +| T1112 | Modify Registry | Defense Evasion | | T1222.001 | Windows File and Directory Permissions Modification | Defense Evasion | | T1547.010 | Port Monitors | Persistence, Privilege Escalation | | T1564.001 | Hidden Files and Directories | Defense Evasion | @@ -1727,7 +2050,8 @@ Monitor and detect registry changes initiated from remote locations, which can b | T1546.012 | Image File Execution Options Injection | Persistence, Privilege Escalation | | T1546.011 | Application Shimming | Persistence, Privilege Escalation | | T1546.001 | Change Default File Association | Persistence, Privilege Escalation | -| T1112 | Modify Registry | Defense Evasion | +| T1036 | Masquerading | Defense Evasion | +| T1562.001 | Disable or Modify Tools | Defense Evasion | #### Kill Chain Phase @@ -1751,7 +2075,7 @@ Attackers are using Zoom as an vector to increase privileges on a sytems. This s - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: Endpoint -- **ATT&CK**: [T1059.003](https://attack.mitre.org/techniques/T1059.003/), [T1068](https://attack.mitre.org/techniques/T1068/) +- **ATT&CK**: [T1059](https://attack.mitre.org/techniques/T1059/), [T1059.003](https://attack.mitre.org/techniques/T1059.003/), [T1068](https://attack.mitre.org/techniques/T1068/) - **Last Updated**: 2020-04-13
@@ -1769,6 +2093,7 @@ Attackers are using Zoom as an vector to increase privileges on a sytems. This s | ID | Technique | Tactic | | ----------- | ----------- |--------------| | T1059.003 | Windows Command Shell | Execution | +| T1059 | Command and Scripting Interpreter | Execution | | T1068 | Exploitation for Privilege Escalation | Privilege Escalation | | T1059.001 | PowerShell | Execution | | T1036.003 | Rename System Utilities | Defense Evasion | @@ -1934,7 +2259,7 @@ Detect tactics used by malware to evade defenses on Windows endpoints. A few of - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: Endpoint -- **ATT&CK**: [T1112](https://attack.mitre.org/techniques/T1112/), [T1222.001](https://attack.mitre.org/techniques/T1222.001/), [T1548.002](https://attack.mitre.org/techniques/T1548.002/), [T1564.001](https://attack.mitre.org/techniques/T1564.001/) +- **ATT&CK**: [T1036](https://attack.mitre.org/techniques/T1036/), [T1112](https://attack.mitre.org/techniques/T1112/), [T1222.001](https://attack.mitre.org/techniques/T1222.001/), [T1548.002](https://attack.mitre.org/techniques/T1548.002/), [T1562.001](https://attack.mitre.org/techniques/T1562.001/), [T1564.001](https://attack.mitre.org/techniques/T1564.001/) - **Last Updated**: 2018-05-31
@@ -1944,6 +2269,10 @@ Detect tactics used by malware to evade defenses on Windows endpoints. A few of * [Disabling Remote User Account Control](detections.md#disabling-remote-user-account-control) +* [Eventvwr UAC Bypass](detections.md#eventvwr-uac-bypass) + +* [FodHelper UAC Bypass](detections.md#fodhelper-uac-bypass) + * [Hiding Files And Directories With Attrib exe](detections.md#hiding-files-and-directories-with-attrib-exe) * [Reg exe used to hide files directories via registry keys](detections.md#reg-exe-used-to-hide-files-directories-via-registry-keys) @@ -1952,12 +2281,17 @@ Detect tactics used by malware to evade defenses on Windows endpoints. A few of * [Suspicious Reg exe Process](detections.md#suspicious-reg-exe-process) +* [System Process Running from Unexpected Location](detections.md#system-process-running-from-unexpected-location) + +* [Windows DisableAntiSpyware Registry](detections.md#windows-disableantispyware-registry) + #### ATT&CK | ID | Technique | Tactic | | ----------- | ----------- |--------------| | T1548.002 | Bypass User Account Control | Defense Evasion, Privilege Escalation | +| T1112 | Modify Registry | Defense Evasion | | T1222.001 | Windows File and Directory Permissions Modification | Defense Evasion | | T1547.010 | Port Monitors | Persistence, Privilege Escalation | | T1564.001 | Hidden Files and Directories | Defense Evasion | @@ -1965,7 +2299,109 @@ Detect tactics used by malware to evade defenses on Windows endpoints. A few of | T1546.012 | Image File Execution Options Injection | Persistence, Privilege Escalation | | T1546.011 | Application Shimming | Persistence, Privilege Escalation | | T1546.001 | Change Default File Association | Persistence, Privilege Escalation | -| T1112 | Modify Registry | Defense Evasion | +| T1036 | Masquerading | Defense Evasion | +| T1562.001 | Disable or Modify Tools | Defense Evasion | + +#### Kill Chain Phase + +* Actions on Objectives + +* Delivery + +* Exploitation + +* Privilege Escalation + + +#### Reference + +* https://attack.mitre.org/wiki/Defense_Evasion + + +_version_: 1 +
+ +--- + +### Windows Discovery Techniques +Monitors for behaviors associated with adversaries discovering objects in the environment that can be leveraged in the progression of the attack. + +- **Product**: UEBA for Security Cloud +- **Datamodel**: +- **ATT&CK**: [T1007](https://attack.mitre.org/techniques/T1007/), [T1012](https://attack.mitre.org/techniques/T1012/), [T1021.002](https://attack.mitre.org/techniques/T1021.002/), [T1039](https://attack.mitre.org/techniques/T1039/), [T1046](https://attack.mitre.org/techniques/T1046/), [T1047](https://attack.mitre.org/techniques/T1047/), [T1053](https://attack.mitre.org/techniques/T1053/), [T1055](https://attack.mitre.org/techniques/T1055/), [T1057](https://attack.mitre.org/techniques/T1057/), [T1068](https://attack.mitre.org/techniques/T1068/), [T1078](https://attack.mitre.org/techniques/T1078/), [T1083](https://attack.mitre.org/techniques/T1083/), [T1087](https://attack.mitre.org/techniques/T1087/), [T1098](https://attack.mitre.org/techniques/T1098/), [T1135](https://attack.mitre.org/techniques/T1135/), [T1199](https://attack.mitre.org/techniques/T1199/), [T1482](https://attack.mitre.org/techniques/T1482/), [T1484](https://attack.mitre.org/techniques/T1484/), [T1518](https://attack.mitre.org/techniques/T1518/), [T1543](https://attack.mitre.org/techniques/T1543/), [T1547](https://attack.mitre.org/techniques/T1547/), [T1574](https://attack.mitre.org/techniques/T1574/), [T1589.001](https://attack.mitre.org/techniques/T1589.001/), [T1590](https://attack.mitre.org/techniques/T1590/), [T1590.001](https://attack.mitre.org/techniques/T1590.001/), [T1590.003](https://attack.mitre.org/techniques/T1590.003/), [T1591](https://attack.mitre.org/techniques/T1591/), [T1592](https://attack.mitre.org/techniques/T1592/), [T1592.002](https://attack.mitre.org/techniques/T1592.002/), [T1595](https://attack.mitre.org/techniques/T1595/), [T1595.002](https://attack.mitre.org/techniques/T1595.002/) +- **Last Updated**: 2021-03-04 + +
+ details + +#### Detection Profile + +* [Reconnaissance and Access to Accounts Groups and Policies via PowerSploit modules](detections.md#reconnaissance-and-access-to-accounts-groups-and-policies-via-powersploit-modules) + +* [Reconnaissance and Access to Accounts and Groups via Mimikatz modules](detections.md#reconnaissance-and-access-to-accounts-and-groups-via-mimikatz-modules) + +* [Reconnaissance and Access to Active Directoty Infrastructure via PowerSploit modules](detections.md#reconnaissance-and-access-to-active-directoty-infrastructure-via-powersploit-modules) + +* [Reconnaissance and Access to Computers and Domains via PowerSploit modules](detections.md#reconnaissance-and-access-to-computers-and-domains-via-powersploit-modules) + +* [Reconnaissance and Access to Computers via Mimikatz modules](detections.md#reconnaissance-and-access-to-computers-via-mimikatz-modules) + +* [Reconnaissance and Access to Operating System Elements via PowerSploit modules](detections.md#reconnaissance-and-access-to-operating-system-elements-via-powersploit-modules) + +* [Reconnaissance and Access to Processes and Services via Mimikatz modules](detections.md#reconnaissance-and-access-to-processes-and-services-via-mimikatz-modules) + +* [Reconnaissance and Access to Shared Resources via Mimikatz modules](detections.md#reconnaissance-and-access-to-shared-resources-via-mimikatz-modules) + +* [Reconnaissance and Access to Shared Resources via PowerSploit modules](detections.md#reconnaissance-and-access-to-shared-resources-via-powersploit-modules) + +* [Reconnaissance of Access and Persistence Opportunities via PowerSploit modules](detections.md#reconnaissance-of-access-and-persistence-opportunities-via-powersploit-modules) + +* [Reconnaissance of Connectivity via PowerSploit modules](detections.md#reconnaissance-of-connectivity-via-powersploit-modules) + +* [Reconnaissance of Credential Stores and Services via Mimikatz modules](detections.md#reconnaissance-of-credential-stores-and-services-via-mimikatz-modules) + +* [Reconnaissance of Defensive Tools via PowerSploit modules](detections.md#reconnaissance-of-defensive-tools-via-powersploit-modules) + +* [Reconnaissance of Privilege Escalation Opportunities via PowerSploit modules](detections.md#reconnaissance-of-privilege-escalation-opportunities-via-powersploit-modules) + +* [Reconnaissance of Process or Service Hijacking Opportunities via Mimikatz modules](detections.md#reconnaissance-of-process-or-service-hijacking-opportunities-via-mimikatz-modules) + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1078 | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | +| T1087 | Account Discovery | Discovery | +| T1484 | Domain Policy Modification | Defense Evasion, Privilege Escalation | +| T1199 | Trusted Relationship | Initial Access | +| T1482 | Domain Trust Discovery | Discovery | +| T1590 | Gather Victim Network Information | Reconnaissance | +| T1591 | Gather Victim Org Information | Reconnaissance | +| T1595 | Active Scanning | Reconnaissance | +| T1592 | Gather Victim Host Information | Reconnaissance | +| T1007 | System Service Discovery | Discovery | +| T1012 | Query Registry | Discovery | +| T1046 | Network Service Scanning | Discovery | +| T1047 | Windows Management Instrumentation | Execution | +| T1057 | Process Discovery | Discovery | +| T1083 | File and Directory Discovery | Discovery | +| T1518 | Software Discovery | Discovery | +| T1592.002 | Software | Reconnaissance | +| T1021.002 | SMB/Windows Admin Shares | Lateral Movement | +| T1135 | Network Share Discovery | Discovery | +| T1039 | Data from Network Shared Drive | Collection | +| T1053 | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | +| T1068 | Exploitation for Privilege Escalation | Privilege Escalation | +| T1543 | Create or Modify System Process | Persistence, Privilege Escalation | +| T1547 | Boot or Logon Autostart Execution | Persistence, Privilege Escalation | +| T1574 | Hijack Execution Flow | Defense Evasion, Persistence, Privilege Escalation | +| T1589.001 | Credentials | Reconnaissance | +| T1590.001 | Domain Properties | Reconnaissance | +| T1590.003 | Network Trust Dependencies | Reconnaissance | +| T1098 | Account Manipulation | Persistence | +| T1595.002 | Vulnerability Scanning | Reconnaissance | +| T1055 | Process Injection | Defense Evasion, Privilege Escalation | #### Kill Chain Phase @@ -1974,7 +2410,9 @@ Detect tactics used by malware to evade defenses on Windows endpoints. A few of #### Reference -* https://attack.mitre.org/wiki/Defense_Evasion +* https://attack.mitre.org/tactics/TA0007/ + +* https://cyberd.us/penetration-testing _version_: 1 @@ -1997,6 +2435,8 @@ Adversaries often try to cover their tracks by manipulating Windows logs. Use th * [Deleting Shadow Copies](detections.md#deleting-shadow-copies) +* [Illegal Deletion of Logs via Mimikatz modules](detections.md#illegal-deletion-of-logs-via-mimikatz-modules) + * [Suspicious wevtutil Usage](detections.md#suspicious-wevtutil-usage) * [USN Journal Deletion](detections.md#usn-journal-deletion) @@ -2009,8 +2449,8 @@ Adversaries often try to cover their tracks by manipulating Windows logs. Use th | ID | Technique | Tactic | | ----------- | ----------- |--------------| | T1490 | Inhibit System Recovery | Impact | -| T1070.001 | Clear Windows Event Logs | Defense Evasion | | T1070 | Indicator Removal on Host | Defense Evasion | +| T1070.001 | Clear Windows Event Logs | Defense Evasion | #### Kill Chain Phase @@ -2036,7 +2476,7 @@ Monitor for activities and techniques associated with maintaining persistence on - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: Endpoint -- **ATT&CK**: [T1053.005](https://attack.mitre.org/techniques/T1053.005/), [T1222.001](https://attack.mitre.org/techniques/T1222.001/), [T1543.003](https://attack.mitre.org/techniques/T1543.003/), [T1546.011](https://attack.mitre.org/techniques/T1546.011/), [T1547.001](https://attack.mitre.org/techniques/T1547.001/), [T1547.010](https://attack.mitre.org/techniques/T1547.010/), [T1564.001](https://attack.mitre.org/techniques/T1564.001/), [T1574.009](https://attack.mitre.org/techniques/T1574.009/), [T1574.011](https://attack.mitre.org/techniques/T1574.011/) +- **ATT&CK**: [T1053](https://attack.mitre.org/techniques/T1053/), [T1053.005](https://attack.mitre.org/techniques/T1053.005/), [T1068](https://attack.mitre.org/techniques/T1068/), [T1078](https://attack.mitre.org/techniques/T1078/), [T1098](https://attack.mitre.org/techniques/T1098/), [T1134](https://attack.mitre.org/techniques/T1134/), [T1207](https://attack.mitre.org/techniques/T1207/), [T1222.001](https://attack.mitre.org/techniques/T1222.001/), [T1484](https://attack.mitre.org/techniques/T1484/), [T1543.003](https://attack.mitre.org/techniques/T1543.003/), [T1546.011](https://attack.mitre.org/techniques/T1546.011/), [T1547.001](https://attack.mitre.org/techniques/T1547.001/), [T1547.010](https://attack.mitre.org/techniques/T1547.010/), [T1548](https://attack.mitre.org/techniques/T1548/), [T1564.001](https://attack.mitre.org/techniques/T1564.001/), [T1574.009](https://attack.mitre.org/techniques/T1574.009/), [T1574.011](https://attack.mitre.org/techniques/T1574.011/), [T1585](https://attack.mitre.org/techniques/T1585/) - **Last Updated**: 2018-05-31
@@ -2050,6 +2490,16 @@ Monitor for activities and techniques associated with maintaining persistence on * [Hiding Files And Directories With Attrib exe](detections.md#hiding-files-and-directories-with-attrib-exe) +* [Illegal Account Creation via PowerSploit modules](detections.md#illegal-account-creation-via-powersploit-modules) + +* [Illegal Enabling or Disabling of Accounts via DSInternals modules](detections.md#illegal-enabling-or-disabling-of-accounts-via-dsinternals-modules) + +* [Illegal Management of Active Directory Elements and Policies via DSInternals modules](detections.md#illegal-management-of-active-directory-elements-and-policies-via-dsinternals-modules) + +* [Illegal Management of Computers and Active Directory Elements via PowerSploit modules](detections.md#illegal-management-of-computers-and-active-directory-elements-via-powersploit-modules) + +* [Illegal Privilege Elevation and Persistence via PowerSploit modules](detections.md#illegal-privilege-elevation-and-persistence-via-powersploit-modules) + * [Monitor Registry Keys for Print Monitors](detections.md#monitor-registry-keys-for-print-monitors) * [Reg exe Manipulating Windows Services Registry Keys](detections.md#reg-exe-manipulating-windows-services-registry-keys) @@ -2066,10 +2516,18 @@ Monitor for activities and techniques associated with maintaining persistence on * [Schtasks used for forcing a reboot](detections.md#schtasks-used-for-forcing-a-reboot) +* [Setting Credentials via DSInternals modules](detections.md#setting-credentials-via-dsinternals-modules) + +* [Setting Credentials via Mimikatz modules](detections.md#setting-credentials-via-mimikatz-modules) + +* [Setting Credentials via PowerSploit modules](detections.md#setting-credentials-via-powersploit-modules) + * [Shim Database File Creation](detections.md#shim-database-file-creation) * [Shim Database Installation With Suspicious Parameters](detections.md#shim-database-installation-with-suspicious-parameters) +* [Suspicious Scheduled Task from Public Directory](detections.md#suspicious-scheduled-task-from-public-directory) + #### ATT&CK @@ -2077,6 +2535,14 @@ Monitor for activities and techniques associated with maintaining persistence on | ----------- | ----------- |--------------| | T1574.009 | Path Interception by Unquoted Path | Defense Evasion, Persistence, Privilege Escalation | | T1222.001 | Windows File and Directory Permissions Modification | Defense Evasion | +| T1585 | Establish Accounts | Resource Development | +| T1078 | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | +| T1098 | Account Manipulation | Persistence | +| T1207 | Rogue Domain Controller | Defense Evasion | +| T1484 | Domain Policy Modification | Defense Evasion, Privilege Escalation | +| T1053 | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | +| T1134 | Access Token Manipulation | Defense Evasion, Privilege Escalation | +| T1548 | Abuse Elevation Control Mechanism | Defense Evasion, Privilege Escalation | | T1547.010 | Port Monitors | Persistence, Privilege Escalation | | T1574.011 | Services Registry Permissions Weakness | Defense Evasion, Persistence, Privilege Escalation | | T1564.001 | Hidden Files and Directories | Defense Evasion | @@ -2084,13 +2550,18 @@ Monitor for activities and techniques associated with maintaining persistence on | T1546.011 | Application Shimming | Persistence, Privilege Escalation | | T1543.003 | Windows Service | Persistence, Privilege Escalation | | T1053.005 | Scheduled Task | Execution, Persistence, Privilege Escalation | +| T1068 | Exploitation for Privilege Escalation | Privilege Escalation | #### Kill Chain Phase * Actions on Objectives +* Exploitation + * Installation +* Privilege Escalation + #### Reference @@ -2115,7 +2586,7 @@ Monitor for and investigate activities that may be associated with a Windows pri - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: Endpoint -- **ATT&CK**: [T1068](https://attack.mitre.org/techniques/T1068/), [T1204.002](https://attack.mitre.org/techniques/T1204.002/), [T1546.008](https://attack.mitre.org/techniques/T1546.008/), [T1546.012](https://attack.mitre.org/techniques/T1546.012/) +- **ATT&CK**: [T1068](https://attack.mitre.org/techniques/T1068/), [T1078](https://attack.mitre.org/techniques/T1078/), [T1098](https://attack.mitre.org/techniques/T1098/), [T1134](https://attack.mitre.org/techniques/T1134/), [T1204.002](https://attack.mitre.org/techniques/T1204.002/), [T1546.008](https://attack.mitre.org/techniques/T1546.008/), [T1546.012](https://attack.mitre.org/techniques/T1546.012/), [T1548](https://attack.mitre.org/techniques/T1548/) - **Last Updated**: 2020-02-04
@@ -2125,8 +2596,12 @@ Monitor for and investigate activities that may be associated with a Windows pri * [Child Processes of Spoolsv exe](detections.md#child-processes-of-spoolsv-exe) +* [Illegal Privilege Elevation via Mimikatz modules](detections.md#illegal-privilege-elevation-via-mimikatz-modules) + * [Overwriting Accessibility Binaries](detections.md#overwriting-accessibility-binaries) +* [Probing Access with Stolen Credentials via PowerSploit modules](detections.md#probing-access-with-stolen-credentials-via-powersploit-modules) + * [Registry Keys Used For Privilege Escalation](detections.md#registry-keys-used-for-privilege-escalation) * [Uncommon Processes On Endpoint](detections.md#uncommon-processes-on-endpoint) @@ -2137,7 +2612,11 @@ Monitor for and investigate activities that may be associated with a Windows pri | ID | Technique | Tactic | | ----------- | ----------- |--------------| | T1068 | Exploitation for Privilege Escalation | Privilege Escalation | +| T1134 | Access Token Manipulation | Defense Evasion, Privilege Escalation | +| T1548 | Abuse Elevation Control Mechanism | Defense Evasion, Privilege Escalation | | T1546.008 | Accessibility Features | Persistence, Privilege Escalation | +| T1078 | Valid Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | +| T1098 | Account Manipulation | Persistence | | T1546.012 | Image File Execution Options Injection | Persistence, Privilege Escalation | | T1204.002 | Malicious File | Execution | @@ -2559,6 +3038,56 @@ Monitor your AWS EC2 instances for activities related to cryptojacking/cryptomin * https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf +_version_: 1 +
+ +--- + +### AWS IAM Privilege Escalation +This analytic story contains detections that query your AWS Cloudtrail for activities related to privilege escalation. + +- **Product**: Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: +- **ATT&CK**: [T1078.004](https://attack.mitre.org/techniques/T1078.004/), [T1136.003](https://attack.mitre.org/techniques/T1136.003/) +- **Last Updated**: 2021-03-08 + +
+ details + +#### Detection Profile + +* [AWS Create Policy Version to allow all resources](detections.md#aws-create-policy-version-to-allow-all-resources) + +* [AWS CreateAccessKey](detections.md#aws-createaccesskey) + +* [AWS CreateLoginProfile](detections.md#aws-createloginprofile) + +* [AWS SetDefaultPolicyVersion](detections.md#aws-setdefaultpolicyversion) + +* [AWS UpdateLoginProfile](detections.md#aws-updateloginprofile) + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1078.004 | Cloud Accounts | Defense Evasion, Initial Access, Persistence, Privilege Escalation | +| T1136.003 | Cloud Account | Persistence | + +#### Kill Chain Phase + +* Actions on Objectives + + +#### Reference + +* https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation/ + +* https://www.cyberark.com/resources/threat-research-blog/the-cloud-shadow-admin-threat-10-permissions-to-protect + +* https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws + + _version_: 1
@@ -2786,7 +3315,7 @@ This analytical story addresses events that indicate abuse of cloud federated cr - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: Endpoint -- **ATT&CK**: [T1003.001](https://attack.mitre.org/techniques/T1003.001/), [T1078](https://attack.mitre.org/techniques/T1078/), [T1136.003](https://attack.mitre.org/techniques/T1136.003/), [T1204.002](https://attack.mitre.org/techniques/T1204.002/), [T1546.012](https://attack.mitre.org/techniques/T1546.012/), [T1556](https://attack.mitre.org/techniques/T1556/) +- **ATT&CK**: [T1003.001](https://attack.mitre.org/techniques/T1003.001/), [T1078](https://attack.mitre.org/techniques/T1078/), [T1136.003](https://attack.mitre.org/techniques/T1136.003/), [T1546.012](https://attack.mitre.org/techniques/T1546.012/), [T1556](https://attack.mitre.org/techniques/T1556/) - **Last Updated**: 2021-01-26
@@ -2816,8 +3345,6 @@ This analytical story addresses events that indicate abuse of cloud federated cr * [Registry Keys Used For Privilege Escalation](detections.md#registry-keys-used-for-privilege-escalation) -* [Uncommon Processes On Endpoint](detections.md#uncommon-processes-on-endpoint) - #### ATT&CK @@ -2828,7 +3355,6 @@ This analytical story addresses events that indicate abuse of cloud federated cr | T1136.003 | Cloud Account | Persistence | | T1556 | Modify Authentication Process | Credential Access, Defense Evasion | | T1546.012 | Image File Execution Options Injection | Persistence, Privilege Escalation | -| T1204.002 | Malicious File | Execution | #### Kill Chain Phase @@ -3587,6 +4113,84 @@ _version_: 1
details +### Clop Ransomware +Leverage searches that allow you to detect and investigate unusual activities that might relate to the Clop ransomware, including looking for file writes associated with Clope, encrypting network shares, deleting and resizing shadow volume storage, registry key modification, deleting of security logs, and more. + +- **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +- **Datamodel**: Endpoint +- **ATT&CK**: [T1003.002](https://attack.mitre.org/techniques/T1003.002/), [T1070.001](https://attack.mitre.org/techniques/T1070.001/), [T1204](https://attack.mitre.org/techniques/T1204/), [T1485](https://attack.mitre.org/techniques/T1485/), [T1486](https://attack.mitre.org/techniques/T1486/), [T1490](https://attack.mitre.org/techniques/T1490/), [T1543](https://attack.mitre.org/techniques/T1543/), [T1569.001, T1569.002](https://attack.mitre.org/techniques/T1569.001, T1569.002/) +- **Last Updated**: 2021-03-17 + +
+ details + +#### Detection Profile + +* [Clop Common Exec Parameter](detections.md#clop-common-exec-parameter) + +* [Clop Ransomware Known Service Name](detections.md#clop-ransomware-known-service-name) + +* [Common Ransomware Extensions](detections.md#common-ransomware-extensions) + +* [Common Ransomware Notes](detections.md#common-ransomware-notes) + +* [Create Service In Suspicious File Path](detections.md#create-service-in-suspicious-file-path) + +* [Deleting Shadow Copies](detections.md#deleting-shadow-copies) + +* [High File Deletion Frequency](detections.md#high-file-deletion-frequency) + +* [High Process Termination Frequency](detections.md#high-process-termination-frequency) + +* [Process Deleting Its Process File Path](detections.md#process-deleting-its-process-file-path) + +* [Ransomware Notes bulk creation](detections.md#ransomware-notes-bulk-creation) + +* [Resize ShadowStorage volume](detections.md#resize-shadowstorage-volume) + +* [Suspicious wevtutil Usage](detections.md#suspicious-wevtutil-usage) + +* [Windows Event Log Cleared](detections.md#windows-event-log-cleared) + + +#### ATT&CK + +| ID | Technique | Tactic | +| ----------- | ----------- |--------------| +| T1204 | User Execution | Execution | +| T1543 | Create or Modify System Process | Persistence, Privilege Escalation | +| T1485 | Data Destruction | Impact | +| | | | +| T1490 | Inhibit System Recovery | Impact | +| T1486 | Data Encrypted for Impact | Impact | +| T1003.002 | Security Account Manager | Credential Access | +| T1070.001 | Clear Windows Event Logs | Defense Evasion | + +#### Kill Chain Phase + +* Actions on Objectives + +* Exploitation + +* Obfuscation + +* Privilege Escalation + + +#### Reference + +* https://www.hhs.gov/sites/default/files/analyst-note-cl0p-tlp-white.pdf + +* https://securityaffairs.co/wordpress/115250/data-breach/qualys-clop-ransomware.html + +* https://www.darkreading.com/attacks-breaches/qualys-is-the-latest-victim-of-accellion-data-breach/d/d-id/1340323 + + +_version_: 1 +
+ +--- + ### ColdRoot MacOS RAT Leverage searches that allow you to detect and investigate unusual activities that relate to the ColdRoot Remote Access Trojan that affects MacOS. An example of some of these activities are changing sensative binaries in the MacOS sub-system, detecting process names and executables associated with the RAT, detecting when a keyboard tab is installed on a MacOS machine and more. @@ -3920,6 +4524,9 @@ Detect activities and various techniques associated with the Orangeworm Attack G | T1569.002 | Service Execution | Execution | | T1059.001 | PowerShell | Execution | | T1059.003 | Windows Command Shell | Execution | +| T1055 | Process Injection | Defense Evasion, Privilege Escalation | +| T1106 | Native API | Execution | +| T1569 | System Services | Execution | | T1574.011 | Services Registry Permissions Weakness | Defense Evasion, Persistence, Privilege Escalation | | T1543.003 | Windows Service | Persistence, Privilege Escalation | @@ -3981,6 +4588,8 @@ Leverage searches that allow you to detect and investigate unusual activities th * [Spike in File Writes](detections.md#spike-in-file-writes) +* [Suspicious Scheduled Task from Public Directory](detections.md#suspicious-scheduled-task-from-public-directory) + * [Suspicious wevtutil Usage](detections.md#suspicious-wevtutil-usage) * [System Processes Run From Unexpected Locations](detections.md#system-processes-run-from-unexpected-locations) @@ -4010,6 +4619,7 @@ Leverage searches that allow you to detect and investigate unusual activities th | T1021.001 | Remote Desktop Protocol | Lateral Movement | | T1047 | Windows Management Instrumentation | Execution | | T1486 | Data Encrypted for Impact | Impact | +| T1059.003 | Windows Command Shell | Execution | | T1021.002 | SMB/Windows Admin Shares | Lateral Movement | | T1053.005 | Scheduled Task | Execution, Persistence, Privilege Escalation | | T1070.001 | Clear Windows Event Logs | Defense Evasion | @@ -4018,7 +4628,6 @@ Leverage searches that allow you to detect and investigate unusual activities th | T1070 | Indicator Removal on Host | Defense Evasion | | T1562.001 | Disable or Modify Tools | Defense Evasion | | T1489 | Service Stop | Impact | -| T1059.003 | Windows Command Shell | Execution | #### Kill Chain Phase @@ -4028,6 +4637,10 @@ Leverage searches that allow you to detect and investigate unusual activities th * Delivery +* Exploitation + +* Privilege Escalation + #### Reference @@ -4087,7 +4700,7 @@ Leverage searches that allow you to detect and investigate unusual activities th - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: Endpoint, Network_Traffic -- **ATT&CK**: [T1021.001](https://attack.mitre.org/techniques/T1021.001/), [T1059.003](https://attack.mitre.org/techniques/T1059.003/), [T1482](https://attack.mitre.org/techniques/T1482/), [T1485](https://attack.mitre.org/techniques/T1485/), [T1486](https://attack.mitre.org/techniques/T1486/), [T1489](https://attack.mitre.org/techniques/T1489/), [T1490](https://attack.mitre.org/techniques/T1490/), [T1562.001](https://attack.mitre.org/techniques/T1562.001/) +- **ATT&CK**: [T1021.001](https://attack.mitre.org/techniques/T1021.001/), [T1053.005](https://attack.mitre.org/techniques/T1053.005/), [T1059.003](https://attack.mitre.org/techniques/T1059.003/), [T1482](https://attack.mitre.org/techniques/T1482/), [T1485](https://attack.mitre.org/techniques/T1485/), [T1486](https://attack.mitre.org/techniques/T1486/), [T1489](https://attack.mitre.org/techniques/T1489/), [T1490](https://attack.mitre.org/techniques/T1490/), [T1562.001](https://attack.mitre.org/techniques/T1562.001/) - **Last Updated**: 2020-11-06
@@ -4097,6 +4710,8 @@ Leverage searches that allow you to detect and investigate unusual activities th * [BCDEdit Failure Recovery Modification](detections.md#bcdedit-failure-recovery-modification) +* [Common Ransomware Extensions](detections.md#common-ransomware-extensions) + * [Common Ransomware Notes](detections.md#common-ransomware-notes) * [NLTest Domain Trust Discovery](detections.md#nltest-domain-trust-discovery) @@ -4107,8 +4722,12 @@ Leverage searches that allow you to detect and investigate unusual activities th * [Ryuk Test Files Detected](detections.md#ryuk-test-files-detected) +* [Ryuk Wake on LAN Command](detections.md#ryuk-wake-on-lan-command) + * [Spike in File Writes](detections.md#spike-in-file-writes) +* [Suspicious Scheduled Task from Public Directory](detections.md#suspicious-scheduled-task-from-public-directory) + * [WBAdmin Delete System Backups](detections.md#wbadmin-delete-system-backups) * [Windows DisableAntiSpyware Registry](detections.md#windows-disableantispyware-registry) @@ -4130,6 +4749,7 @@ Leverage searches that allow you to detect and investigate unusual activities th | T1021.001 | Remote Desktop Protocol | Lateral Movement | | T1047 | Windows Management Instrumentation | Execution | | T1486 | Data Encrypted for Impact | Impact | +| T1059.003 | Windows Command Shell | Execution | | T1021.002 | SMB/Windows Admin Shares | Lateral Movement | | T1053.005 | Scheduled Task | Execution, Persistence, Privilege Escalation | | T1070.001 | Clear Windows Event Logs | Defense Evasion | @@ -4138,7 +4758,6 @@ Leverage searches that allow you to detect and investigate unusual activities th | T1070 | Indicator Removal on Host | Defense Evasion | | T1562.001 | Disable or Modify Tools | Defense Evasion | | T1489 | Service Stop | Impact | -| T1059.003 | Windows Command Shell | Execution | #### Kill Chain Phase @@ -4148,6 +4767,10 @@ Leverage searches that allow you to detect and investigate unusual activities th * Exploitation +* Lateral Movement + +* Privilege Escalation + * Reconnaissance @@ -4249,7 +4872,7 @@ Quickly identify systems running new or unusual processes in your environment th - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: Endpoint -- **ATT&CK**: [T1016](https://attack.mitre.org/techniques/T1016/), [T1036.003](https://attack.mitre.org/techniques/T1036.003/), [T1204.002](https://attack.mitre.org/techniques/T1204.002/), [T1218.011](https://attack.mitre.org/techniques/T1218.011/) +- **ATT&CK**: [T1003](https://attack.mitre.org/techniques/T1003/), [T1016](https://attack.mitre.org/techniques/T1016/), [T1036.003](https://attack.mitre.org/techniques/T1036.003/), [T1053](https://attack.mitre.org/techniques/T1053/), [T1059](https://attack.mitre.org/techniques/T1059/), [T1072](https://attack.mitre.org/techniques/T1072/), [T1117](https://attack.mitre.org/techniques/T1117/), [T1202](https://attack.mitre.org/techniques/T1202/), [T1203](https://attack.mitre.org/techniques/T1203/), [T1204.002](https://attack.mitre.org/techniques/T1204.002/), [T1218.011](https://attack.mitre.org/techniques/T1218.011/) - **Last Updated**: 2020-02-04
@@ -4257,10 +4880,26 @@ Quickly identify systems running new or unusual processes in your environment th #### Detection Profile +* [Credential Extraction indicative of FGDump and CacheDump with s option](detections.md#credential-extraction-indicative-of-fgdump-and-cachedump-with-s-option) + +* [Credential Extraction indicative of FGDump and CacheDump with v option](detections.md#credential-extraction-indicative-of-fgdump-and-cachedump-with-v-option) + +* [Credential Extraction indicative of use of Mimikatz modules](detections.md#credential-extraction-indicative-of-use-of-mimikatz-modules) + +* [Credential Extraction native Microsoft debuggers peek into the kernel](detections.md#credential-extraction-native-microsoft-debuggers-peek-into-the-kernel) + +* [Credential Extraction native Microsoft debuggers via z command line option](detections.md#credential-extraction-native-microsoft-debuggers-via-z-command-line-option) + * [Detect Rare Executables](detections.md#detect-rare-executables) * [Detect processes used for System Network Configuration Discovery](detections.md#detect-processes-used-for-system-network-configuration-discovery) +* [First time seen command line argument](detections.md#first-time-seen-command-line-argument) + +* [More than usual number of LOLBAS applications in short time period](detections.md#more-than-usual-number-of-lolbas-applications-in-short-time-period) + +* [Rare Parent-Child Process Relationship](detections.md#rare-parent-child-process-relationship) + * [RunDLL Loading DLL By Ordinal](detections.md#rundll-loading-dll-by-ordinal) * [System Processes Run From Unexpected Locations](detections.md#system-processes-run-from-unexpected-locations) @@ -4276,7 +4915,14 @@ Quickly identify systems running new or unusual processes in your environment th | ID | Technique | Tactic | | ----------- | ----------- |--------------| +| T1003 | OS Credential Dumping | Credential Access | | T1016 | System Network Configuration Discovery | Discovery | +| T1059 | Command and Scripting Interpreter | Execution | +| | | | +| T1202 | Indirect Command Execution | Defense Evasion | +| T1053 | Scheduled Task/Job | Execution, Persistence, Privilege Escalation | +| T1203 | Exploitation for Client Execution | Execution | +| T1072 | Software Deployment Tools | Execution, Lateral Movement | | T1218.011 | Rundll32 | Defense Evasion | | T1036.003 | Rename System Utilities | Defense Evasion | | T1204.002 | Malicious File | Execution | @@ -4287,6 +4933,8 @@ Quickly identify systems running new or unusual processes in your environment th * Command and Control +* Exploitation + * Installation @@ -4353,7 +5001,7 @@ Windows services are often used by attackers for persistence and the ability to - **Product**: Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud - **Datamodel**: Endpoint -- **ATT&CK**: [T1543.003](https://attack.mitre.org/techniques/T1543.003/), [T1569.002](https://attack.mitre.org/techniques/T1569.002/), [T1574.011](https://attack.mitre.org/techniques/T1574.011/) +- **ATT&CK**: [T1055](https://attack.mitre.org/techniques/T1055/), [T1106](https://attack.mitre.org/techniques/T1106/), [T1543.003](https://attack.mitre.org/techniques/T1543.003/), [T1569](https://attack.mitre.org/techniques/T1569/), [T1569.002](https://attack.mitre.org/techniques/T1569.002/), [T1574.011](https://attack.mitre.org/techniques/T1574.011/) - **Last Updated**: 2017-11-02
@@ -4363,6 +5011,10 @@ Windows services are often used by attackers for persistence and the ability to * [First Time Seen Running Windows Service](detections.md#first-time-seen-running-windows-service) +* [Illegal Service and Process Control via Mimikatz modules](detections.md#illegal-service-and-process-control-via-mimikatz-modules) + +* [Illegal Service and Process Control via PowerSploit modules](detections.md#illegal-service-and-process-control-via-powersploit-modules) + * [Reg exe Manipulating Windows Services Registry Keys](detections.md#reg-exe-manipulating-windows-services-registry-keys) * [Sc exe Manipulating Windows Services](detections.md#sc-exe-manipulating-windows-services) @@ -4375,6 +5027,9 @@ Windows services are often used by attackers for persistence and the ability to | T1569.002 | Service Execution | Execution | | T1059.001 | PowerShell | Execution | | T1059.003 | Windows Command Shell | Execution | +| T1055 | Process Injection | Defense Evasion, Privilege Escalation | +| T1106 | Native API | Execution | +| T1569 | System Services | Execution | | T1574.011 | Services Registry Permissions Weakness | Defense Evasion, Persistence, Privilege Escalation | | T1543.003 | Windows Service | Persistence, Privilege Escalation | diff --git a/docs/stories.wiki b/docs/stories.wiki index d2fdf91c86..c0e34d272f 100644 --- a/docs/stories.wiki +++ b/docs/stories.wiki @@ -400,7 +400,7 @@ Cobalt Strike is threat emulation software. Red teams and penetration testers us * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218.011/ T1218.011] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1055/ T1055], [https://attack.mitre.org/techniques/T1218.010/ T1218.010], [https://attack.mitre.org/techniques/T1127.001/ T1127.001], [https://attack.mitre.org/techniques/T1036.003/ T1036.003], [https://attack.mitre.org/techniques/T1218.011/ T1218.011], [https://attack.mitre.org/techniques/T1127/ T1127] * '''Last Updated''': 2021-02-16
@@ -408,9 +408,25 @@ Cobalt Strike is threat emulation software. Red teams and penetration testers us ====Detection Profile==== +* [[Documentation:ESSOC:detections:Detections#Cobalt_strike_named_pipes|Cobalt Strike Named Pipes]] + +* [[Documentation:ESSOC:detections:Detections#Detect_regsvr32_application_control_bypass|Detect Regsvr32 Application Control Bypass]] + +* [[Documentation:ESSOC:detections:Detections#Suspicious_dllhost_no_command_line_arguments|Suspicious DLLHost no Command Line Arguments]] + +* [[Documentation:ESSOC:detections:Detections#Suspicious_gpupdate_no_command_line_arguments|Suspicious GPUpdate no Command Line Arguments]] + +* [[Documentation:ESSOC:detections:Detections#Suspicious_msbuild_rename|Suspicious MSBuild Rename]] + * [[Documentation:ESSOC:detections:Detections#Suspicious_rundll32_startw|Suspicious Rundll32 StartW]] -* [[Documentation:ESSOC:detections:Detections#Suspicious_rundll32_no_commandline_arguments|Suspicious Rundll32 no CommandLine Arguments]] +* [[Documentation:ESSOC:detections:Detections#Suspicious_rundll32_no_command_line_arguments|Suspicious Rundll32 no Command Line Arguments]] + +* [[Documentation:ESSOC:detections:Detections#Suspicious_searchprotocolhost_no_command_line_arguments|Suspicious SearchProtocolHost no Command Line Arguments]] + +* [[Documentation:ESSOC:detections:Detections#Suspicious_microsoft_workflow_compiler_rename|Suspicious microsoft workflow compiler rename]] + +* [[Documentation:ESSOC:detections:Detections#Suspicious_msbuild_path|Suspicious msbuild path]] @@ -420,9 +436,29 @@ Cobalt Strike is threat emulation software. Red teams and penetration testers us ! Technique ! Tactic |- +| T1055 +| Process Injection +| Defense Evasion, Privilege Escalation +|- +| T1218.010 +| Regsvr32 +| Defense Evasion +|- +| T1127.001 +| MSBuild +| Defense Evasion +|- +| T1036.003 +| Rename System Utilities +| Defense Evasion +|- | T1218.011 | Rundll32 | Defense Evasion +|- +| T1127 +| Trusted Developer Utilities Proxy Execution +| Defense Evasion |} @@ -430,6 +466,8 @@ Cobalt Strike is threat emulation software. Red teams and penetration testers us * Actions on Objectives +* Exploitation + ====Reference==== @@ -443,6 +481,10 @@ Cobalt Strike is threat emulation software. Red teams and penetration testers us * https://www.fireeye.com/blog/threat-research/2020/12/unauthorized-access-of-fireeye-red-team-tools.html +* https://github.com/MichaelKoczwara/Awesome-CobaltStrike-Defence + +* https://github.com/zer0yu/Awesome-CobaltStrike + ''version'': 1
@@ -664,7 +706,7 @@ Uncover activity consistent with credential dumping, a technique wherein attacke * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003.001/ T1003.001], [https://attack.mitre.org/techniques/T1059.001/ T1059.001], [https://attack.mitre.org/techniques/T1003.002/ T1003.002], [https://attack.mitre.org/techniques/T1003/ T1003], [https://attack.mitre.org/techniques/T1003.003/ T1003.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003.001/ T1003.001], [https://attack.mitre.org/techniques/T1055/ T1055], [https://attack.mitre.org/techniques/T1068/ T1068], [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1098/ T1098], [https://attack.mitre.org/techniques/T1134/ T1134], [https://attack.mitre.org/techniques/T1543/ T1543], [https://attack.mitre.org/techniques/T1547/ T1547], [https://attack.mitre.org/techniques/T1548/ T1548], [https://attack.mitre.org/techniques/T1554/ T1554], [https://attack.mitre.org/techniques/T1556/ T1556], [https://attack.mitre.org/techniques/T1558/ T1558], [https://attack.mitre.org/techniques/T1555/ T1555], [https://attack.mitre.org/techniques/T1087/ T1087], [https://attack.mitre.org/techniques/T1201/ T1201], [https://attack.mitre.org/techniques/T1552/ T1552], [https://attack.mitre.org/techniques/T1059.001/ T1059.001], [https://attack.mitre.org/techniques/T1003.002/ T1003.002], [https://attack.mitre.org/techniques/T1003/ T1003], [https://attack.mitre.org/techniques/T1003.003/ T1003.003], [https://attack.mitre.org/techniques/T1558.003/ T1558.003] * '''Last Updated''': 2020-02-04
@@ -674,6 +716,12 @@ Uncover activity consistent with credential dumping, a technique wherein attacke * [[Documentation:ESSOC:detections:Detections#Access_lsass_memory_for_dump_creation|Access LSASS Memory for Dump Creation]] +* [[Documentation:ESSOC:detections:Detections#Applying_stolen_credentials_via_mimikatz_modules|Applying Stolen Credentials via Mimikatz modules]] + +* [[Documentation:ESSOC:detections:Detections#Applying_stolen_credentials_via_powersploit_modules|Applying Stolen Credentials via PowerSploit modules]] + +* [[Documentation:ESSOC:detections:Detections#Assessment_of_credential_strength_via_dsinternals_modules|Assessment of Credential Strength via DSInternals modules]] + * [[Documentation:ESSOC:detections:Detections#Attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass|Attempt To Set Default PowerShell Execution Policy To Unrestricted or Bypass]] * [[Documentation:ESSOC:detections:Detections#Attempted_credential_dump_from_registry_via_reg_exe|Attempted Credential Dump From Registry via Reg exe]] @@ -690,10 +738,32 @@ Uncover activity consistent with credential dumping, a technique wherein attacke * [[Documentation:ESSOC:detections:Detections#Credential_dumping_via_symlink_to_shadow_copy|Credential Dumping via Symlink to Shadow Copy]] +* [[Documentation:ESSOC:detections:Detections#Credential_extraction_indicative_of_fgdump_and_cachedump_with_s_option|Credential Extraction indicative of FGDump and CacheDump with s option]] + +* [[Documentation:ESSOC:detections:Detections#Credential_extraction_indicative_of_fgdump_and_cachedump_with_v_option|Credential Extraction indicative of FGDump and CacheDump with v option]] + +* [[Documentation:ESSOC:detections:Detections#Credential_extraction_indicative_of_lazagne_command_line_options|Credential Extraction indicative of Lazagne command line options]] + +* [[Documentation:ESSOC:detections:Detections#Credential_extraction_indicative_of_use_of_dsinternals_credential_conversion_modules|Credential Extraction indicative of use of DSInternals credential conversion modules]] + +* [[Documentation:ESSOC:detections:Detections#Credential_extraction_indicative_of_use_of_dsinternals_modules|Credential Extraction indicative of use of DSInternals modules]] + +* [[Documentation:ESSOC:detections:Detections#Credential_extraction_indicative_of_use_of_mimikatz_modules|Credential Extraction indicative of use of Mimikatz modules]] + +* [[Documentation:ESSOC:detections:Detections#Credential_extraction_indicative_of_use_of_powersploit_modules|Credential Extraction indicative of use of PowerSploit modules]] + +* [[Documentation:ESSOC:detections:Detections#Credential_extraction_native_microsoft_debuggers_peek_into_the_kernel|Credential Extraction native Microsoft debuggers peek into the kernel]] + +* [[Documentation:ESSOC:detections:Detections#Credential_extraction_native_microsoft_debuggers_via_z_command_line_option|Credential Extraction native Microsoft debuggers via z command line option]] + +* [[Documentation:ESSOC:detections:Detections#Credential_extraction_via_get-addbaccount_module_present_in_powersploit_and_dsinternals|Credential Extraction via Get-ADDBAccount module present in PowerSploit and DSInternals]] + * [[Documentation:ESSOC:detections:Detections#Detect_credential_dumping_through_lsass_access|Detect Credential Dumping through LSASS access]] * [[Documentation:ESSOC:detections:Detections#Detect_dump_lsass_memory_using_comsvcs|Detect Dump LSASS Memory using comsvcs]] +* [[Documentation:ESSOC:detections:Detections#Detect_kerberoasting|Detect Kerberoasting]] + * [[Documentation:ESSOC:detections:Detections#Detect_mimikatz_using_loaded_images|Detect Mimikatz Using Loaded Images]] * [[Documentation:ESSOC:detections:Detections#Dump_lsass_via_comsvcs_dll|Dump LSASS via comsvcs DLL]] @@ -702,7 +772,7 @@ Uncover activity consistent with credential dumping, a technique wherein attacke * [[Documentation:ESSOC:detections:Detections#Dump_lsass_via_procdump_rename|Dump LSASS via procdump Rename]] -* [[Documentation:ESSOC:detections:Detections#Ntdsutil_export_ntds|Ntdsutil export ntds]] +* [[Documentation:ESSOC:detections:Detections#Ntdsutil_export_ntds|Ntdsutil Export NTDS]] * [[Documentation:ESSOC:detections:Detections#Unsigned_image_loaded_by_lsass|Unsigned Image Loaded by LSASS]] @@ -718,6 +788,66 @@ Uncover activity consistent with credential dumping, a technique wherein attacke | LSASS Memory | Credential Access |- +| T1055 +| Process Injection +| Defense Evasion, Privilege Escalation +|- +| T1068 +| Exploitation for Privilege Escalation +| Privilege Escalation +|- +| T1078 +| Valid Accounts +| Defense Evasion, Initial Access, Persistence, Privilege Escalation +|- +| T1098 +| Account Manipulation +| Persistence +|- +| T1134 +| Access Token Manipulation +| Defense Evasion, Privilege Escalation +|- +| T1543 +| Create or Modify System Process +| Persistence, Privilege Escalation +|- +| T1547 +| Boot or Logon Autostart Execution +| Persistence, Privilege Escalation +|- +| T1548 +| Abuse Elevation Control Mechanism +| Defense Evasion, Privilege Escalation +|- +| T1554 +| Compromise Client Software Binary +| Persistence +|- +| T1556 +| Modify Authentication Process +| Credential Access, Defense Evasion +|- +| T1558 +| Steal or Forge Kerberos Tickets +| Credential Access +|- +| T1555 +| Credentials from Password Stores +| Credential Access +|- +| T1087 +| Account Discovery +| Discovery +|- +| T1201 +| Password Policy Discovery +| Discovery +|- +| T1552 +| Unsecured Credentials +| Credential Access +|- | T1059.001 | PowerShell | Execution @@ -733,6 +863,10 @@ Uncover activity consistent with credential dumping, a technique wherein attacke | T1003.003 | NTDS | Credential Access +|- +| T1558.003 +| Kerberoasting +| Credential Access |} @@ -874,6 +1008,51 @@ The stealing of data by an adversary. * https://attack.mitre.org/tactics/TA0010/ +''version'': 1 +
+
+ +---- + +===Deobfuscate-decode files or information=== +Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1140/ T1140] +* '''Last Updated''': 2021-03-24 + +
+
+ +====Detection Profile==== + +* [[Documentation:ESSOC:detections:Detections#Certutil_with_decode_argument|CertUtil With Decode Argument]] + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1140 +| Deobfuscate/Decode Files or Information +| Defense Evasion +|} + + +====Kill Chain Phase==== + +* Exploitation + + +====Reference==== + +* https://attack.mitre.org/techniques/T1140/ + + ''version'': 1
@@ -1067,6 +1246,170 @@ Uncover activity consistent with CVE-2020-5902. Discovered by Positive Technolog * https://blog.cloudflare.com/cve-2020-5902-helping-to-protect-against-the-f5-tmui-rce-vulnerability/ +''version'': 1 +
+
+ +---- + +===Hafnium group=== +HAFNIUM group was identified by Microsoft as exploiting 4 Microsoft Exchange CVEs in the wild - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint, Network_Traffic +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059.001/ T1059.001], [https://attack.mitre.org/techniques/T1505.003/ T1505.003], [https://attack.mitre.org/techniques/T1136.001/ T1136.001], [https://attack.mitre.org/techniques/T1021.002/ T1021.002], [https://attack.mitre.org/techniques/T1003.001/ T1003.001], [https://attack.mitre.org/techniques/T1114.002/ T1114.002], [https://attack.mitre.org/techniques/T1003.003/ T1003.003], [https://attack.mitre.org/techniques/T1190/ T1190] +* '''Last Updated''': 2021-03-03 + +
+
+ +====Detection Profile==== + +* [[Documentation:ESSOC:detections:Detections#Any_powershell_downloadstring|Any Powershell DownloadString]] + +* [[Documentation:ESSOC:detections:Detections#Attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass|Attempt To Set Default PowerShell Execution Policy To Unrestricted or Bypass]] + +* [[Documentation:ESSOC:detections:Detections#Detect_exchange_web_shell|Detect Exchange Web Shell]] + +* [[Documentation:ESSOC:detections:Detections#Detect_new_local_admin_account|Detect New Local Admin account]] + +* [[Documentation:ESSOC:detections:Detections#Detect_psexec_with_accepteula_flag|Detect PsExec With accepteula Flag]] + +* [[Documentation:ESSOC:detections:Detections#Dump_lsass_via_comsvcs_dll|Dump LSASS via comsvcs DLL]] + +* [[Documentation:ESSOC:detections:Detections#Dump_lsass_via_procdump|Dump LSASS via procdump]] + +* [[Documentation:ESSOC:detections:Detections#Dump_lsass_via_procdump_rename|Dump LSASS via procdump Rename]] + +* [[Documentation:ESSOC:detections:Detections#Email_servers_sending_high_volume_traffic_to_hosts|Email servers sending high volume traffic to hosts]] + +* [[Documentation:ESSOC:detections:Detections#Malicious_powershell_process_-_connect_to_internet_with_hidden_window|Malicious PowerShell Process - Connect To Internet With Hidden Window]] + +* [[Documentation:ESSOC:detections:Detections#Malicious_powershell_process_-_execution_policy_bypass|Malicious PowerShell Process - Execution Policy Bypass]] + +* [[Documentation:ESSOC:detections:Detections#Nishang_powershelltcponeline|Nishang PowershellTCPOneLine]] + +* [[Documentation:ESSOC:detections:Detections#Ntdsutil_export_ntds|Ntdsutil Export NTDS]] + +* [[Documentation:ESSOC:detections:Detections#Unified_messaging_service_spawning_a_process|Unified Messaging Service Spawning a Process]] + +* [[Documentation:ESSOC:detections:Detections#W3wp_spawning_shell|W3WP Spawning Shell]] + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1059.001 +| PowerShell +| Execution +|- +| T1505.003 +| Web Shell +| Persistence +|- +| T1136.001 +| Local Account +| Persistence +|- +| T1021.002 +| SMB/Windows Admin Shares +| Lateral Movement +|- +| T1003.001 +| LSASS Memory +| Credential Access +|- +| T1114.002 +| Remote Email Collection +| Collection +|- +| T1003.003 +| NTDS +| Credential Access +|- +| T1190 +| Exploit Public-Facing Application +| Initial Access +|} + + +====Kill Chain Phase==== + +* Actions on Objectives + +* Command and Control + +* Exploitation + +* Installation + + +====Reference==== + +* https://www.splunk.com/en_us/blog/security/detecting-hafnium-exchange-server-zero-day-activity-in-splunk.html + +* https://www.volexity.com/blog/2021/03/02/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities/ + +* https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/ + +* https://blog.rapid7.com/2021/03/03/rapid7s-insightidr-enables-detection-and-response-to-microsoft-exchange-0-day/ + + +''version'': 1 +
+
+ +---- + +===Ingress tool transfer=== +Adversaries may transfer tools or other files from an external system into a compromised environment. Files may be copied from an external adversary controlled system through the command and control channel to bring tools into the victim network or through alternate protocols with another tool such as FTP. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1105/ T1105] +* '''Last Updated''': 2021-03-24 + +
+
+ +====Detection Profile==== + +* [[Documentation:ESSOC:detections:Detections#Certutil_download_with_urlcache_and_split_arguments|CertUtil Download With URLCache and Split Arguments]] + +* [[Documentation:ESSOC:detections:Detections#Certutil_download_with_verifyctl_and_split_arguments|CertUtil Download With VerifyCtl and Split Arguments]] + +* [[Documentation:ESSOC:detections:Detections#Suspicious_curl_network_connection|Suspicious Curl Network Connection]] + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1105 +| Ingress Tool Transfer +| Command and Control +|} + + +====Kill Chain Phase==== + +* Actions on Objectives + +* Exploitation + + +====Reference==== + +* https://attack.mitre.org/techniques/T1105/ + + ''version'': 1
@@ -1088,6 +1431,8 @@ Detect and investigate tactics, techniques, and procedures around how attackers * [[Documentation:ESSOC:detections:Detections#Detect_activity_related_to_pass_the_hash_attacks|Detect Activity Related to Pass the Hash Attacks]] +* [[Documentation:ESSOC:detections:Detections#Detect_pass_the_hash|Detect Pass the Hash]] + * [[Documentation:ESSOC:detections:Detections#Kerberoasting_spn_request_with_rc4_encryption|Kerberoasting spn request with RC4 encryption]] * [[Documentation:ESSOC:detections:Detections#Remote_desktop_network_traffic|Remote Desktop Network Traffic]] @@ -1143,7 +1488,7 @@ Attackers are finding stealthy ways "live off the land," leveraging utilities an * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059.001/ T1059.001], [https://attack.mitre.org/techniques/T1027/ T1027] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059.001/ T1059.001], [https://attack.mitre.org/techniques/T1003/ T1003], [https://attack.mitre.org/techniques/T1021/ T1021], [https://attack.mitre.org/techniques/T1113/ T1113], [https://attack.mitre.org/techniques/T1123/ T1123], [https://attack.mitre.org/techniques/T1563/ T1563], [https://attack.mitre.org/techniques/T1053/ T1053], [https://attack.mitre.org/techniques/T1134/ T1134], [https://attack.mitre.org/techniques/T1548/ T1548], [https://attack.mitre.org/techniques/T1055/ T1055], [https://attack.mitre.org/techniques/T1106/ T1106], [https://attack.mitre.org/techniques/T1569/ T1569], [https://attack.mitre.org/techniques/T1027/ T1027] * '''Last Updated''': 2017-08-23
@@ -1151,8 +1496,26 @@ Attackers are finding stealthy ways "live off the land," leveraging utilities an ====Detection Profile==== +* [[Documentation:ESSOC:detections:Detections#Any_powershell_downloadfile|Any Powershell DownloadFile]] + +* [[Documentation:ESSOC:detections:Detections#Any_powershell_downloadstring|Any Powershell DownloadString]] + * [[Documentation:ESSOC:detections:Detections#Attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass|Attempt To Set Default PowerShell Execution Policy To Unrestricted or Bypass]] +* [[Documentation:ESSOC:detections:Detections#Credential_extraction_indicative_of_use_of_dsinternals_credential_conversion_modules|Credential Extraction indicative of use of DSInternals credential conversion modules]] + +* [[Documentation:ESSOC:detections:Detections#Credential_extraction_indicative_of_use_of_dsinternals_modules|Credential Extraction indicative of use of DSInternals modules]] + +* [[Documentation:ESSOC:detections:Detections#Credential_extraction_indicative_of_use_of_powersploit_modules|Credential Extraction indicative of use of PowerSploit modules]] + +* [[Documentation:ESSOC:detections:Detections#Credential_extraction_via_get-addbaccount_module_present_in_powersploit_and_dsinternals|Credential Extraction via Get-ADDBAccount module present in PowerSploit and DSInternals]] + +* [[Documentation:ESSOC:detections:Detections#Illegal_access_to_user_content_via_powersploit_modules|Illegal Access To User Content via PowerSploit modules]] + +* [[Documentation:ESSOC:detections:Detections#Illegal_privilege_elevation_and_persistence_via_powersploit_modules|Illegal Privilege Elevation and Persistence via PowerSploit modules]] + +* [[Documentation:ESSOC:detections:Detections#Illegal_service_and_process_control_via_powersploit_modules|Illegal Service and Process Control via PowerSploit modules]] + * [[Documentation:ESSOC:detections:Detections#Malicious_powershell_process_-_connect_to_internet_with_hidden_window|Malicious PowerShell Process - Connect To Internet With Hidden Window]] * [[Documentation:ESSOC:detections:Detections#Malicious_powershell_process_-_encoded_command|Malicious PowerShell Process - Encoded Command]] @@ -1173,6 +1536,50 @@ Attackers are finding stealthy ways "live off the land," leveraging utilities an | PowerShell | Execution |- +| T1003 +| OS Credential Dumping +| Credential Access +|- +| T1021 +| Remote Services +| Lateral Movement +|- +| T1113 +| Screen Capture +| Collection +|- +| T1123 +| Audio Capture +| Collection +|- +| T1563 +| Remote Service Session Hijacking +| Lateral Movement +|- +| T1053 +| Scheduled Task/Job +| Execution, Persistence, Privilege Escalation +|- +| T1134 +| Access Token Manipulation +| Defense Evasion, Privilege Escalation +|- +| T1548 +| Abuse Elevation Control Mechanism +| Defense Evasion, Privilege Escalation +|- +| T1055 +| Process Injection +| Defense Evasion, Privilege Escalation +|- +| T1106 +| Native API +| Execution +|- +| T1569 +| System Services +| Execution +|- | T1027 | Obfuscated Files or Information | Defense Evasion @@ -1185,6 +1592,8 @@ Attackers are finding stealthy ways "live off the land," leveraging utilities an * Command and Control +* Exploitation + * Installation @@ -1201,6 +1610,125 @@ Attackers are finding stealthy ways "live off the land," leveraging utilities an ---- +===Nobelium group=== +Sunburst is a trojanized updates to SolarWinds Orion IT monitoring and management software. It was discovered by FireEye in December 2020. The actors behind this campaign gained access to numerous public and private organizations around the world. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint, Network_Traffic, Web +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1071.002/ T1071.002], [https://attack.mitre.org/techniques/T1059.003/ T1059.003], [https://attack.mitre.org/techniques/T1218.005/ T1218.005], [https://attack.mitre.org/techniques/T1569.002/ T1569.002], [https://attack.mitre.org/techniques/T1027/ T1027], [https://attack.mitre.org/techniques/T1543.003/ T1543.003], [https://attack.mitre.org/techniques/T1053.005/ T1053.005], [https://attack.mitre.org/techniques/T1203/ T1203], [https://attack.mitre.org/techniques/T1505.003/ T1505.003], [https://attack.mitre.org/techniques/T1071.001/ T1071.001], [https://attack.mitre.org/techniques/T1018/ T1018] +* '''Last Updated''': 2020-12-14 + +
+
+ +====Detection Profile==== + +* [[Documentation:ESSOC:detections:Detections#Detect_outbound_smb_traffic|Detect Outbound SMB Traffic]] + +* [[Documentation:ESSOC:detections:Detections#Detect_prohibited_applications_spawning_cmd_exe|Detect Prohibited Applications Spawning cmd exe]] + +* [[Documentation:ESSOC:detections:Detections#Detect_rundll32_inline_hta_execution|Detect Rundll32 Inline HTA Execution]] + +* [[Documentation:ESSOC:detections:Detections#First_time_seen_running_windows_service|First Time Seen Running Windows Service]] + +* [[Documentation:ESSOC:detections:Detections#Malicious_powershell_process_-_encoded_command|Malicious PowerShell Process - Encoded Command]] + +* [[Documentation:ESSOC:detections:Detections#Sc_exe_manipulating_windows_services|Sc exe Manipulating Windows Services]] + +* [[Documentation:ESSOC:detections:Detections#Scheduled_task_deleted_or_created_via_cmd|Scheduled Task Deleted Or Created via CMD]] + +* [[Documentation:ESSOC:detections:Detections#Schtasks_scheduling_job_on_remote_system|Schtasks scheduling job on remote system]] + +* [[Documentation:ESSOC:detections:Detections#Sunburst_correlation_dll_and_network_event|Sunburst Correlation DLL and Network Event]] + +* [[Documentation:ESSOC:detections:Detections#Supernova_webshell|Supernova Webshell]] + +* [[Documentation:ESSOC:detections:Detections#Tor_traffic|TOR Traffic]] + +* [[Documentation:ESSOC:detections:Detections#Windows_adfind_exe|Windows AdFind Exe]] + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1071.002 +| File Transfer Protocols +| Command and Control +|- +| T1059.003 +| Windows Command Shell +| Execution +|- +| T1218.005 +| Mshta +| Defense Evasion +|- +| T1569.002 +| Service Execution +| Execution +|- +| T1027 +| Obfuscated Files or Information +| Defense Evasion +|- +| T1543.003 +| Windows Service +| Persistence, Privilege Escalation +|- +| T1053.005 +| Scheduled Task +| Execution, Persistence, Privilege Escalation +|- +| T1203 +| Exploitation for Client Execution +| Execution +|- +| T1505.003 +| Web Shell +| Persistence +|- +| T1071.001 +| Web Protocols +| Command and Control +|- +| T1018 +| Remote System Discovery +| Discovery +|} + + +====Kill Chain Phase==== + +* Actions on Objectives + +* Command and Control + +* Exfiltration + +* Exploitation + +* Installation + + +====Reference==== + +* https://www.microsoft.com/security/blog/2021/03/04/goldmax-goldfinder-sibot-analyzing-nobelium-malware/ + +* https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html + +* https://msrc-blog.microsoft.com/2020/12/13/customer-guidance-on-recent-nation-state-cyber-attacks/ + + +''version'': 2 +
+
+ +---- + ===Phishing payloads=== Detect signs of malicious payloads that may indicate that your environment has been breached via a phishing attack. @@ -1366,40 +1894,26 @@ Use the searches in this Analytic Story to help you detect structured query lang ---- -===Sunburst malware=== -Sunburst is a trojanized updates to SolarWinds Orion IT monitoring and management software. It was discovered by FireEye in December 2020. The actors behind this campaign gained access to numerous public and private organizations around the world. +===Silver sparrow=== +Silver Sparrow, identified by Red Canary Intelligence, is a new forward looking MacOS (Intel and M1) malicious software downloader utilizing JavaScript for execution and a launchAgent to establish persistence. * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud -* '''Datamodel''': Endpoint, Network_Traffic, Web -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1071.002/ T1071.002], [https://attack.mitre.org/techniques/T1059.003/ T1059.003], [https://attack.mitre.org/techniques/T1569.002/ T1569.002], [https://attack.mitre.org/techniques/T1027/ T1027], [https://attack.mitre.org/techniques/T1543.003/ T1543.003], [https://attack.mitre.org/techniques/T1053.005/ T1053.005], [https://attack.mitre.org/techniques/T1203/ T1203], [https://attack.mitre.org/techniques/T1505.003/ T1505.003], [https://attack.mitre.org/techniques/T1071.001/ T1071.001], [https://attack.mitre.org/techniques/T1018/ T1018] -* '''Last Updated''': 2020-12-14 +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1105/ T1105], [https://attack.mitre.org/techniques/T1543.001/ T1543.001], [https://attack.mitre.org/techniques/T1074/ T1074] +* '''Last Updated''': 2021-02-24
====Detection Profile==== -* [[Documentation:ESSOC:detections:Detections#Detect_outbound_smb_traffic|Detect Outbound SMB Traffic]] +* [[Documentation:ESSOC:detections:Detections#Suspicious_curl_network_connection|Suspicious Curl Network Connection]] -* [[Documentation:ESSOC:detections:Detections#Detect_prohibited_applications_spawning_cmd_exe|Detect Prohibited Applications Spawning cmd exe]] +* [[Documentation:ESSOC:detections:Detections#Suspicious_plistbuddy_usage|Suspicious PlistBuddy Usage]] -* [[Documentation:ESSOC:detections:Detections#First_time_seen_running_windows_service|First Time Seen Running Windows Service]] +* [[Documentation:ESSOC:detections:Detections#Suspicious_plistbuddy_usage_via_osquery|Suspicious PlistBuddy Usage via OSquery]] -* [[Documentation:ESSOC:detections:Detections#Malicious_powershell_process_-_encoded_command|Malicious PowerShell Process - Encoded Command]] - -* [[Documentation:ESSOC:detections:Detections#Sc_exe_manipulating_windows_services|Sc exe Manipulating Windows Services]] - -* [[Documentation:ESSOC:detections:Detections#Scheduled_task_deleted_or_created_via_cmd|Scheduled Task Deleted Or Created via CMD]] - -* [[Documentation:ESSOC:detections:Detections#Schtasks_scheduling_job_on_remote_system|Schtasks scheduling job on remote system]] - -* [[Documentation:ESSOC:detections:Detections#Sunburst_correlation_dll_and_network_event|Sunburst Correlation DLL and Network Event]] - -* [[Documentation:ESSOC:detections:Detections#Supernova_webshell|Supernova Webshell]] - -* [[Documentation:ESSOC:detections:Detections#Tor_traffic|TOR Traffic]] - -* [[Documentation:ESSOC:detections:Detections#Windows_adfind_exe|Windows AdFind Exe]] +* [[Documentation:ESSOC:detections:Detections#Suspicious_sqlite3_lsquarantine_behavior|Suspicious SQLite3 LSQuarantine Behavior]] @@ -1409,45 +1923,17 @@ Sunburst is a trojanized updates to SolarWinds Orion IT monitoring and managemen ! Technique ! Tactic |- -| T1071.002 -| File Transfer Protocols +| T1105 +| Ingress Tool Transfer | Command and Control |- -| T1059.003 -| Windows Command Shell -| Execution -|- -| T1569.002 -| Service Execution -| Execution -|- -| T1027 -| Obfuscated Files or Information -| Defense Evasion -|- -| T1543.003 -| Windows Service +| T1543.001 +| Launch Agent | Persistence, Privilege Escalation |- -| T1053.005 -| Scheduled Task -| Execution, Persistence, Privilege Escalation -|- -| T1203 -| Exploitation for Client Execution -| Execution -|- -| T1505.003 -| Web Shell -| Persistence -|- -| T1071.001 -| Web Protocols -| Command and Control -|- -| T1018 -| Remote System Discovery -| Discovery +| T1074 +| Data Staged +| Collection |} @@ -1455,20 +1941,12 @@ Sunburst is a trojanized updates to SolarWinds Orion IT monitoring and managemen * Actions on Objectives -* Command and Control - -* Exfiltration - -* Exploitation - -* Installation - ====Reference==== -* https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html +* https://redcanary.com/blog/clipping-silver-sparrows-wings/ -* https://msrc-blog.microsoft.com/2020/12/13/customer-guidance-on-recent-nation-state-cyber-attacks/ +* https://www.sentinelone.com/blog/5-things-you-need-to-know-about-silver-sparrow/ ''version'': 1 @@ -1482,7 +1960,7 @@ Leveraging the Windows command-line interface (CLI) is one of the most common at * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059.003/ T1059.003], [https://attack.mitre.org/techniques/T1068/ T1068], [https://attack.mitre.org/techniques/T1059.001/ T1059.001], [https://attack.mitre.org/techniques/T1036.003/ T1036.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059.003/ T1059.003], [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1068/ T1068], [https://attack.mitre.org/techniques/T1059.001/ T1059.001], [https://attack.mitre.org/techniques/T1036.003/ T1036.003] * '''Last Updated''': 2020-02-03
@@ -1514,6 +1992,10 @@ Leveraging the Windows command-line interface (CLI) is one of the most common at | Windows Command Shell | Execution |- +| T1059 +| Command and Scripting Interpreter +| Execution +|- | T1068 | Exploitation for Privilege Escalation | Privilege Escalation @@ -1752,7 +2234,7 @@ Monitor and detect techniques used by attackers who leverage the mshta.exe proce * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218.005/ T1218.005], [https://attack.mitre.org/techniques/T1059.003/ T1059.003], [https://attack.mitre.org/techniques/T1547.001/ T1547.001] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1218.005/ T1218.005], [https://attack.mitre.org/techniques/T1059.003/ T1059.003], [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1547.001/ T1547.001] * '''Last Updated''': 2021-01-20
@@ -1792,6 +2274,10 @@ Monitor and detect techniques used by attackers who leverage the mshta.exe proce | Windows Command Shell | Execution |- +| T1059 +| Command and Scripting Interpreter +| Execution +|- | T1547.001 | Registry Run Keys / Startup Folder | Persistence, Privilege Escalation @@ -2012,7 +2498,7 @@ Monitor and detect techniques used by attackers who leverage rundll32.exe to exe * [[Documentation:ESSOC:detections:Detections#Suspicious_rundll32_dllregisterserver|Suspicious Rundll32 dllregisterserver]] -* [[Documentation:ESSOC:detections:Detections#Suspicious_rundll32_no_commandline_arguments|Suspicious Rundll32 no CommandLine Arguments]] +* [[Documentation:ESSOC:detections:Detections#Suspicious_rundll32_no_command_line_arguments|Suspicious Rundll32 no Command Line Arguments]] @@ -2124,7 +2610,7 @@ Monitor and detect registry changes initiated from remote locations, which can b * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1548.002/ T1548.002], [https://attack.mitre.org/techniques/T1222.001/ T1222.001], [https://attack.mitre.org/techniques/T1547.010/ T1547.010], [https://attack.mitre.org/techniques/T1564.001/ T1564.001], [https://attack.mitre.org/techniques/T1547.001/ T1547.001], [https://attack.mitre.org/techniques/T1546.012/ T1546.012], [https://attack.mitre.org/techniques/T1546.011/ T1546.011], [https://attack.mitre.org/techniques/T1546.001/ T1546.001], [https://attack.mitre.org/techniques/T1112/ T1112] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1548.002/ T1548.002], [https://attack.mitre.org/techniques/T1112/ T1112], [https://attack.mitre.org/techniques/T1222.001/ T1222.001], [https://attack.mitre.org/techniques/T1547.010/ T1547.010], [https://attack.mitre.org/techniques/T1564.001/ T1564.001], [https://attack.mitre.org/techniques/T1547.001/ T1547.001], [https://attack.mitre.org/techniques/T1546.012/ T1546.012], [https://attack.mitre.org/techniques/T1546.011/ T1546.011], [https://attack.mitre.org/techniques/T1546.001/ T1546.001], [https://attack.mitre.org/techniques/T1036/ T1036], [https://attack.mitre.org/techniques/T1562.001/ T1562.001] * '''Last Updated''': 2018-05-31
@@ -2160,6 +2646,10 @@ Monitor and detect registry changes initiated from remote locations, which can b | Bypass User Account Control | Defense Evasion, Privilege Escalation |- +| T1112 +| Modify Registry +| Defense Evasion +|- | T1222.001 | Windows File and Directory Permissions Modification | Defense Evasion @@ -2188,8 +2678,12 @@ Monitor and detect registry changes initiated from remote locations, which can b | Change Default File Association | Persistence, Privilege Escalation |- -| T1112 -| Modify Registry +| T1036 +| Masquerading +| Defense Evasion +|- +| T1562.001 +| Disable or Modify Tools | Defense Evasion |} @@ -2217,7 +2711,7 @@ Attackers are using Zoom as an vector to increase privileges on a sytems. This s * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059.003/ T1059.003], [https://attack.mitre.org/techniques/T1068/ T1068], [https://attack.mitre.org/techniques/T1059.001/ T1059.001], [https://attack.mitre.org/techniques/T1036.003/ T1036.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1059.003/ T1059.003], [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques/T1068/ T1068], [https://attack.mitre.org/techniques/T1059.001/ T1059.001], [https://attack.mitre.org/techniques/T1036.003/ T1036.003] * '''Last Updated''': 2020-04-13
@@ -2241,6 +2735,10 @@ Attackers are using Zoom as an vector to increase privileges on a sytems. This s | Windows Command Shell | Execution |- +| T1059 +| Command and Scripting Interpreter +| Execution +|- | T1068 | Exploitation for Privilege Escalation | Privilege Escalation @@ -2447,7 +2945,7 @@ Detect tactics used by malware to evade defenses on Windows endpoints. A few of * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1548.002/ T1548.002], [https://attack.mitre.org/techniques/T1222.001/ T1222.001], [https://attack.mitre.org/techniques/T1547.010/ T1547.010], [https://attack.mitre.org/techniques/T1564.001/ T1564.001], [https://attack.mitre.org/techniques/T1547.001/ T1547.001], [https://attack.mitre.org/techniques/T1546.012/ T1546.012], [https://attack.mitre.org/techniques/T1546.011/ T1546.011], [https://attack.mitre.org/techniques/T1546.001/ T1546.001], [https://attack.mitre.org/techniques/T1112/ T1112] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1548.002/ T1548.002], [https://attack.mitre.org/techniques/T1112/ T1112], [https://attack.mitre.org/techniques/T1222.001/ T1222.001], [https://attack.mitre.org/techniques/T1547.010/ T1547.010], [https://attack.mitre.org/techniques/T1564.001/ T1564.001], [https://attack.mitre.org/techniques/T1547.001/ T1547.001], [https://attack.mitre.org/techniques/T1546.012/ T1546.012], [https://attack.mitre.org/techniques/T1546.011/ T1546.011], [https://attack.mitre.org/techniques/T1546.001/ T1546.001], [https://attack.mitre.org/techniques/T1036/ T1036], [https://attack.mitre.org/techniques/T1562.001/ T1562.001] * '''Last Updated''': 2018-05-31
@@ -2457,6 +2955,10 @@ Detect tactics used by malware to evade defenses on Windows endpoints. A few of * [[Documentation:ESSOC:detections:Detections#Disabling_remote_user_account_control|Disabling Remote User Account Control]] +* [[Documentation:ESSOC:detections:Detections#Eventvwr_uac_bypass|Eventvwr UAC Bypass]] + +* [[Documentation:ESSOC:detections:Detections#Fodhelper_uac_bypass|FodHelper UAC Bypass]] + * [[Documentation:ESSOC:detections:Detections#Hiding_files_and_directories_with_attrib_exe|Hiding Files And Directories With Attrib exe]] * [[Documentation:ESSOC:detections:Detections#Reg_exe_used_to_hide_files_directories_via_registry_keys|Reg exe used to hide files directories via registry keys]] @@ -2465,6 +2967,10 @@ Detect tactics used by malware to evade defenses on Windows endpoints. A few of * [[Documentation:ESSOC:detections:Detections#Suspicious_reg_exe_process|Suspicious Reg exe Process]] +* [[Documentation:ESSOC:detections:Detections#System_process_running_from_unexpected_location|System Process Running from Unexpected Location]] + +* [[Documentation:ESSOC:detections:Detections#Windows_disableantispyware_registry|Windows DisableAntiSpyware Registry]] + ====ATT&CK==== @@ -2477,6 +2983,10 @@ Detect tactics used by malware to evade defenses on Windows endpoints. A few of | Bypass User Account Control | Defense Evasion, Privilege Escalation |- +| T1112 +| Modify Registry +| Defense Evasion +|- | T1222.001 | Windows File and Directory Permissions Modification | Defense Evasion @@ -2505,8 +3015,12 @@ Detect tactics used by malware to evade defenses on Windows endpoints. A few of | Change Default File Association | Persistence, Privilege Escalation |- -| T1112 -| Modify Registry +| T1036 +| Masquerading +| Defense Evasion +|- +| T1562.001 +| Disable or Modify Tools | Defense Evasion |} @@ -2515,12 +3029,213 @@ Detect tactics used by malware to evade defenses on Windows endpoints. A few of * Actions on Objectives +* Delivery + +* Exploitation + +* Privilege Escalation + ====Reference==== * https://attack.mitre.org/wiki/Defense_Evasion +''version'': 1 +
+
+ +---- + +===Windows discovery techniques=== +Monitors for behaviors associated with adversaries discovering objects in the environment that can be leveraged in the progression of the attack. + +* '''Product''': UEBA for Security Cloud +* '''Datamodel''': +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1087/ T1087], [https://attack.mitre.org/techniques/T1484/ T1484], [https://attack.mitre.org/techniques/T1199/ T1199], [https://attack.mitre.org/techniques/T1482/ T1482], [https://attack.mitre.org/techniques/T1590/ T1590], [https://attack.mitre.org/techniques/T1591/ T1591], [https://attack.mitre.org/techniques/T1595/ T1595], [https://attack.mitre.org/techniques/T1592/ T1592], [https://attack.mitre.org/techniques/T1007/ T1007], [https://attack.mitre.org/techniques/T1012/ T1012], [https://attack.mitre.org/techniques/T1046/ T1046], [https://attack.mitre.org/techniques/T1047/ T1047], [https://attack.mitre.org/techniques/T1057/ T1057], [https://attack.mitre.org/techniques/T1083/ T1083], [https://attack.mitre.org/techniques/T1518/ T1518], [https://attack.mitre.org/techniques/T1592.002/ T1592.002], [https://attack.mitre.org/techniques/T1021.002/ T1021.002], [https://attack.mitre.org/techniques/T1135/ T1135], [https://attack.mitre.org/techniques/T1039/ T1039], [https://attack.mitre.org/techniques/T1053/ T1053], [https://attack.mitre.org/techniques/T1068/ T1068], [https://attack.mitre.org/techniques/T1543/ T1543], [https://attack.mitre.org/techniques/T1547/ T1547], [https://attack.mitre.org/techniques/T1574/ T1574], [https://attack.mitre.org/techniques/T1589.001/ T1589.001], [https://attack.mitre.org/techniques/T1590.001/ T1590.001], [https://attack.mitre.org/techniques/T1590.003/ T1590.003], [https://attack.mitre.org/techniques/T1098/ T1098], [https://attack.mitre.org/techniques/T1595.002/ T1595.002], [https://attack.mitre.org/techniques/T1055/ T1055] +* '''Last Updated''': 2021-03-04 + +
+
+ +====Detection Profile==== + +* [[Documentation:ESSOC:detections:Detections#Reconnaissance_and_access_to_accounts_groups_and_policies_via_powersploit_modules|Reconnaissance and Access to Accounts Groups and Policies via PowerSploit modules]] + +* [[Documentation:ESSOC:detections:Detections#Reconnaissance_and_access_to_accounts_and_groups_via_mimikatz_modules|Reconnaissance and Access to Accounts and Groups via Mimikatz modules]] + +* [[Documentation:ESSOC:detections:Detections#Reconnaissance_and_access_to_active_directoty_infrastructure_via_powersploit_modules|Reconnaissance and Access to Active Directoty Infrastructure via PowerSploit modules]] + +* [[Documentation:ESSOC:detections:Detections#Reconnaissance_and_access_to_computers_and_domains_via_powersploit_modules|Reconnaissance and Access to Computers and Domains via PowerSploit modules]] + +* [[Documentation:ESSOC:detections:Detections#Reconnaissance_and_access_to_computers_via_mimikatz_modules|Reconnaissance and Access to Computers via Mimikatz modules]] + +* [[Documentation:ESSOC:detections:Detections#Reconnaissance_and_access_to_operating_system_elements_via_powersploit_modules|Reconnaissance and Access to Operating System Elements via PowerSploit modules]] + +* [[Documentation:ESSOC:detections:Detections#Reconnaissance_and_access_to_processes_and_services_via_mimikatz_modules|Reconnaissance and Access to Processes and Services via Mimikatz modules]] + +* [[Documentation:ESSOC:detections:Detections#Reconnaissance_and_access_to_shared_resources_via_mimikatz_modules|Reconnaissance and Access to Shared Resources via Mimikatz modules]] + +* [[Documentation:ESSOC:detections:Detections#Reconnaissance_and_access_to_shared_resources_via_powersploit_modules|Reconnaissance and Access to Shared Resources via PowerSploit modules]] + +* [[Documentation:ESSOC:detections:Detections#Reconnaissance_of_access_and_persistence_opportunities_via_powersploit_modules|Reconnaissance of Access and Persistence Opportunities via PowerSploit modules]] + +* [[Documentation:ESSOC:detections:Detections#Reconnaissance_of_connectivity_via_powersploit_modules|Reconnaissance of Connectivity via PowerSploit modules]] + +* [[Documentation:ESSOC:detections:Detections#Reconnaissance_of_credential_stores_and_services_via_mimikatz_modules|Reconnaissance of Credential Stores and Services via Mimikatz modules]] + +* [[Documentation:ESSOC:detections:Detections#Reconnaissance_of_defensive_tools_via_powersploit_modules|Reconnaissance of Defensive Tools via PowerSploit modules]] + +* [[Documentation:ESSOC:detections:Detections#Reconnaissance_of_privilege_escalation_opportunities_via_powersploit_modules|Reconnaissance of Privilege Escalation Opportunities via PowerSploit modules]] + +* [[Documentation:ESSOC:detections:Detections#Reconnaissance_of_process_or_service_hijacking_opportunities_via_mimikatz_modules|Reconnaissance of Process or Service Hijacking Opportunities via Mimikatz modules]] + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1078 +| Valid Accounts +| Defense Evasion, Initial Access, Persistence, Privilege Escalation +|- +| T1087 +| Account Discovery +| Discovery +|- +| T1484 +| Domain Policy Modification +| Defense Evasion, Privilege Escalation +|- +| T1199 +| Trusted Relationship +| Initial Access +|- +| T1482 +| Domain Trust Discovery +| Discovery +|- +| T1590 +| Gather Victim Network Information +| Reconnaissance +|- +| T1591 +| Gather Victim Org Information +| Reconnaissance +|- +| T1595 +| Active Scanning +| Reconnaissance +|- +| T1592 +| Gather Victim Host Information +| Reconnaissance +|- +| T1007 +| System Service Discovery +| Discovery +|- +| T1012 +| Query Registry +| Discovery +|- +| T1046 +| Network Service Scanning +| Discovery +|- +| T1047 +| Windows Management Instrumentation +| Execution +|- +| T1057 +| Process Discovery +| Discovery +|- +| T1083 +| File and Directory Discovery +| Discovery +|- +| T1518 +| Software Discovery +| Discovery +|- +| T1592.002 +| Software +| Reconnaissance +|- +| T1021.002 +| SMB/Windows Admin Shares +| Lateral Movement +|- +| T1135 +| Network Share Discovery +| Discovery +|- +| T1039 +| Data from Network Shared Drive +| Collection +|- +| T1053 +| Scheduled Task/Job +| Execution, Persistence, Privilege Escalation +|- +| T1068 +| Exploitation for Privilege Escalation +| Privilege Escalation +|- +| T1543 +| Create or Modify System Process +| Persistence, Privilege Escalation +|- +| T1547 +| Boot or Logon Autostart Execution +| Persistence, Privilege Escalation +|- +| T1574 +| Hijack Execution Flow +| Defense Evasion, Persistence, Privilege Escalation +|- +| T1589.001 +| Credentials +| Reconnaissance +|- +| T1590.001 +| Domain Properties +| Reconnaissance +|- +| T1590.003 +| Network Trust Dependencies +| Reconnaissance +|- +| T1098 +| Account Manipulation +| Persistence +|- +| T1595.002 +| Vulnerability Scanning +| Reconnaissance +|- +| T1055 +| Process Injection +| Defense Evasion, Privilege Escalation +|} + + +====Kill Chain Phase==== + +* Actions on Objectives + + +====Reference==== + +* https://attack.mitre.org/tactics/TA0007/ + +* https://cyberd.us/penetration-testing + + ''version'': 1
@@ -2532,7 +3247,7 @@ Adversaries often try to cover their tracks by manipulating Windows logs. Use th * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1490/ T1490], [https://attack.mitre.org/techniques/T1070.001/ T1070.001], [https://attack.mitre.org/techniques/T1070/ T1070] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1490/ T1490], [https://attack.mitre.org/techniques/T1070/ T1070], [https://attack.mitre.org/techniques/T1070.001/ T1070.001] * '''Last Updated''': 2017-09-12
@@ -2542,6 +3257,8 @@ Adversaries often try to cover their tracks by manipulating Windows logs. Use th * [[Documentation:ESSOC:detections:Detections#Deleting_shadow_copies|Deleting Shadow Copies]] +* [[Documentation:ESSOC:detections:Detections#Illegal_deletion_of_logs_via_mimikatz_modules|Illegal Deletion of Logs via Mimikatz modules]] + * [[Documentation:ESSOC:detections:Detections#Suspicious_wevtutil_usage|Suspicious wevtutil Usage]] * [[Documentation:ESSOC:detections:Detections#Usn_journal_deletion|USN Journal Deletion]] @@ -2560,13 +3277,13 @@ Adversaries often try to cover their tracks by manipulating Windows logs. Use th | Inhibit System Recovery | Impact |- -| T1070.001 -| Clear Windows Event Logs -| Defense Evasion -|- | T1070 | Indicator Removal on Host | Defense Evasion +|- +| T1070.001 +| Clear Windows Event Logs +| Defense Evasion |} @@ -2595,7 +3312,7 @@ Monitor for activities and techniques associated with maintaining persistence on * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1574.009/ T1574.009], [https://attack.mitre.org/techniques/T1222.001/ T1222.001], [https://attack.mitre.org/techniques/T1547.010/ T1547.010], [https://attack.mitre.org/techniques/T1574.011/ T1574.011], [https://attack.mitre.org/techniques/T1564.001/ T1564.001], [https://attack.mitre.org/techniques/T1547.001/ T1547.001], [https://attack.mitre.org/techniques/T1546.011/ T1546.011], [https://attack.mitre.org/techniques/T1543.003/ T1543.003], [https://attack.mitre.org/techniques/T1053.005/ T1053.005] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1574.009/ T1574.009], [https://attack.mitre.org/techniques/T1222.001/ T1222.001], [https://attack.mitre.org/techniques/T1585/ T1585], [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1098/ T1098], [https://attack.mitre.org/techniques/T1207/ T1207], [https://attack.mitre.org/techniques/T1484/ T1484], [https://attack.mitre.org/techniques/T1053/ T1053], [https://attack.mitre.org/techniques/T1134/ T1134], [https://attack.mitre.org/techniques/T1548/ T1548], [https://attack.mitre.org/techniques/T1547.010/ T1547.010], [https://attack.mitre.org/techniques/T1574.011/ T1574.011], [https://attack.mitre.org/techniques/T1564.001/ T1564.001], [https://attack.mitre.org/techniques/T1547.001/ T1547.001], [https://attack.mitre.org/techniques/T1546.011/ T1546.011], [https://attack.mitre.org/techniques/T1543.003/ T1543.003], [https://attack.mitre.org/techniques/T1053.005/ T1053.005], [https://attack.mitre.org/techniques/T1068/ T1068] * '''Last Updated''': 2018-05-31
@@ -2609,6 +3326,16 @@ Monitor for activities and techniques associated with maintaining persistence on * [[Documentation:ESSOC:detections:Detections#Hiding_files_and_directories_with_attrib_exe|Hiding Files And Directories With Attrib exe]] +* [[Documentation:ESSOC:detections:Detections#Illegal_account_creation_via_powersploit_modules|Illegal Account Creation via PowerSploit modules]] + +* [[Documentation:ESSOC:detections:Detections#Illegal_enabling_or_disabling_of_accounts_via_dsinternals_modules|Illegal Enabling or Disabling of Accounts via DSInternals modules]] + +* [[Documentation:ESSOC:detections:Detections#Illegal_management_of_active_directory_elements_and_policies_via_dsinternals_modules|Illegal Management of Active Directory Elements and Policies via DSInternals modules]] + +* [[Documentation:ESSOC:detections:Detections#Illegal_management_of_computers_and_active_directory_elements_via_powersploit_modules|Illegal Management of Computers and Active Directory Elements via PowerSploit modules]] + +* [[Documentation:ESSOC:detections:Detections#Illegal_privilege_elevation_and_persistence_via_powersploit_modules|Illegal Privilege Elevation and Persistence via PowerSploit modules]] + * [[Documentation:ESSOC:detections:Detections#Monitor_registry_keys_for_print_monitors|Monitor Registry Keys for Print Monitors]] * [[Documentation:ESSOC:detections:Detections#Reg_exe_manipulating_windows_services_registry_keys|Reg exe Manipulating Windows Services Registry Keys]] @@ -2625,10 +3352,18 @@ Monitor for activities and techniques associated with maintaining persistence on * [[Documentation:ESSOC:detections:Detections#Schtasks_used_for_forcing_a_reboot|Schtasks used for forcing a reboot]] +* [[Documentation:ESSOC:detections:Detections#Setting_credentials_via_dsinternals_modules|Setting Credentials via DSInternals modules]] + +* [[Documentation:ESSOC:detections:Detections#Setting_credentials_via_mimikatz_modules|Setting Credentials via Mimikatz modules]] + +* [[Documentation:ESSOC:detections:Detections#Setting_credentials_via_powersploit_modules|Setting Credentials via PowerSploit modules]] + * [[Documentation:ESSOC:detections:Detections#Shim_database_file_creation|Shim Database File Creation]] * [[Documentation:ESSOC:detections:Detections#Shim_database_installation_with_suspicious_parameters|Shim Database Installation With Suspicious Parameters]] +* [[Documentation:ESSOC:detections:Detections#Suspicious_scheduled_task_from_public_directory|Suspicious Scheduled Task from Public Directory]] + ====ATT&CK==== @@ -2645,6 +3380,38 @@ Monitor for activities and techniques associated with maintaining persistence on | Windows File and Directory Permissions Modification | Defense Evasion |- +| T1585 +| Establish Accounts +| Resource Development +|- +| T1078 +| Valid Accounts +| Defense Evasion, Initial Access, Persistence, Privilege Escalation +|- +| T1098 +| Account Manipulation +| Persistence +|- +| T1207 +| Rogue Domain Controller +| Defense Evasion +|- +| T1484 +| Domain Policy Modification +| Defense Evasion, Privilege Escalation +|- +| T1053 +| Scheduled Task/Job +| Execution, Persistence, Privilege Escalation +|- +| T1134 +| Access Token Manipulation +| Defense Evasion, Privilege Escalation +|- +| T1548 +| Abuse Elevation Control Mechanism +| Defense Evasion, Privilege Escalation +|- | T1547.010 | Port Monitors | Persistence, Privilege Escalation @@ -2672,6 +3439,10 @@ Monitor for activities and techniques associated with maintaining persistence on | T1053.005 | Scheduled Task | Execution, Persistence, Privilege Escalation +|- +| T1068 +| Exploitation for Privilege Escalation +| Privilege Escalation |} @@ -2679,8 +3450,12 @@ Monitor for activities and techniques associated with maintaining persistence on * Actions on Objectives +* Exploitation + * Installation +* Privilege Escalation + ====Reference==== @@ -2706,7 +3481,7 @@ Monitor for and investigate activities that may be associated with a Windows pri * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1068/ T1068], [https://attack.mitre.org/techniques/T1546.008/ T1546.008], [https://attack.mitre.org/techniques/T1546.012/ T1546.012], [https://attack.mitre.org/techniques/T1204.002/ T1204.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1068/ T1068], [https://attack.mitre.org/techniques/T1134/ T1134], [https://attack.mitre.org/techniques/T1548/ T1548], [https://attack.mitre.org/techniques/T1546.008/ T1546.008], [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1098/ T1098], [https://attack.mitre.org/techniques/T1546.012/ T1546.012], [https://attack.mitre.org/techniques/T1204.002/ T1204.002] * '''Last Updated''': 2020-02-04
@@ -2716,8 +3491,12 @@ Monitor for and investigate activities that may be associated with a Windows pri * [[Documentation:ESSOC:detections:Detections#Child_processes_of_spoolsv_exe|Child Processes of Spoolsv exe]] +* [[Documentation:ESSOC:detections:Detections#Illegal_privilege_elevation_via_mimikatz_modules|Illegal Privilege Elevation via Mimikatz modules]] + * [[Documentation:ESSOC:detections:Detections#Overwriting_accessibility_binaries|Overwriting Accessibility Binaries]] +* [[Documentation:ESSOC:detections:Detections#Probing_access_with_stolen_credentials_via_powersploit_modules|Probing Access with Stolen Credentials via PowerSploit modules]] + * [[Documentation:ESSOC:detections:Detections#Registry_keys_used_for_privilege_escalation|Registry Keys Used For Privilege Escalation]] * [[Documentation:ESSOC:detections:Detections#Uncommon_processes_on_endpoint|Uncommon Processes On Endpoint]] @@ -2734,10 +3513,26 @@ Monitor for and investigate activities that may be associated with a Windows pri | Exploitation for Privilege Escalation | Privilege Escalation |- +| T1134 +| Access Token Manipulation +| Defense Evasion, Privilege Escalation +|- +| T1548 +| Abuse Elevation Control Mechanism +| Defense Evasion, Privilege Escalation +|- | T1546.008 | Accessibility Features | Persistence, Privilege Escalation |- +| T1078 +| Valid Accounts +| Defense Evasion, Initial Access, Persistence, Privilege Escalation +|- +| T1098 +| Account Manipulation +| Persistence +|- | T1546.012 | Image File Execution Options Injection | Persistence, Privilege Escalation @@ -3216,6 +4011,67 @@ Monitor your AWS EC2 instances for activities related to cryptojacking/cryptomin * https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf +''version'': 1 +
+
+ +---- + +===Aws iam privilege escalation=== +This analytic story contains detections that query your AWS Cloudtrail for activities related to privilege escalation. + +* '''Product''': Splunk Security Analytics for AWS, Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078.004/ T1078.004], [https://attack.mitre.org/techniques/T1136.003/ T1136.003] +* '''Last Updated''': 2021-03-08 + +
+
+ +====Detection Profile==== + +* [[Documentation:ESSOC:detections:Detections#Aws_create_policy_version_to_allow_all_resources|AWS Create Policy Version to allow all resources]] + +* [[Documentation:ESSOC:detections:Detections#Aws_createaccesskey|AWS CreateAccessKey]] + +* [[Documentation:ESSOC:detections:Detections#Aws_createloginprofile|AWS CreateLoginProfile]] + +* [[Documentation:ESSOC:detections:Detections#Aws_setdefaultpolicyversion|AWS SetDefaultPolicyVersion]] + +* [[Documentation:ESSOC:detections:Detections#Aws_updateloginprofile|AWS UpdateLoginProfile]] + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1078.004 +| Cloud Accounts +| Defense Evasion, Initial Access, Persistence, Privilege Escalation +|- +| T1136.003 +| Cloud Account +| Persistence +|} + + +====Kill Chain Phase==== + +* Actions on Objectives + + +====Reference==== + +* https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation/ + +* https://www.cyberark.com/resources/threat-research-blog/the-cloud-shadow-admin-threat-10-permissions-to-protect + +* https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws + + ''version'': 1
@@ -3477,7 +4333,7 @@ This analytical story addresses events that indicate abuse of cloud federated cr * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1003.001/ T1003.001], [https://attack.mitre.org/techniques/T1136.003/ T1136.003], [https://attack.mitre.org/techniques/T1556/ T1556], [https://attack.mitre.org/techniques/T1546.012/ T1546.012], [https://attack.mitre.org/techniques/T1204.002/ T1204.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1078/ T1078], [https://attack.mitre.org/techniques/T1003.001/ T1003.001], [https://attack.mitre.org/techniques/T1136.003/ T1136.003], [https://attack.mitre.org/techniques/T1556/ T1556], [https://attack.mitre.org/techniques/T1546.012/ T1546.012] * '''Last Updated''': 2021-01-26
@@ -3507,8 +4363,6 @@ This analytical story addresses events that indicate abuse of cloud federated cr * [[Documentation:ESSOC:detections:Detections#Registry_keys_used_for_privilege_escalation|Registry Keys Used For Privilege Escalation]] -* [[Documentation:ESSOC:detections:Detections#Uncommon_processes_on_endpoint|Uncommon Processes On Endpoint]] - ====ATT&CK==== @@ -3536,10 +4390,6 @@ This analytical story addresses events that indicate abuse of cloud federated cr | T1546.012 | Image File Execution Options Injection | Persistence, Privilege Escalation -|- -| T1204.002 -| Malicious File -| Execution |} @@ -4431,6 +5281,113 @@ Identify unusual changes to your AWS EC2 instances that may indicate malicious a ==Malware== +===Clop ransomware=== +Leverage searches that allow you to detect and investigate unusual activities that might relate to the Clop ransomware, including looking for file writes associated with Clope, encrypting network shares, deleting and resizing shadow volume storage, registry key modification, deleting of security logs, and more. + +* '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud +* '''Datamodel''': Endpoint +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1204/ T1204], [https://attack.mitre.org/techniques/T1543/ T1543], [https://attack.mitre.org/techniques/T1485/ T1485], [https://attack.mitre.org/techniques// ], [https://attack.mitre.org/techniques/T1490/ T1490], [https://attack.mitre.org/techniques/T1486/ T1486], [https://attack.mitre.org/techniques/T1003.002/ T1003.002], [https://attack.mitre.org/techniques/T1070.001/ T1070.001] +* '''Last Updated''': 2021-03-17 + +
+
+ +====Detection Profile==== + +* [[Documentation:ESSOC:detections:Detections#Clop_common_exec_parameter|Clop Common Exec Parameter]] + +* [[Documentation:ESSOC:detections:Detections#Clop_ransomware_known_service_name|Clop Ransomware Known Service Name]] + +* [[Documentation:ESSOC:detections:Detections#Common_ransomware_extensions|Common Ransomware Extensions]] + +* [[Documentation:ESSOC:detections:Detections#Common_ransomware_notes|Common Ransomware Notes]] + +* [[Documentation:ESSOC:detections:Detections#Create_service_in_suspicious_file_path|Create Service In Suspicious File Path]] + +* [[Documentation:ESSOC:detections:Detections#Deleting_shadow_copies|Deleting Shadow Copies]] + +* [[Documentation:ESSOC:detections:Detections#High_file_deletion_frequency|High File Deletion Frequency]] + +* [[Documentation:ESSOC:detections:Detections#High_process_termination_frequency|High Process Termination Frequency]] + +* [[Documentation:ESSOC:detections:Detections#Process_deleting_its_process_file_path|Process Deleting Its Process File Path]] + +* [[Documentation:ESSOC:detections:Detections#Ransomware_notes_bulk_creation|Ransomware Notes bulk creation]] + +* [[Documentation:ESSOC:detections:Detections#Resize_shadowstorage_volume|Resize ShadowStorage volume]] + +* [[Documentation:ESSOC:detections:Detections#Suspicious_wevtutil_usage|Suspicious wevtutil Usage]] + +* [[Documentation:ESSOC:detections:Detections#Windows_event_log_cleared|Windows Event Log Cleared]] + + + +====ATT&CK==== +{| +! style="text-align:left;"| ID +! Technique +! Tactic +|- +| T1204 +| User Execution +| Execution +|- +| T1543 +| Create or Modify System Process +| Persistence, Privilege Escalation +|- +| T1485 +| Data Destruction +| Impact +|- +| +| +| +|- +| T1490 +| Inhibit System Recovery +| Impact +|- +| T1486 +| Data Encrypted for Impact +| Impact +|- +| T1003.002 +| Security Account Manager +| Credential Access +|- +| T1070.001 +| Clear Windows Event Logs +| Defense Evasion +|} + + +====Kill Chain Phase==== + +* Actions on Objectives + +* Exploitation + +* Obfuscation + +* Privilege Escalation + + +====Reference==== + +* https://www.hhs.gov/sites/default/files/analyst-note-cl0p-tlp-white.pdf + +* https://securityaffairs.co/wordpress/115250/data-breach/qualys-clop-ransomware.html + +* https://www.darkreading.com/attacks-breaches/qualys-is-the-latest-victim-of-accellion-data-breach/d/d-id/1340323 + + +''version'': 1 +
+
+ +---- + ===Coldroot macos rat=== Leverage searches that allow you to detect and investigate unusual activities that relate to the ColdRoot Remote Access Trojan that affects MacOS. An example of some of these activities are changing sensative binaries in the MacOS sub-system, detecting process names and executables associated with the RAT, detecting when a keyboard tab is installed on a MacOS machine and more. @@ -4844,7 +5801,7 @@ Detect activities and various techniques associated with the Orangeworm Attack G * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1569.002/ T1569.002], [https://attack.mitre.org/techniques/T1059.001/ T1059.001], [https://attack.mitre.org/techniques/T1059.003/ T1059.003], [https://attack.mitre.org/techniques/T1574.011/ T1574.011], [https://attack.mitre.org/techniques/T1543.003/ T1543.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1569.002/ T1569.002], [https://attack.mitre.org/techniques/T1059.001/ T1059.001], [https://attack.mitre.org/techniques/T1059.003/ T1059.003], [https://attack.mitre.org/techniques/T1055/ T1055], [https://attack.mitre.org/techniques/T1106/ T1106], [https://attack.mitre.org/techniques/T1569/ T1569], [https://attack.mitre.org/techniques/T1574.011/ T1574.011], [https://attack.mitre.org/techniques/T1543.003/ T1543.003] * '''Last Updated''': 2020-01-22
@@ -4878,6 +5835,18 @@ Detect activities and various techniques associated with the Orangeworm Attack G | Windows Command Shell | Execution |- +| T1055 +| Process Injection +| Defense Evasion, Privilege Escalation +|- +| T1106 +| Native API +| Execution +|- +| T1569 +| System Services +| Execution +|- | T1574.011 | Services Registry Permissions Weakness | Defense Evasion, Persistence, Privilege Escalation @@ -4915,7 +5884,7 @@ Leverage searches that allow you to detect and investigate unusual activities th * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint, Network_Traffic -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1490/ T1490], [https://attack.mitre.org/techniques/T1485/ T1485], [https://attack.mitre.org/techniques/T1482/ T1482], [https://attack.mitre.org/techniques/T1048/ T1048], [https://attack.mitre.org/techniques/T1547.001/ T1547.001], [https://attack.mitre.org/techniques/T1021.001/ T1021.001], [https://attack.mitre.org/techniques/T1047/ T1047], [https://attack.mitre.org/techniques/T1486/ T1486], [https://attack.mitre.org/techniques/T1021.002/ T1021.002], [https://attack.mitre.org/techniques/T1053.005/ T1053.005], [https://attack.mitre.org/techniques/T1070.001/ T1070.001], [https://attack.mitre.org/techniques/T1036.003/ T1036.003], [https://attack.mitre.org/techniques/T1071.001/ T1071.001], [https://attack.mitre.org/techniques/T1070/ T1070], [https://attack.mitre.org/techniques/T1562.001/ T1562.001], [https://attack.mitre.org/techniques/T1489/ T1489], [https://attack.mitre.org/techniques/T1059.003/ T1059.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1490/ T1490], [https://attack.mitre.org/techniques/T1485/ T1485], [https://attack.mitre.org/techniques/T1482/ T1482], [https://attack.mitre.org/techniques/T1048/ T1048], [https://attack.mitre.org/techniques/T1547.001/ T1547.001], [https://attack.mitre.org/techniques/T1021.001/ T1021.001], [https://attack.mitre.org/techniques/T1047/ T1047], [https://attack.mitre.org/techniques/T1486/ T1486], [https://attack.mitre.org/techniques/T1059.003/ T1059.003], [https://attack.mitre.org/techniques/T1021.002/ T1021.002], [https://attack.mitre.org/techniques/T1053.005/ T1053.005], [https://attack.mitre.org/techniques/T1070.001/ T1070.001], [https://attack.mitre.org/techniques/T1036.003/ T1036.003], [https://attack.mitre.org/techniques/T1071.001/ T1071.001], [https://attack.mitre.org/techniques/T1070/ T1070], [https://attack.mitre.org/techniques/T1562.001/ T1562.001], [https://attack.mitre.org/techniques/T1489/ T1489] * '''Last Updated''': 2020-02-04
@@ -4947,6 +5916,8 @@ Leverage searches that allow you to detect and investigate unusual activities th * [[Documentation:ESSOC:detections:Detections#Spike_in_file_writes|Spike in File Writes]] +* [[Documentation:ESSOC:detections:Detections#Suspicious_scheduled_task_from_public_directory|Suspicious Scheduled Task from Public Directory]] + * [[Documentation:ESSOC:detections:Detections#Suspicious_wevtutil_usage|Suspicious wevtutil Usage]] * [[Documentation:ESSOC:detections:Detections#System_processes_run_from_unexpected_locations|System Processes Run From Unexpected Locations]] @@ -5003,6 +5974,10 @@ Leverage searches that allow you to detect and investigate unusual activities th | Data Encrypted for Impact | Impact |- +| T1059.003 +| Windows Command Shell +| Execution +|- | T1021.002 | SMB/Windows Admin Shares | Lateral Movement @@ -5034,10 +6009,6 @@ Leverage searches that allow you to detect and investigate unusual activities th | T1489 | Service Stop | Impact -|- -| T1059.003 -| Windows Command Shell -| Execution |} @@ -5049,6 +6020,10 @@ Leverage searches that allow you to detect and investigate unusual activities th * Delivery +* Exploitation + +* Privilege Escalation + ====Reference==== @@ -5117,7 +6092,7 @@ Leverage searches that allow you to detect and investigate unusual activities th * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint, Network_Traffic -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1490/ T1490], [https://attack.mitre.org/techniques/T1485/ T1485], [https://attack.mitre.org/techniques/T1482/ T1482], [https://attack.mitre.org/techniques/T1048/ T1048], [https://attack.mitre.org/techniques/T1547.001/ T1547.001], [https://attack.mitre.org/techniques/T1021.001/ T1021.001], [https://attack.mitre.org/techniques/T1047/ T1047], [https://attack.mitre.org/techniques/T1486/ T1486], [https://attack.mitre.org/techniques/T1021.002/ T1021.002], [https://attack.mitre.org/techniques/T1053.005/ T1053.005], [https://attack.mitre.org/techniques/T1070.001/ T1070.001], [https://attack.mitre.org/techniques/T1036.003/ T1036.003], [https://attack.mitre.org/techniques/T1071.001/ T1071.001], [https://attack.mitre.org/techniques/T1070/ T1070], [https://attack.mitre.org/techniques/T1562.001/ T1562.001], [https://attack.mitre.org/techniques/T1489/ T1489], [https://attack.mitre.org/techniques/T1059.003/ T1059.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1490/ T1490], [https://attack.mitre.org/techniques/T1485/ T1485], [https://attack.mitre.org/techniques/T1482/ T1482], [https://attack.mitre.org/techniques/T1048/ T1048], [https://attack.mitre.org/techniques/T1547.001/ T1547.001], [https://attack.mitre.org/techniques/T1021.001/ T1021.001], [https://attack.mitre.org/techniques/T1047/ T1047], [https://attack.mitre.org/techniques/T1486/ T1486], [https://attack.mitre.org/techniques/T1059.003/ T1059.003], [https://attack.mitre.org/techniques/T1021.002/ T1021.002], [https://attack.mitre.org/techniques/T1053.005/ T1053.005], [https://attack.mitre.org/techniques/T1070.001/ T1070.001], [https://attack.mitre.org/techniques/T1036.003/ T1036.003], [https://attack.mitre.org/techniques/T1071.001/ T1071.001], [https://attack.mitre.org/techniques/T1070/ T1070], [https://attack.mitre.org/techniques/T1562.001/ T1562.001], [https://attack.mitre.org/techniques/T1489/ T1489] * '''Last Updated''': 2020-11-06
@@ -5127,6 +6102,8 @@ Leverage searches that allow you to detect and investigate unusual activities th * [[Documentation:ESSOC:detections:Detections#Bcdedit_failure_recovery_modification|BCDEdit Failure Recovery Modification]] +* [[Documentation:ESSOC:detections:Detections#Common_ransomware_extensions|Common Ransomware Extensions]] + * [[Documentation:ESSOC:detections:Detections#Common_ransomware_notes|Common Ransomware Notes]] * [[Documentation:ESSOC:detections:Detections#Nltest_domain_trust_discovery|NLTest Domain Trust Discovery]] @@ -5137,8 +6114,12 @@ Leverage searches that allow you to detect and investigate unusual activities th * [[Documentation:ESSOC:detections:Detections#Ryuk_test_files_detected|Ryuk Test Files Detected]] +* [[Documentation:ESSOC:detections:Detections#Ryuk_wake_on_lan_command|Ryuk Wake on LAN Command]] + * [[Documentation:ESSOC:detections:Detections#Spike_in_file_writes|Spike in File Writes]] +* [[Documentation:ESSOC:detections:Detections#Suspicious_scheduled_task_from_public_directory|Suspicious Scheduled Task from Public Directory]] + * [[Documentation:ESSOC:detections:Detections#Wbadmin_delete_system_backups|WBAdmin Delete System Backups]] * [[Documentation:ESSOC:detections:Detections#Windows_disableantispyware_registry|Windows DisableAntiSpyware Registry]] @@ -5187,6 +6168,10 @@ Leverage searches that allow you to detect and investigate unusual activities th | Data Encrypted for Impact | Impact |- +| T1059.003 +| Windows Command Shell +| Execution +|- | T1021.002 | SMB/Windows Admin Shares | Lateral Movement @@ -5218,10 +6203,6 @@ Leverage searches that allow you to detect and investigate unusual activities th | T1489 | Service Stop | Impact -|- -| T1059.003 -| Windows Command Shell -| Execution |} @@ -5233,6 +6214,10 @@ Leverage searches that allow you to detect and investigate unusual activities th * Exploitation +* Lateral Movement + +* Privilege Escalation + * Reconnaissance @@ -5361,7 +6346,7 @@ Quickly identify systems running new or unusual processes in your environment th * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1016/ T1016], [https://attack.mitre.org/techniques/T1218.011/ T1218.011], [https://attack.mitre.org/techniques/T1036.003/ T1036.003], [https://attack.mitre.org/techniques/T1204.002/ T1204.002] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1003/ T1003], [https://attack.mitre.org/techniques/T1016/ T1016], [https://attack.mitre.org/techniques/T1059/ T1059], [https://attack.mitre.org/techniques// ], [https://attack.mitre.org/techniques/T1202/ T1202], [https://attack.mitre.org/techniques/T1053/ T1053], [https://attack.mitre.org/techniques/T1203/ T1203], [https://attack.mitre.org/techniques/T1072/ T1072], [https://attack.mitre.org/techniques/T1218.011/ T1218.011], [https://attack.mitre.org/techniques/T1036.003/ T1036.003], [https://attack.mitre.org/techniques/T1204.002/ T1204.002] * '''Last Updated''': 2020-02-04
@@ -5369,10 +6354,26 @@ Quickly identify systems running new or unusual processes in your environment th ====Detection Profile==== +* [[Documentation:ESSOC:detections:Detections#Credential_extraction_indicative_of_fgdump_and_cachedump_with_s_option|Credential Extraction indicative of FGDump and CacheDump with s option]] + +* [[Documentation:ESSOC:detections:Detections#Credential_extraction_indicative_of_fgdump_and_cachedump_with_v_option|Credential Extraction indicative of FGDump and CacheDump with v option]] + +* [[Documentation:ESSOC:detections:Detections#Credential_extraction_indicative_of_use_of_mimikatz_modules|Credential Extraction indicative of use of Mimikatz modules]] + +* [[Documentation:ESSOC:detections:Detections#Credential_extraction_native_microsoft_debuggers_peek_into_the_kernel|Credential Extraction native Microsoft debuggers peek into the kernel]] + +* [[Documentation:ESSOC:detections:Detections#Credential_extraction_native_microsoft_debuggers_via_z_command_line_option|Credential Extraction native Microsoft debuggers via z command line option]] + * [[Documentation:ESSOC:detections:Detections#Detect_rare_executables|Detect Rare Executables]] * [[Documentation:ESSOC:detections:Detections#Detect_processes_used_for_system_network_configuration_discovery|Detect processes used for System Network Configuration Discovery]] +* [[Documentation:ESSOC:detections:Detections#First_time_seen_command_line_argument|First time seen command line argument]] + +* [[Documentation:ESSOC:detections:Detections#More_than_usual_number_of_lolbas_applications_in_short_time_period|More than usual number of LOLBAS applications in short time period]] + +* [[Documentation:ESSOC:detections:Detections#Rare_parent-child_process_relationship|Rare Parent-Child Process Relationship]] + * [[Documentation:ESSOC:detections:Detections#Rundll_loading_dll_by_ordinal|RunDLL Loading DLL By Ordinal]] * [[Documentation:ESSOC:detections:Detections#System_processes_run_from_unexpected_locations|System Processes Run From Unexpected Locations]] @@ -5391,10 +6392,38 @@ Quickly identify systems running new or unusual processes in your environment th ! Technique ! Tactic |- +| T1003 +| OS Credential Dumping +| Credential Access +|- | T1016 | System Network Configuration Discovery | Discovery |- +| T1059 +| Command and Scripting Interpreter +| Execution +|- +| +| +| +|- +| T1202 +| Indirect Command Execution +| Defense Evasion +|- +| T1053 +| Scheduled Task/Job +| Execution, Persistence, Privilege Escalation +|- +| T1203 +| Exploitation for Client Execution +| Execution +|- +| T1072 +| Software Deployment Tools +| Execution, Lateral Movement +|- | T1218.011 | Rundll32 | Defense Evasion @@ -5415,6 +6444,8 @@ Quickly identify systems running new or unusual processes in your environment th * Command and Control +* Exploitation + * Installation @@ -5493,7 +6524,7 @@ Windows services are often used by attackers for persistence and the ability to * '''Product''': Splunk Enterprise, Splunk Enterprise Security, Splunk Cloud * '''Datamodel''': Endpoint -* '''ATT&CK''': [https://attack.mitre.org/techniques/T1569.002/ T1569.002], [https://attack.mitre.org/techniques/T1059.001/ T1059.001], [https://attack.mitre.org/techniques/T1059.003/ T1059.003], [https://attack.mitre.org/techniques/T1574.011/ T1574.011], [https://attack.mitre.org/techniques/T1543.003/ T1543.003] +* '''ATT&CK''': [https://attack.mitre.org/techniques/T1569.002/ T1569.002], [https://attack.mitre.org/techniques/T1059.001/ T1059.001], [https://attack.mitre.org/techniques/T1059.003/ T1059.003], [https://attack.mitre.org/techniques/T1055/ T1055], [https://attack.mitre.org/techniques/T1106/ T1106], [https://attack.mitre.org/techniques/T1569/ T1569], [https://attack.mitre.org/techniques/T1574.011/ T1574.011], [https://attack.mitre.org/techniques/T1543.003/ T1543.003] * '''Last Updated''': 2017-11-02
@@ -5503,6 +6534,10 @@ Windows services are often used by attackers for persistence and the ability to * [[Documentation:ESSOC:detections:Detections#First_time_seen_running_windows_service|First Time Seen Running Windows Service]] +* [[Documentation:ESSOC:detections:Detections#Illegal_service_and_process_control_via_mimikatz_modules|Illegal Service and Process Control via Mimikatz modules]] + +* [[Documentation:ESSOC:detections:Detections#Illegal_service_and_process_control_via_powersploit_modules|Illegal Service and Process Control via PowerSploit modules]] + * [[Documentation:ESSOC:detections:Detections#Reg_exe_manipulating_windows_services_registry_keys|Reg exe Manipulating Windows Services Registry Keys]] * [[Documentation:ESSOC:detections:Detections#Sc_exe_manipulating_windows_services|Sc exe Manipulating Windows Services]] @@ -5527,6 +6562,18 @@ Windows services are often used by attackers for persistence and the ability to | Windows Command Shell | Execution |- +| T1055 +| Process Injection +| Defense Evasion, Privilege Escalation +|- +| T1106 +| Native API +| Execution +|- +| T1569 +| System Services +| Execution +|- | T1574.011 | Services Registry Permissions Weakness | Defense Evasion, Persistence, Privilege Escalation @@ -5776,7 +6823,7 @@ Reduce the risk of CVE-2018-11409, an information disclosure vulnerability withi '' ############# # Automatically generated by doc_gen.py in https://github.com/splunk/security_content -# On Date: 2021-03-24 17:37:01.248549 UTC +# On Date: 2021-03-25 19:28:46.265272 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# diff --git a/package/app.manifest b/package/app.manifest index 4d24968033..d49a2b3d50 100644 --- a/package/app.manifest +++ b/package/app.manifest @@ -5,7 +5,7 @@ "id": { "group": null, "name": "DA-ESS-ContentUpdate", - "version": "3.17.0" + "version": "3.18.0" }, "author": [ { diff --git a/package/default/analytic_stories.conf b/package/default/analytic_stories.conf index cca07d1910..18c521dae0 100644 --- a/package/default/analytic_stories.conf +++ b/package/default/analytic_stories.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security_content -# On Date: 2021-03-12T17:19:06 UTC +# On Date: 2021-03-25T19:21:00 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# @@ -34,8 +34,8 @@ version = 1 reference = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf"] detection_searches = ["ESCU - Abnormally High AWS Instances Launched by User - MLTK - Rule", "ESCU - Abnormally High AWS Instances Launched by User - Rule", "ESCU - EC2 Instance Started In Previously Unseen Region - Rule", "ESCU - EC2 Instance Started With Previously Unseen AMI - Rule", "ESCU - EC2 Instance Started With Previously Unseen Instance Type - Rule", "ESCU - EC2 Instance Started With Previously Unseen User - Rule"] mappings = {"cis20": ["CIS 1", "CIS 12", "CIS 13"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1078.004", "T1535"], "nist": ["DE.AE", "DE.DP", "ID.AM"]} -investigative_searches = ["ESCU - Get Notable History - Response Task", "ESCU - Investigate AWS activities via region name - Response Task", "ESCU - Get EC2 Launch Details - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get EC2 Instance Details by instanceId - Response Task"] -support_searches = ["ESCU - Baseline of Excessive AWS Instances Launched by User - MLTK", "ESCU - Previously Seen EC2 Launches By User", "ESCU - Previously Seen EC2 AMIs", "ESCU - Previously Seen EC2 Instance Types", "ESCU - Previously Seen AWS Regions"] +investigative_searches = ["ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get EC2 Instance Details by instanceId - Response Task", "ESCU - Investigate AWS activities via region name - Response Task", "ESCU - Get EC2 Launch Details - Response Task", "ESCU - Get Notable History - Response Task"] +support_searches = ["ESCU - Previously Seen AWS Regions", "ESCU - Previously Seen EC2 Launches By User", "ESCU - Baseline of Excessive AWS Instances Launched by User - MLTK", "ESCU - Previously Seen EC2 Instance Types", "ESCU - Previously Seen EC2 AMIs"] data_models = [] providing_technologies = none description = Monitor your AWS EC2 instances for activities related to cryptojacking/cryptomining. New instances that originate from previously unseen regions, users who launch abnormally high numbers of instances, or EC2 instances started by previously unseen users are just a few examples of potentially malicious behavior. @@ -44,6 +44,22 @@ Cryptojacking has attracted an increasing amount of media attention since its ex When malicious miners appropriate a cloud instance, often spinning up hundreds of new instances, the costs can become astronomical for the account holder. So, it is critically important to monitor your systems for suspicious activities that could indicate that your network has been infiltrated. \ This Analytic Story is focused on detecting suspicious new instances in your EC2 environment to help prevent such a disaster. It contains detection searches that will detect when a previously unused instance type or AMI is used. It also contains support searches to build lookup files to ensure proper execution of the detection searches. +[AWS IAM Privilege Escalation] +category = Cloud Security +creation_date = 2021-03-08 +modification_date = 2021-03-08 +id = ced74200-8465-4bc3-bd2c-22782eec6750 +version = 1 +reference = ["https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation/", "https://www.cyberark.com/resources/threat-research-blog/the-cloud-shadow-admin-threat-10-permissions-to-protect", "https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws"] +detection_searches = ["ESCU - AWS Create Policy Version to allow all resources - Rule", "ESCU - AWS CreateAccessKey - Rule", "ESCU - AWS CreateLoginProfile - Rule", "ESCU - AWS SetDefaultPolicyVersion - Rule", "ESCU - AWS UpdateLoginProfile - Rule"] +mappings = {"cis20": ["CIS 13"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1078.004", "T1136.003"], "nist": ["DE.CM", "PR.AC", "PR.DS"]} +investigative_searches = [] +support_searches = [] +data_models = [] +providing_technologies = none +description = This analytic story contains detections that query your AWS Cloudtrail for activities related to privilege escalation. +narrative = Amazon Web Services provides a neat feature called Identity and Access Management (IAM) that enables organizations to manage various AWS services and resources in a secure way. All IAM users have roles, groups and policies associated with them which governs and sets permissions to allow a user to access specific restrictions. \ However, if these IAM policies are misconfigured and have specific combinations of weak permissions; it can allow attackers to escalate their privileges and further compromise the organization. Rhino Security Labs have published comprehensive blogs detailing various AWS Escalation methods. By using this as an inspiration, Splunk’s research team wants to highlight how these attack vectors look in AWS Cloudtrail logs and provide you with detection queries to uncover these potentially malicious events via this Analytic Story. \ + [AWS Network ACL Activity] category = Cloud Security creation_date = 2018-05-21 @@ -53,8 +69,8 @@ version = 2 reference = ["https://docs.aws.amazon.com/AmazonVPC/latest/UserGuide/VPC_Appendix_NACLs.html", "https://aws.amazon.com/blogs/security/how-to-help-prepare-for-ddos-attacks-by-reducing-your-attack-surface/"] detection_searches = ["ESCU - AWS Network Access Control List Created with All Open Ports - Rule", "ESCU - AWS Network Access Control List Deleted - Rule", "ESCU - Detect Spike in Network ACL Activity - Rule", "ESCU - Detect Spike in blocked Outbound Traffic from your AWS - Rule"] mappings = {"cis20": ["CIS 11", "CIS 12"], "kill_chain_phases": ["Actions on Objectives", "Command and Control"], "mitre_attack": ["T1562.007"], "nist": ["DE.AE", "DE.CM", "DE.DP", "PR.AC"]} -investigative_searches = ["ESCU - Get DNS Server History for a host - Response Task", "ESCU - AWS Network Interface details via resourceId - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - AWS Network ACL Details from ID - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task"] -support_searches = ["ESCU - Baseline of Network ACL Activity by ARN", "ESCU - Baseline of blocked outbound traffic from AWS"] +investigative_searches = ["ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - AWS Network Interface details via resourceId - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - AWS Network ACL Details from ID - Response Task"] +support_searches = ["ESCU - Baseline of blocked outbound traffic from AWS", "ESCU - Baseline of Network ACL Activity by ARN"] data_models = [] providing_technologies = none description = Monitor your AWS network infrastructure for bad configurations and malicious activity. Investigative searches help you probe deeper, when the facts warrant it. @@ -69,7 +85,7 @@ version = 1 reference = ["https://aws.amazon.com/security-hub/features/"] detection_searches = ["ESCU - Detect Spike in AWS Security Hub Alerts for EC2 Instance - Rule", "ESCU - Detect Spike in AWS Security Hub Alerts for User - Rule"] mappings = {"cis20": ["CIS 13"], "nist": ["DE.AE", "DE.DP"]} -investigative_searches = ["ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get EC2 Launch Details - Response Task", "ESCU - Get EC2 Instance Details by instanceId - Response Task"] +investigative_searches = ["ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get EC2 Instance Details by instanceId - Response Task", "ESCU - Get EC2 Launch Details - Response Task"] support_searches = [] data_models = [] providing_technologies = none @@ -85,7 +101,7 @@ version = 1 reference = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf"] detection_searches = ["ESCU - AWS Cloud Provisioning From Previously Unseen City - Rule", "ESCU - AWS Cloud Provisioning From Previously Unseen Country - Rule", "ESCU - AWS Cloud Provisioning From Previously Unseen IP Address - Rule", "ESCU - AWS Cloud Provisioning From Previously Unseen Region - Rule"] mappings = {"cis20": ["CIS 1"], "mitre_attack": ["T1535"], "nist": ["ID.AM"]} -investigative_searches = ["ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - AWS Investigate Security Hub alerts by dest - Response Task", "ESCU - Get All AWS Activity From Region - Response Task", "ESCU - Get All AWS Activity From Country - Response Task", "ESCU - Get All AWS Activity From City - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task"] +investigative_searches = ["ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get All AWS Activity From City - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - AWS Investigate Security Hub alerts by dest - Response Task", "ESCU - Get All AWS Activity From Region - Response Task", "ESCU - Get All AWS Activity From Country - Response Task"] support_searches = ["ESCU - Previously Seen AWS Provisioning Activity Sources"] data_models = [] providing_technologies = none @@ -103,7 +119,7 @@ reference = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.p detection_searches = ["ESCU - Detect API activity from users without MFA - Rule", "ESCU - Detect AWS API Activities From Unapproved Accounts - Rule", "ESCU - Detect Spike in AWS API Activity - Rule", "ESCU - Detect Spike in Security Group Activity - Rule", "ESCU - Detect new API calls from user roles - Rule"] mappings = {"cis20": ["CIS 1", "CIS 16"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1078.004"], "nist": ["DE.CM", "DE.DP", "ID.AM", "PR.AC"]} investigative_searches = ["ESCU - Investigate AWS User Activities by user field - Response Task", "ESCU - Get Notable History - Response Task"] -support_searches = ["ESCU - Create a list of approved AWS service accounts", "ESCU - Baseline of API Calls per User ARN", "ESCU - Previously seen API call per user roles in CloudTrail", "ESCU - Baseline of Security Group Activity by ARN"] +support_searches = ["ESCU - Previously seen API call per user roles in CloudTrail", "ESCU - Create a list of approved AWS service accounts", "ESCU - Baseline of API Calls per User ARN", "ESCU - Baseline of Security Group Activity by ARN"] data_models = [] providing_technologies = none description = Detect and investigate dormant user accounts for your AWS environment that have become active again. Because inactive and ad-hoc accounts are common attack targets, it's critical to enable governance within your environment. @@ -182,7 +198,7 @@ version = 1 reference = ["https://www.zerofox.com/blog/what-is-digital-risk-monitoring/", "https://securingtomorrow.mcafee.com/consumer/family-safety/what-is-typosquatting/", "https://blog.malwarebytes.com/cybercrime/2016/06/explained-typosquatting/"] detection_searches = ["ESCU - Monitor DNS For Brand Abuse - Rule", "ESCU - Monitor Email For Brand Abuse - Rule", "ESCU - Monitor Web Traffic For Brand Abuse - Rule"] mappings = {"cis20": ["CIS 7"], "kill_chain_phases": ["Actions on Objectives", "Delivery"], "nist": ["PR.IP"]} -investigative_searches = ["ESCU - Get Email Info - Response Task", "ESCU - Get Emails From Specific Sender - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Get Notable History - Response Task"] +investigative_searches = ["ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Get Emails From Specific Sender - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Email Info - Response Task"] support_searches = ["ESCU - DNSTwist Domain Names"] data_models = ["Email", "Network_Resolution", "Web"] providing_technologies = none @@ -191,6 +207,22 @@ narrative = While you can educate your users and customers about the risks and t You can use our adaptation of `DNSTwist`, together with the support searches in this Analytic Story, to generate permutations of specified brands and external domains. Splunk can monitor email, DNS requests, and web traffic for these permutations and provide you with early warnings and situational awareness--powerful elements of an effective defense.\ Notable events will include IP addresses, URLs, and user data. Drilling down can provide you with even more actionable intelligence, including likely geographic information, contextual searches to help you scope the problem, and investigative searches. +[Clop Ransomware] +category = Malware +creation_date = 2021-03-17 +modification_date = 2021-03-17 +id = 5a6f6849-1a26-4fae-aa05-fa730556eeb6 +version = 1 +reference = ["https://www.hhs.gov/sites/default/files/analyst-note-cl0p-tlp-white.pdf", "https://securityaffairs.co/wordpress/115250/data-breach/qualys-clop-ransomware.html", "https://www.darkreading.com/attacks-breaches/qualys-is-the-latest-victim-of-accellion-data-breach/d/d-id/1340323"] +detection_searches = ["ESCU - Clop Common Exec Parameter - Rule", "ESCU - Clop Ransomware Known Service Name - Rule", "ESCU - Common Ransomware Extensions - Rule", "ESCU - Common Ransomware Notes - Rule", "ESCU - Create Service In Suspicious File Path - Rule", "ESCU - Deleting Shadow Copies - Rule", "ESCU - High File Deletion Frequency - Rule", "ESCU - High Process Termination Frequency - Rule", "ESCU - Process Deleting Its Process File Path - Rule", "ESCU - Ransomware Notes bulk creation - Rule", "ESCU - Resize ShadowStorage volume - Rule", "ESCU - Suspicious wevtutil Usage - Rule", "ESCU - Windows Event Log Cleared - Rule"] +mappings = {"cis20": ["CIS 10", "CIS 3", "CIS 5", "CIS 6", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Exploitation", "Obfuscation", "Privilege Escalation"], "mitre_attack": ["T1003.002", "T1070.001", "T1204", "T1485", "T1486", "T1490", "T1543", "T1569.001, T1569.002"], "nist": ["DE.AE", "DE.CM", "DE.DP", "PR.AC", "PR.AT", "PR.IP", "PR.PT"]} +investigative_searches = [] +support_searches = [] +data_models = ["Endpoint"] +providing_technologies = none +description = Leverage searches that allow you to detect and investigate unusual activities that might relate to the Clop ransomware, including looking for file writes associated with Clope, encrypting network shares, deleting and resizing shadow volume storage, registry key modification, deleting of security logs, and more. +narrative = Clop ransomware campaigns targeting healthcare and other vertical sectors, involve the use of ransomware payloads along with exfiltration of data per HHS bulletin. Malicious actors demand payment for ransome of data and threaten deletion and exposure of exfiltrated data. + [Cloud Cryptomining] category = Cloud Security creation_date = 2019-10-02 @@ -200,8 +232,8 @@ version = 1 reference = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf"] detection_searches = ["ESCU - Abnormally High Number Of Cloud Instances Launched - Rule", "ESCU - Cloud Compute Instance Created By Previously Unseen User - Rule", "ESCU - Cloud Compute Instance Created In Previously Unused Region - Rule", "ESCU - Cloud Compute Instance Created With Previously Unseen Image - Rule", "ESCU - Cloud Compute Instance Created With Previously Unseen Instance Type - Rule"] mappings = {"cis20": ["CIS 1", "CIS 12", "CIS 13"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1078.004", "T1535"], "nist": ["DE.AE", "DE.DP", "ID.AM"]} -investigative_searches = ["ESCU - Get Notable History - Response Task", "ESCU - AWS Investigate Security Hub alerts by dest - Response Task", "ESCU - Investigate AWS activities via region name - Response Task", "ESCU - Get EC2 Launch Details - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get EC2 Instance Details by instanceId - Response Task"] -support_searches = ["ESCU - Baseline Of Cloud Instances Launched", "ESCU - Previously Seen Cloud Compute Creations By User - Initial", "ESCU - Previously Seen Cloud Compute Instance Types - Initial", "ESCU - Previously Seen Cloud Compute Images - Initial", "ESCU - Baseline Of Cloud Instances Destroyed", "ESCU - Previously Seen Cloud Compute Creations By User - Update", "ESCU - Previously Seen Cloud Regions - Update", "ESCU - Previously Seen Cloud Regions - Initial", "ESCU - Previously Seen Cloud Compute Images - Update", "ESCU - Previously Seen Cloud Compute Instance Types - Update"] +investigative_searches = ["ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get EC2 Instance Details by instanceId - Response Task", "ESCU - Investigate AWS activities via region name - Response Task", "ESCU - AWS Investigate Security Hub alerts by dest - Response Task", "ESCU - Get EC2 Launch Details - Response Task", "ESCU - Get Notable History - Response Task"] +support_searches = ["ESCU - Previously Seen Cloud Compute Creations By User - Initial", "ESCU - Previously Seen Cloud Compute Instance Types - Update", "ESCU - Previously Seen Cloud Compute Images - Update", "ESCU - Previously Seen Cloud Regions - Update", "ESCU - Previously Seen Cloud Compute Instance Types - Initial", "ESCU - Previously Seen Cloud Compute Creations By User - Update", "ESCU - Baseline Of Cloud Instances Destroyed", "ESCU - Baseline Of Cloud Instances Launched", "ESCU - Previously Seen Cloud Regions - Initial", "ESCU - Previously Seen Cloud Compute Images - Initial"] data_models = ["Change"] providing_technologies = none description = Monitor your cloud compute instances for activities related to cryptojacking/cryptomining. New instances that originate from previously unseen regions, users who launch abnormally high numbers of instances, or compute instances started by previously unseen users are just a few examples of potentially malicious behavior. @@ -234,7 +266,7 @@ id = bcfd17e8-5461-400a-80a2-3b7d1459220c version = 1 reference = ["https://www.cobaltstrike.com/", "https://www.infocyte.com/blog/2020/09/02/cobalt-strike-the-new-favorite-among-thieves/", "https://bluescreenofjeff.com/2017-01-24-how-to-write-malleable-c2-profiles-for-cobalt-strike/", "https://blog.talosintelligence.com/2020/09/coverage-strikes-back-cobalt-strike-paper.html", "https://www.fireeye.com/blog/threat-research/2020/12/unauthorized-access-of-fireeye-red-team-tools.html", "https://github.com/MichaelKoczwara/Awesome-CobaltStrike-Defence", "https://github.com/zer0yu/Awesome-CobaltStrike"] detection_searches = ["ESCU - Cobalt Strike Named Pipes - Rule", "ESCU - Detect Regsvr32 Application Control Bypass - Rule", "ESCU - Suspicious DLLHost no Command Line Arguments - Rule", "ESCU - Suspicious GPUpdate no Command Line Arguments - Rule", "ESCU - Suspicious MSBuild Rename - Rule", "ESCU - Suspicious Rundll32 StartW - Rule", "ESCU - Suspicious Rundll32 no Command Line Arguments - Rule", "ESCU - Suspicious SearchProtocolHost no Command Line Arguments - Rule", "ESCU - Suspicious microsoft workflow compiler rename - Rule", "ESCU - Suspicious msbuild path - Rule"] -mappings = {"cis20": ["CIS 16", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Exploitation"], "mitre_attack": ["T1036.003", "T1055", "T1127, T1036.003", "T1127.001", "T1218.010", "T1218.011"], "nist": ["DE.CM", "PR.PT"]} +mappings = {"cis20": ["CIS 16", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Exploitation"], "mitre_attack": ["T1036.003", "T1055", "T1127", "T1127.001", "T1218.010", "T1218.011"], "nist": ["DE.CM", "PR.PT"]} investigative_searches = [] support_searches = [] data_models = ["Endpoint"] @@ -296,8 +328,8 @@ version = 1 reference = ["https://attack.mitre.org/wiki/Command_and_Control", "https://searchsecurity.techtarget.com/feature/Command-and-control-servers-The-puppet-masters-that-govern-malware"] detection_searches = ["ESCU - Clients Connecting to Multiple DNS Servers - Rule", "ESCU - DNS Query Length Outliers - MLTK - Rule", "ESCU - DNS Query Length With High Standard Deviation - Rule", "ESCU - DNS Query Requests Resolved by Unauthorized DNS Servers - Rule", "ESCU - Detect Large Outbound ICMP Packets - Rule", "ESCU - Detect Long DNS TXT Record Response - Rule", "ESCU - Detect Spike in blocked Outbound Traffic from your AWS - Rule", "ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - Detection of DNS Tunnels - Rule", "ESCU - Excessive DNS Failures - Rule", "ESCU - Prohibited Network Traffic Allowed - Rule", "ESCU - Protocol or Port Mismatch - Rule", "ESCU - TOR Traffic - Rule"] mappings = {"cis20": ["CIS 1", "CIS 11", "CIS 12", "CIS 13", "CIS 3", "CIS 8", "CIS 9"], "kill_chain_phases": ["Actions on Objectives", "Command and Control", "Delivery"], "mitre_attack": ["T1048", "T1048.003", "T1071.001", "T1071.004", "T1095", "T1189"], "nist": ["DE.AE", "DE.CM", "ID.AM", "PR.AC", "PR.DS", "PR.IP", "PR.PT"]} -investigative_searches = ["ESCU - Get DNS Server History for a host - Response Task", "ESCU - AWS Network Interface details via resourceId - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - AWS Network ACL Details from ID - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task"] -support_searches = ["ESCU - Baseline of DNS Query Length - MLTK", "ESCU - Baseline of blocked outbound traffic from AWS"] +investigative_searches = ["ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - AWS Network Interface details via resourceId - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - AWS Network ACL Details from ID - Response Task"] +support_searches = ["ESCU - Baseline of blocked outbound traffic from AWS", "ESCU - Baseline of DNS Query Length - MLTK"] data_models = ["Network_Resolution", "Network_Traffic"] providing_technologies = none description = Detect and investigate tactics, techniques, and procedures leveraged by attackers to establish and operate command and control channels. Implants installed by attackers on compromised endpoints use these channels to receive instructions and send data back to the malicious operators. @@ -346,7 +378,7 @@ version = 3 reference = ["https://attack.mitre.org/wiki/Technique/T1003", "https://cyberwardog.blogspot.com/2017/03/chronicles-of-threat-hunter-hunting-for.html"] detection_searches = ["ESCU - Access LSASS Memory for Dump Creation - Rule", "ESCU - Attempt To Set Default PowerShell Execution Policy To Unrestricted or Bypass - Rule", "ESCU - Attempted Credential Dump From Registry via Reg exe - Rule", "ESCU - Create Remote Thread into LSASS - Rule", "ESCU - Creation of Shadow Copy - Rule", "ESCU - Creation of Shadow Copy with wmic and powershell - Rule", "ESCU - Creation of lsass Dump with Taskmgr - Rule", "ESCU - Credential Dumping via Copy Command from Shadow Copy - Rule", "ESCU - Credential Dumping via Symlink to Shadow Copy - Rule", "ESCU - Detect Credential Dumping through LSASS access - Rule", "ESCU - Detect Mimikatz Using Loaded Images - Rule", "ESCU - Dump LSASS via comsvcs DLL - Rule", "ESCU - Dump LSASS via procdump - Rule", "ESCU - Dump LSASS via procdump Rename - Rule", "ESCU - Ntdsutil Export NTDS - Rule", "ESCU - Unsigned Image Loaded by LSASS - Rule"] mappings = {"cis20": ["CIS 16", "CIS 3", "CIS 5", "CIS 6", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Installation"], "mitre_attack": ["T1003.001", "T1003.002", "T1003.003", "T1059.001"], "nist": ["DE.AE", "DE.CM", "PR.AC", "PR.IP"]} -investigative_searches = ["ESCU - Investigate Failed Logins for Multiple Destinations - Response Task", "ESCU - Investigate Previous Unseen User - Response Task", "ESCU - Investigate Pass the Hash Attempts - Response Task", "ESCU - Investigate Pass the Ticket Attempts - Response Task"] +investigative_searches = ["ESCU - Investigate Pass the Ticket Attempts - Response Task", "ESCU - Investigate Previous Unseen User - Response Task", "ESCU - Investigate Failed Logins for Multiple Destinations - Response Task", "ESCU - Investigate Pass the Hash Attempts - Response Task"] support_searches = [] data_models = ["Endpoint"] providing_technologies = none @@ -364,8 +396,8 @@ version = 2 reference = ["https://www.us-cert.gov/ncas/alerts/TA18-074A"] detection_searches = ["ESCU - Create local admin accounts using net exe - Rule", "ESCU - Detect New Local Admin account - Rule", "ESCU - Detect Outbound SMB Traffic - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - First time seen command line argument - Rule", "ESCU - Malicious PowerShell Process - Execution Policy Bypass - Rule", "ESCU - Processes launching netsh - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - SMB Traffic Spike - Rule", "ESCU - Sc exe Manipulating Windows Services - Rule", "ESCU - Scheduled Task Deleted Or Created via CMD - Rule", "ESCU - Single Letter Process On Endpoint - Rule", "ESCU - Suspicious Reg exe Process - Rule"] mappings = {"cis20": ["CIS 12", "CIS 16", "CIS 2", "CIS 3", "CIS 5", "CIS 7", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Command and Control", "Installation"], "mitre_attack": ["T1021.002", "T1053.005", "T1059.001", "T1059.003", "T1071.002", "T1112", "T1136.001", "T1204.002", "T1543.003", "T1547.001", "T1562.004"], "nist": ["DE.AE", "DE.CM", "ID.AM", "PR.AC", "PR.AT", "PR.DS", "PR.IP", "PR.PT"]} -investigative_searches = ["ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Process File Activity - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Parent Process Info - Response Task"] -support_searches = ["ESCU - Previously seen command line arguments", "ESCU - Baseline of SMB Traffic - MLTK"] +investigative_searches = ["ESCU - Get Process File Activity - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] +support_searches = ["ESCU - Baseline of SMB Traffic - MLTK", "ESCU - Previously seen command line arguments"] data_models = ["Endpoint", "Network_Traffic"] providing_technologies = none description = Monitor for suspicious activities associated with DHS Technical Alert US-CERT TA18-074A. Some of the activities that adversaries used in these compromises included spearfishing attacks, malware, watering-hole domains, many and more. @@ -440,13 +472,29 @@ version = 1 reference = ["https://www.cisecurity.org/controls/data-protection/", "https://www.sans.org/reading-room/whitepapers/dns/splunk-detect-dns-tunneling-37022", "https://umbrella.cisco.com/blog/2013/04/15/on-the-trail-of-malicious-dynamic-dns-domains/"] detection_searches = ["ESCU - Detect USB device insertion - Rule", "ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - Detection of DNS Tunnels - Rule"] mappings = {"cis20": ["CIS 12", "CIS 13", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Command and Control", "Installation"], "mitre_attack": ["T1048.003", "T1189"], "nist": ["DE.AE", "DE.CM", "PR.DS", "PR.PT"]} -investigative_searches = ["ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task"] +investigative_searches = ["ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] support_searches = [] data_models = ["Change_Analysis", "Network_Resolution"] providing_technologies = none description = Fortify your data-protection arsenal--while continuing to ensure data confidentiality and integrity--with searches that monitor for and help you investigate possible signs of data exfiltration. narrative = Attackers can leverage a variety of resources to compromise or exfiltrate enterprise data. Common exfiltration techniques include remote-access channels via low-risk, high-payoff active-collections operations and close-access operations using insiders and removable media. While this Analytic Story is not a comprehensive listing of all the methods by which attackers can exfiltrate data, it provides a useful starting point. +[Deobfuscate-Decode Files or Information] +category = Adversary Tactics +creation_date = 2021-03-24 +modification_date = 2021-03-24 +id = 0bd01a54-8cbe-11eb-abcd-acde48001122 +version = 1 +reference = ["https://attack.mitre.org/techniques/T1140/"] +detection_searches = ["ESCU - CertUtil With Decode Argument - Rule"] +mappings = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1140"]} +investigative_searches = [] +support_searches = [] +data_models = ["Endpoint"] +providing_technologies = none +description = Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis. +narrative = An example of obfuscated files is `Certutil.exe` usage to encode a portable executable to a certificate file, which is base64 encoded, to hide the originating file. There are many utilities cross-platform to encode using XOR, using compressed .cab files to hide contents and scripting languages that may perform similar native Windows tasks. Triaging an event related will require the capability to review related process events and file modifications. Using a tool such as CyberChef will assist with identifying the encoding that was used, and potentially assist with decoding the contents. + [Detect Zerologon Attack] category = Adversary Tactics creation_date = 2020-09-18 @@ -473,7 +521,7 @@ reference = ["https://attack.mitre.org/wiki/Technique/T1089", "https://blog.malw detection_searches = ["ESCU - Attempt To Add Certificate To Untrusted Store - Rule", "ESCU - Attempt To Stop Security Service - Rule", "ESCU - Processes launching netsh - Rule", "ESCU - Sc exe Manipulating Windows Services - Rule", "ESCU - Suspicious Reg exe Process - Rule", "ESCU - Unload Sysmon Filter Driver - Rule"] mappings = {"cis20": ["CIS 3", "CIS 5", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Installation"], "mitre_attack": ["T1112", "T1543.003", "T1553.004", "T1562.001", "T1562.004"], "nist": ["DE.CM", "PR.AC", "PR.AT", "PR.IP", "PR.PT"]} investigative_searches = ["ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] -support_searches = ["ESCU - Previously seen command line arguments", "ESCU - Baseline of SMB Traffic - MLTK"] +support_searches = ["ESCU - Baseline of SMB Traffic - MLTK", "ESCU - Previously seen command line arguments"] data_models = ["Endpoint"] providing_technologies = none description = Looks for activities and techniques associated with the disabling of security tools on a Windows system, such as suspicious `reg.exe` processes, processes launching netsh, and many others. @@ -488,7 +536,7 @@ version = 2 reference = ["https://www.fireeye.com/blog/threat-research/2017/09/apt33-insights-into-iranian-cyber-espionage.html", "https://umbrella.cisco.com/blog/2013/04/15/on-the-trail-of-malicious-dynamic-dns-domains/", "http://www.noip.com/blog/2014/07/11/dynamic-dns-can-use-2/", "https://www.splunk.com/blog/2015/08/04/detecting-dynamic-dns-domains-in-splunk.html"] detection_searches = ["ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - Detect web traffic to dynamic domain providers - Rule"] mappings = {"cis20": ["CIS 12", "CIS 13", "CIS 7", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Command and Control"], "mitre_attack": ["T1071.001", "T1189"], "nist": ["DE.AE", "DE.CM", "DE.DP", "PR.DS", "PR.IP", "PR.PT"]} -investigative_searches = ["ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get Notable History - Response Task"] +investigative_searches = ["ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Notable History - Response Task"] support_searches = [] data_models = ["Network_Resolution", "Web"] providing_technologies = none @@ -504,7 +552,7 @@ version = 1 reference = ["https://www.us-cert.gov/ncas/alerts/TA18-201A", "https://www.first.org/resources/papers/conf2017/Advanced-Incident-Detection-and-Threat-Hunting-using-Sysmon-and-Splunk.pdf", "https://www.vkremez.com/2017/05/emotet-banking-trojan-malware-analysis.html"] detection_searches = ["ESCU - Detect Rare Executables - Rule", "ESCU - Detect Use of cmd exe to Launch Script Interpreters - Rule", "ESCU - Detection of tools built by NirSoft - Rule", "ESCU - Email Attachments With Lots Of Spaces - Rule", "ESCU - Prohibited Software On Endpoint - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - SMB Traffic Spike - Rule", "ESCU - Suspicious Email Attachment Extensions - Rule"] mappings = {"cis20": ["CIS 12", "CIS 2", "CIS 3", "CIS 7", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Command and Control", "Delivery", "Exploitation", "Installation"], "mitre_attack": ["T1021.002", "T1059.003", "T1072", "T1547.001", "T1566.001"], "nist": ["DE.AE", "DE.CM", "ID.AM", "PR.DS", "PR.IP", "PR.PT"]} -investigative_searches = ["ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get History Of Email Sources - Response Task"] +investigative_searches = ["ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] support_searches = ["ESCU - Baseline of SMB Traffic - MLTK"] data_models = ["Email", "Endpoint", "Network_Traffic"] providing_technologies = none @@ -574,8 +622,8 @@ version = 2 reference = ["https://www.us-cert.gov/HIDDEN-COBRA-North-Korean-Malicious-Cyber-Activity", "https://www.operationblockbuster.com/wp-content/uploads/2016/02/Operation-Blockbuster-Destructive-Malware-Report.pdf"] detection_searches = ["ESCU - Create or delete windows shares using net exe - Rule", "ESCU - DNS Query Length Outliers - MLTK - Rule", "ESCU - DNS Query Length With High Standard Deviation - Rule", "ESCU - Detect Outbound SMB Traffic - Rule", "ESCU - First time seen command line argument - Rule", "ESCU - Remote Desktop Network Traffic - Rule", "ESCU - Remote Desktop Process Running On System - Rule", "ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - SMB Traffic Spike - Rule", "ESCU - Suspicious File Write - Rule"] mappings = {"cis20": ["CIS 12", "CIS 16", "CIS 3", "CIS 8", "CIS 9"], "kill_chain_phases": ["Actions on Objectives", "Command and Control"], "mitre_attack": ["T1021.001", "T1021.002", "T1048.003", "T1059.001", "T1059.003", "T1070.005", "T1071.002", "T1071.004"], "nist": ["DE.AE", "DE.CM", "PR.AC", "PR.IP", "PR.PT"]} -investigative_searches = ["ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Outbound Emails to Hidden Cobra Threat Actors - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Investigate Successful Remote Desktop Authentications - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task"] -support_searches = ["ESCU - Previously seen command line arguments", "ESCU - Baseline of DNS Query Length - MLTK", "ESCU - Baseline of SMB Traffic - MLTK"] +investigative_searches = ["ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Investigate Successful Remote Desktop Authentications - Response Task", "ESCU - Get Outbound Emails to Hidden Cobra Threat Actors - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] +support_searches = ["ESCU - Baseline of SMB Traffic - MLTK", "ESCU - Baseline of DNS Query Length - MLTK", "ESCU - Previously seen command line arguments"] data_models = ["Endpoint", "Network_Resolution", "Network_Traffic"] providing_technologies = none description = Monitor for and investigate activities, including the creation or deletion of hidden shares and file writes, that may be evidence of infiltration by North Korean government-sponsored cybercriminals. Details of this activity were reported in DHS Report TA-18-149A. @@ -600,6 +648,22 @@ providing_technologies = none description = Detect evidence of tactics used to redirect traffic from a host to a destination other than the one intended--potentially one that is part of an adversary's attack infrastructure. An example is redirecting communications regarding patches and updates or misleading users into visiting a malicious website. narrative = Attackers will often attempt to manipulate client communications for nefarious purposes. In some cases, an attacker may endeavor to modify a local host file to redirect communications with resources (such as antivirus or system-update services) to prevent clients from receiving patches or updates. In other cases, an attacker might use this tactic to have the client connect to a site that looks like the intended site, but instead installs malware or collects information from the victim. Additionally, an attacker may redirect a victim in order to execute a MITM attack and observe communications. +[Ingress Tool Transfer] +category = Adversary Tactics +creation_date = 2021-03-24 +modification_date = 2021-03-24 +id = b3782036-8cbd-11eb-9d8e-acde48001122 +version = 1 +reference = ["https://attack.mitre.org/techniques/T1105/"] +detection_searches = ["ESCU - CertUtil Download With URLCache and Split Arguments - Rule", "ESCU - CertUtil Download With VerifyCtl and Split Arguments - Rule", "ESCU - Suspicious Curl Network Connection - Rule"] +mappings = {"kill_chain_phases": ["Actions on Objectives", "Exploitation"], "mitre_attack": ["T1105"]} +investigative_searches = [] +support_searches = [] +data_models = ["Endpoint"] +providing_technologies = none +description = Adversaries may transfer tools or other files from an external system into a compromised environment. Files may be copied from an external adversary controlled system through the command and control channel to bring tools into the victim network or through alternate protocols with another tool such as FTP. +narrative = Ingress tool transfer is a Technique under tactic Command and Control. Behaviors will include the use of living off the land binaries to download implants or binaries over alternate communication ports. It is imperative to baseline applications on endpoints to understand what generates network activity, to where, and what is its native behavior. These utilities, when abused, will write files to disk in world writeable paths.\ During triage, review the reputation of the remote public destination IP or domain. Capture any files written to disk and perform analysis. Review other parrallel processes for additional behaviors. + [JBoss Vulnerability] category = Vulnerability creation_date = 2017-09-14 @@ -639,7 +703,7 @@ version = 1 reference = ["https://github.com/splunk/cloud-datamodel-security-research"] detection_searches = ["ESCU - Amazon EKS Kubernetes Pod scan detection - Rule", "ESCU - Amazon EKS Kubernetes cluster scan detection - Rule", "ESCU - GCP Kubernetes cluster pod scan detection - Rule", "ESCU - GCP Kubernetes cluster scan detection - Rule", "ESCU - Kubernetes Azure pod scan fingerprint - Rule", "ESCU - Kubernetes Azure scan fingerprint - Rule"] mappings = {"kill_chain_phases": ["Reconnaissance"], "mitre_attack": ["T1526"]} -investigative_searches = ["ESCU - GCP Kubernetes activity by src ip - Response Task", "ESCU - Amazon EKS Kubernetes activity by src ip - Response Task", "ESCU - Get Notable History - Response Task"] +investigative_searches = ["ESCU - GCP Kubernetes activity by src ip - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Amazon EKS Kubernetes activity by src ip - Response Task"] support_searches = [] data_models = [] providing_technologies = none @@ -687,7 +751,7 @@ version = 2 reference = ["https://www.fireeye.com/blog/executive-perspective/2015/08/malware_lateral_move.html"] detection_searches = ["ESCU - Detect Activity Related to Pass the Hash Attacks - Rule", "ESCU - Kerberoasting spn request with RC4 encryption - Rule", "ESCU - Remote Desktop Network Traffic - Rule", "ESCU - Remote Desktop Process Running On System - Rule", "ESCU - Schtasks scheduling job on remote system - Rule"] mappings = {"cis20": ["CIS 16", "CIS 3", "CIS 5", "CIS 8", "CIS 9"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1021.001", "T1053.005", "T1550.002", "T1558.003"], "nist": ["DE.AE", "DE.CM", "PR.AC", "PR.AT", "PR.IP", "PR.PT"]} -investigative_searches = ["ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Investigate Successful Remote Desktop Authentications - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get History Of Email Sources - Response Task"] +investigative_searches = ["ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Investigate Successful Remote Desktop Authentications - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] support_searches = [] data_models = ["Endpoint", "Network_Traffic"] providing_technologies = none @@ -707,7 +771,7 @@ version = 4 reference = ["https://blogs.mcafee.com/mcafee-labs/malware-employs-powershell-to-infect-systems/", "https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/"] detection_searches = ["ESCU - Any Powershell DownloadFile - Rule", "ESCU - Any Powershell DownloadString - Rule", "ESCU - Attempt To Set Default PowerShell Execution Policy To Unrestricted or Bypass - Rule", "ESCU - Malicious PowerShell Process - Connect To Internet With Hidden Window - Rule", "ESCU - Malicious PowerShell Process - Encoded Command - Rule", "ESCU - Malicious PowerShell Process - Multiple Suspicious Command-Line Arguments - Rule", "ESCU - Malicious PowerShell Process With Obfuscation Techniques - Rule"] mappings = {"cis20": ["CIS 3", "CIS 7", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Command and Control", "Exploitation", "Installation"], "mitre_attack": ["T1027", "T1059.001"], "nist": ["DE.CM", "PR.IP", "PR.PT"]} -investigative_searches = ["ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Notable History - Response Task"] +investigative_searches = ["ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] support_searches = [] data_models = ["Endpoint"] providing_technologies = none @@ -784,7 +848,7 @@ reference = ["https://www.microsoft.com/security/blog/2021/03/04/goldmax-goldfin detection_searches = ["ESCU - Detect Outbound SMB Traffic - Rule", "ESCU - Detect Prohibited Applications Spawning cmd exe - Rule", "ESCU - Detect Rundll32 Inline HTA Execution - Rule", "ESCU - First Time Seen Running Windows Service - Rule", "ESCU - Malicious PowerShell Process - Encoded Command - Rule", "ESCU - Sc exe Manipulating Windows Services - Rule", "ESCU - Scheduled Task Deleted Or Created via CMD - Rule", "ESCU - Schtasks scheduling job on remote system - Rule", "ESCU - Sunburst Correlation DLL and Network Event - Rule", "ESCU - Supernova Webshell - Rule", "ESCU - TOR Traffic - Rule", "ESCU - Windows AdFind Exe - Rule"] mappings = {"cis20": ["CIS 12", "CIS 13", "CIS 18", "CIS 2", "CIS 3", "CIS 4", "CIS 5", "CIS 6", "CIS 7", "CIS 8", "CIS 9"], "kill_chain_phases": ["Actions on Objectives", "Command and Control", "Exfiltration", "Exploitation", "Installation"], "mitre_attack": ["T1018", "T1027", "T1053.005", "T1059.003", "T1071.001", "T1071.002", "T1203", "T1218.005", "T1505.003", "T1543.003", "T1569.002"], "nist": ["DE.AE", "DE.CM", "ID.AM", "ID.RA", "PR.AC", "PR.AT", "PR.DS", "PR.IP", "PR.PT"]} investigative_searches = [] -support_searches = ["ESCU - Previously Seen Running Windows Services - Update", "ESCU - Previously Seen Running Windows Services - Initial"] +support_searches = ["ESCU - Previously Seen Running Windows Services - Initial", "ESCU - Previously Seen Running Windows Services - Update"] data_models = ["Endpoint", "Network_Traffic", "Web"] providing_technologies = none description = Sunburst is a trojanized updates to SolarWinds Orion IT monitoring and management software. It was discovered by FireEye in December 2020. The actors behind this campaign gained access to numerous public and private organizations around the world. @@ -800,7 +864,7 @@ reference = ["https://docs.microsoft.com/en-us/previous-versions/tn-archive/bb49 detection_searches = ["ESCU - Processes created by netsh - Rule", "ESCU - Processes launching netsh - Rule"] mappings = {"cis20": ["CIS 8"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1562.004"], "nist": ["DE.CM", "PR.PT"]} investigative_searches = ["ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] -support_searches = ["ESCU - Previously seen command line arguments", "ESCU - Baseline of SMB Traffic - MLTK"] +support_searches = ["ESCU - Baseline of SMB Traffic - MLTK", "ESCU - Previously seen command line arguments"] data_models = ["Endpoint"] providing_technologies = none description = Detect activities and various techniques associated with the abuse of `netsh.exe`, which can disable local firewall settings or set up a remote connection to a host from an infected system. @@ -832,8 +896,8 @@ version = 2 reference = ["https://www.symantec.com/blogs/threat-intelligence/orangeworm-targets-healthcare-us-europe-asia", "https://www.infosecurity-magazine.com/news/healthcare-targeted-by-hacker/"] detection_searches = ["ESCU - First Time Seen Running Windows Service - Rule", "ESCU - First time seen command line argument - Rule", "ESCU - Sc exe Manipulating Windows Services - Rule"] mappings = {"cis20": ["CIS 2", "CIS 3", "CIS 5", "CIS 8", "CIS 9"], "kill_chain_phases": ["Actions on Objectives", "Command and Control", "Installation"], "mitre_attack": ["T1059.001", "T1059.003", "T1543.003", "T1569.002"], "nist": ["DE.AE", "DE.CM", "ID.AM", "PR.AC", "PR.AT", "PR.DS", "PR.IP", "PR.PT"]} -investigative_searches = ["ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Notable History - Response Task"] -support_searches = ["ESCU - Previously seen command line arguments", "ESCU - Previously Seen Running Windows Services - Update", "ESCU - Previously Seen Running Windows Services - Initial"] +investigative_searches = ["ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] +support_searches = ["ESCU - Previously Seen Running Windows Services - Initial", "ESCU - Previously Seen Running Windows Services - Update", "ESCU - Previously seen command line arguments"] data_models = ["Endpoint"] providing_technologies = none description = Detect activities and various techniques associated with the Orangeworm Attack Group, a group that frequently targets the healthcare industry. @@ -874,8 +938,8 @@ version = 1 reference = ["https://www.infosecurity-magazine.com/news/scope-of-mudcarp-attacks-highlight-1/", "http://blog.amossys.fr/badflick-is-not-so-bad.html"] detection_searches = ["ESCU - First time seen command line argument - Rule", "ESCU - Malicious PowerShell Process - Connect To Internet With Hidden Window - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Unusually Long Command Line - MLTK - Rule", "ESCU - Unusually Long Command Line - Rule"] mappings = {"cis20": ["CIS 3", "CIS 7", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Command and Control"], "mitre_attack": ["T1059.001", "T1059.003", "T1547.001"], "nist": ["DE.AE", "DE.CM", "PR.IP", "PR.PT"]} -investigative_searches = ["ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Notable History - Response Task"] -support_searches = ["ESCU - Previously seen command line arguments", "ESCU - Baseline of Command Line Length - MLTK"] +investigative_searches = ["ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] +support_searches = ["ESCU - Baseline of Command Line Length - MLTK", "ESCU - Previously seen command line arguments"] data_models = ["Endpoint"] providing_technologies = none description = Monitor your environment for suspicious behaviors that resemble the techniques employed by the MUDCARP threat group. @@ -917,7 +981,7 @@ version = 1 reference = ["http://www.novetta.com/2015/02/advanced-methods-to-detect-advanced-cyber-attacks-protocol-abuse/"] detection_searches = ["ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - Prohibited Network Traffic Allowed - Rule", "ESCU - Protocol or Port Mismatch - Rule", "ESCU - TOR Traffic - Rule"] mappings = {"cis20": ["CIS 12", "CIS 13", "CIS 8", "CIS 9"], "kill_chain_phases": ["Actions on Objectives", "Command and Control", "Delivery"], "mitre_attack": ["T1048", "T1048.003", "T1071.001", "T1189"], "nist": ["DE.AE", "DE.CM", "PR.AC", "PR.DS", "PR.PT"]} -investigative_searches = ["ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Parent Process Info - Response Task"] +investigative_searches = ["ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] support_searches = [] data_models = ["Network_Resolution", "Network_Traffic"] providing_technologies = none @@ -933,7 +997,7 @@ version = 1 reference = ["https://www.carbonblack.com/2017/06/28/carbon-black-threat-research-technical-analysis-petya-notpetya-ransomware/", "https://www.splunk.com/blog/2017/06/27/closing-the-detection-to-mitigation-gap-or-to-petya-or-notpetya-whocares-.html"] detection_searches = ["ESCU - BCDEdit Failure Recovery Modification - Rule", "ESCU - Common Ransomware Extensions - Rule", "ESCU - Common Ransomware Notes - Rule", "ESCU - Deleting Shadow Copies - Rule", "ESCU - Prohibited Network Traffic Allowed - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Remote Process Instantiation via WMI - Rule", "ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - SMB Traffic Spike - Rule", "ESCU - Scheduled tasks used in BadRabbit ransomware - Rule", "ESCU - Schtasks used for forcing a reboot - Rule", "ESCU - Spike in File Writes - Rule", "ESCU - Suspicious Scheduled Task from Public Directory - Rule", "ESCU - Suspicious wevtutil Usage - Rule", "ESCU - System Processes Run From Unexpected Locations - Rule", "ESCU - TOR Traffic - Rule", "ESCU - USN Journal Deletion - Rule", "ESCU - Unusually Long Command Line - MLTK - Rule", "ESCU - Unusually Long Command Line - Rule", "ESCU - WBAdmin Delete System Backups - Rule", "ESCU - Windows Event Log Cleared - Rule"] mappings = {"cis20": ["CIS 10", "CIS 12", "CIS 3", "CIS 5", "CIS 6", "CIS 8", "CIS 9"], "kill_chain_phases": ["Actions on Objectives", "Command and Control", "Delivery", "Exploitation", "Privilege Escalation"], "mitre_attack": ["T1021.002", "T1036.003", "T1047", "T1048", "T1053.005", "T1070", "T1070.001", "T1071.001", "T1485", "T1490", "T1547.001"], "nist": ["DE.AE", "DE.CM", "DE.DP", "PR.AC", "PR.AT", "PR.IP", "PR.PT"]} -investigative_searches = ["ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Backup Logs For Endpoint - Response Task", "ESCU - Get Sysmon WMI Activity for Host - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get History Of Email Sources - Response Task"] +investigative_searches = ["ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Sysmon WMI Activity for Host - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Backup Logs For Endpoint - Response Task"] support_searches = ["ESCU - Baseline of Command Line Length - MLTK", "ESCU - Baseline of SMB Traffic - MLTK"] data_models = ["Endpoint", "Network_Traffic"] providing_technologies = none @@ -1015,7 +1079,7 @@ version = 1 reference = ["https://www.crowdstrike.com/blog/an-in-depth-analysis-of-samsam-ransomware-and-boss-spider/", "https://nakedsecurity.sophos.com/2018/07/31/samsam-the-almost-6-million-ransomware/", "https://thehackernews.com/2018/07/samsam-ransomware-attacks.html"] detection_searches = ["ESCU - Batch File Write to System32 - Rule", "ESCU - Common Ransomware Extensions - Rule", "ESCU - Common Ransomware Notes - Rule", "ESCU - Deleting Shadow Copies - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - Detect attackers scanning for vulnerable JBoss servers - Rule", "ESCU - Detect malicious requests to exploit JBoss servers - Rule", "ESCU - File with Samsam Extension - Rule", "ESCU - Prohibited Software On Endpoint - Rule", "ESCU - Remote Desktop Network Bruteforce - Rule", "ESCU - Remote Desktop Network Traffic - Rule", "ESCU - Samsam Test File Write - Rule", "ESCU - Spike in File Writes - Rule"] mappings = {"cis20": ["CIS 10", "CIS 12", "CIS 16", "CIS 18", "CIS 2", "CIS 3", "CIS 4", "CIS 8", "CIS 9"], "kill_chain_phases": ["Actions on Objectives", "Command and Control", "Delivery", "Installation", "Reconnaissance"], "mitre_attack": ["T1021.001", "T1021.002", "T1082", "T1204.002", "T1485", "T1486", "T1490"], "nist": ["DE.AE", "DE.CM", "ID.AM", "ID.RA", "PR.AC", "PR.DS", "PR.IP", "PR.MA", "PR.PT"]} -investigative_searches = ["ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Backup Logs For Endpoint - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Investigate Successful Remote Desktop Authentications - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get History Of Email Sources - Response Task"] +investigative_searches = ["ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Investigate Successful Remote Desktop Authentications - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Backup Logs For Endpoint - Response Task"] support_searches = [] data_models = ["Endpoint", "Network_Traffic", "Web"] providing_technologies = none @@ -1112,8 +1176,8 @@ version = 1 reference = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf"] detection_searches = ["ESCU - Abnormally High AWS Instances Launched by User - MLTK - Rule", "ESCU - Abnormally High AWS Instances Launched by User - Rule", "ESCU - Abnormally High AWS Instances Terminated by User - MLTK - Rule", "ESCU - Abnormally High AWS Instances Terminated by User - Rule", "ESCU - EC2 Instance Started In Previously Unseen Region - Rule", "ESCU - EC2 Instance Started With Previously Unseen User - Rule"] mappings = {"cis20": ["CIS 1", "CIS 12", "CIS 13"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1078.004", "T1535"], "nist": ["DE.AE", "DE.DP", "ID.AM"]} -investigative_searches = ["ESCU - Get Notable History - Response Task", "ESCU - AWS Investigate Security Hub alerts by dest - Response Task", "ESCU - Investigate AWS activities via region name - Response Task", "ESCU - Get EC2 Launch Details - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get EC2 Instance Details by instanceId - Response Task"] -support_searches = ["ESCU - Baseline of Excessive AWS Instances Terminated by User - MLTK", "ESCU - Previously Seen EC2 Launches By User", "ESCU - Baseline of Excessive AWS Instances Launched by User - MLTK", "ESCU - Previously Seen AWS Regions"] +investigative_searches = ["ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get EC2 Instance Details by instanceId - Response Task", "ESCU - Investigate AWS activities via region name - Response Task", "ESCU - AWS Investigate Security Hub alerts by dest - Response Task", "ESCU - Get EC2 Launch Details - Response Task", "ESCU - Get Notable History - Response Task"] +support_searches = ["ESCU - Previously Seen AWS Regions", "ESCU - Baseline of Excessive AWS Instances Launched by User - MLTK", "ESCU - Previously Seen EC2 Launches By User", "ESCU - Baseline of Excessive AWS Instances Terminated by User - MLTK"] data_models = [] providing_technologies = none description = Use the searches in this Analytic Story to monitor your AWS EC2 instances for evidence of anomalous activity and suspicious behaviors, such as EC2 instances that originate from unusual locations or those launched by previously unseen users (among others). Included investigative searches will help you probe more deeply, when the information warrants it. @@ -1144,8 +1208,8 @@ version = 2 reference = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf", "https://www.tripwire.com/state-of-security/security-data-protection/cloud/public-aws-s3-buckets-writable/"] detection_searches = ["ESCU - Detect New Open S3 Buckets over AWS CLI - Rule", "ESCU - Detect New Open S3 buckets - Rule", "ESCU - Detect S3 access from a new IP - Rule", "ESCU - Detect Spike in S3 Bucket deletion - Rule"] mappings = {"cis20": ["CIS 13", "CIS 14"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1530"], "nist": ["DE.CM", "DE.DP", "PR.AC", "PR.DS"]} -investigative_searches = ["ESCU - Get Notable History - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - AWS S3 Bucket details via bucketName - Response Task", "ESCU - Investigate AWS activities via region name - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task"] -support_searches = ["ESCU - Baseline of S3 Bucket deletion activity by ARN", "ESCU - Previously seen S3 bucket access by remote IP"] +investigative_searches = ["ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - AWS S3 Bucket details via bucketName - Response Task", "ESCU - Investigate AWS activities via region name - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - Get Notable History - Response Task"] +support_searches = ["ESCU - Previously seen S3 bucket access by remote IP", "ESCU - Baseline of S3 Bucket deletion activity by ARN"] data_models = [] providing_technologies = none description = Use the searches in this Analytic Story to monitor your AWS S3 buckets for evidence of anomalous activity and suspicious behaviors, such as detecting open S3 buckets and buckets being accessed from a new IP. The contextual and investigative searches will give you more information, when required. @@ -1162,7 +1226,7 @@ version = 1 reference = ["https://rhinosecuritylabs.com/aws/hiding-cloudcobalt-strike-beacon-c2-using-amazon-apis/"] detection_searches = ["ESCU - Detect Spike in blocked Outbound Traffic from your AWS - Rule"] mappings = {"cis20": ["CIS 11"], "kill_chain_phases": ["Actions on Objectives", "Command and Control"], "nist": ["DE.AE", "DE.CM", "PR.AC"]} -investigative_searches = ["ESCU - Get DNS Server History for a host - Response Task", "ESCU - AWS Network Interface details via resourceId - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - AWS Network ACL Details from ID - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task"] +investigative_searches = ["ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - AWS Network Interface details via resourceId - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - AWS Network ACL Details from ID - Response Task"] support_searches = ["ESCU - Baseline of blocked outbound traffic from AWS"] data_models = [] providing_technologies = none @@ -1182,7 +1246,7 @@ reference = ["https://aws.amazon.com/blogs/security/aws-cloudtrail-now-tracks-cr detection_searches = ["ESCU - AWS Cross Account Activity From Previously Unseen Account - Rule", "ESCU - Detect AWS Console Login by New User - Rule", "ESCU - Detect AWS Console Login by User from New City - Rule", "ESCU - Detect AWS Console Login by User from New Country - Rule", "ESCU - Detect AWS Console Login by User from New Region - Rule"] mappings = {"cis20": ["CIS 16"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1535"], "nist": ["DE.AE", "DE.DP", "PR.AC", "PR.DS"]} investigative_searches = ["ESCU - Investigate AWS User Activities by user field - Response Task", "ESCU - Get Notable History - Response Task"] -support_searches = ["ESCU - Previously Seen AWS Cross Account Activity - Update", "ESCU - Previously Seen Users In CloudTrail - Update", "ESCU - Previously Seen AWS Cross Account Activity - Initial", "ESCU - Previously Seen Users in CloudTrail - Initial"] +support_searches = ["ESCU - Previously Seen AWS Cross Account Activity - Update", "ESCU - Previously Seen Users In CloudTrail - Update", "ESCU - Previously Seen Users in CloudTrail - Initial", "ESCU - Previously Seen AWS Cross Account Activity - Initial"] data_models = ["Authentication"] providing_technologies = none description = Monitor your cloud authentication events. Searches within this Analytic Story leverage the recent cloud updates to the Authentication data model to help you stay aware of and investigate suspicious login activity. @@ -1199,7 +1263,7 @@ reference = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.p detection_searches = ["ESCU - Abnormally High Number Of Cloud Instances Destroyed - Rule", "ESCU - Abnormally High Number Of Cloud Instances Launched - Rule", "ESCU - Cloud Instance Modified By Previously Unseen User - Rule"] mappings = {"cis20": ["CIS 1", "CIS 13"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1078.004"], "nist": ["DE.AE", "DE.DP", "ID.AM"]} investigative_searches = ["ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task"] -support_searches = ["ESCU - Baseline Of Cloud Instances Destroyed", "ESCU - Previously Seen Cloud Instance Modifications By User - Initial", "ESCU - Previously Seen Cloud Instance Modifications By User - Update", "ESCU - Baseline Of Cloud Instances Launched"] +support_searches = ["ESCU - Baseline Of Cloud Instances Destroyed", "ESCU - Baseline Of Cloud Instances Launched", "ESCU - Previously Seen Cloud Instance Modifications By User - Initial", "ESCU - Previously Seen Cloud Instance Modifications By User - Update"] data_models = ["Change"] providing_technologies = none description = Monitor your cloud infrastructure provisioning activities for behaviors originating from unfamiliar or unusual locations. These behaviors may indicate that malicious activities are occurring somewhere within your cloud environment. @@ -1232,7 +1296,7 @@ reference = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.p detection_searches = ["ESCU - Abnormally High Number Of Cloud Infrastructure API Calls - Rule", "ESCU - Abnormally High Number Of Cloud Security Group API Calls - Rule", "ESCU - Cloud API Calls From Previously Unseen User Roles - Rule"] mappings = {"cis20": ["CIS 1", "CIS 16"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1078", "T1078.004"], "nist": ["DE.CM", "DE.DP", "ID.AM", "PR.AC"]} investigative_searches = ["ESCU - AWS Investigate User Activities By ARN - Response Task"] -support_searches = ["ESCU - Baseline Of Cloud Infrastructure API Calls Per User", "ESCU - Previously Seen Cloud API Calls Per User Role - Update", "ESCU - Previously Seen Cloud API Calls Per User Role - Initial", "ESCU - Baseline Of Cloud Security Group API Calls Per User"] +support_searches = ["ESCU - Baseline Of Cloud Infrastructure API Calls Per User", "ESCU - Baseline Of Cloud Security Group API Calls Per User", "ESCU - Previously Seen Cloud API Calls Per User Role - Update", "ESCU - Previously Seen Cloud API Calls Per User Role - Initial"] data_models = ["Change"] providing_technologies = none description = Detect and investigate suspicious activities by users and roles in your cloud environments. @@ -1249,7 +1313,7 @@ reference = ["https://attack.mitre.org/wiki/Technique/T1059", "https://www.micro detection_searches = ["ESCU - Detect Prohibited Applications Spawning cmd exe - Rule", "ESCU - Detect Use of cmd exe to Launch Script Interpreters - Rule", "ESCU - First time seen command line argument - Rule", "ESCU - System Processes Run From Unexpected Locations - Rule", "ESCU - Unusually Long Command Line - MLTK - Rule", "ESCU - Unusually Long Command Line - Rule"] mappings = {"cis20": ["CIS 3", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Command and Control", "Exploitation"], "mitre_attack": ["T1036.003", "T1059.001", "T1059.003"], "nist": ["DE.CM", "PR.IP", "PR.PT"]} investigative_searches = ["ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] -support_searches = ["ESCU - Previously seen command line arguments", "ESCU - Baseline of Command Line Length - MLTK"] +support_searches = ["ESCU - Baseline of Command Line Length - MLTK", "ESCU - Previously seen command line arguments"] data_models = ["Endpoint"] providing_technologies = none description = Leveraging the Windows command-line interface (CLI) is one of the most common attack techniques--one that is also detailed in the MITRE ATT&CK framework. Use this Analytic Story to help you identify unusual or suspicious use of the CLI on Windows systems. @@ -1264,7 +1328,7 @@ version = 1 reference = ["http://blogs.splunk.com/2015/10/01/random-words-on-entropy-and-dns/", "http://www.darkreading.com/analytics/security-monitoring/got-malware-three-signs-revealed-in-dns-traffic/d/d-id/1139680", "https://live.paloaltonetworks.com/t5/Threat-Vulnerability-Articles/What-are-suspicious-DNS-queries/ta-p/71454"] detection_searches = ["ESCU - Clients Connecting to Multiple DNS Servers - Rule", "ESCU - DNS Query Length Outliers - MLTK - Rule", "ESCU - DNS Query Length With High Standard Deviation - Rule", "ESCU - DNS Query Requests Resolved by Unauthorized DNS Servers - Rule", "ESCU - Detect Long DNS TXT Record Response - Rule", "ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - Detection of DNS Tunnels - Rule", "ESCU - Excessive DNS Failures - Rule"] mappings = {"cis20": ["CIS 1", "CIS 12", "CIS 13", "CIS 3", "CIS 8", "CIS 9"], "kill_chain_phases": ["Actions on Objectives", "Command and Control"], "mitre_attack": ["T1048.003", "T1071.004", "T1189"], "nist": ["DE.AE", "DE.CM", "ID.AM", "PR.DS", "PR.IP", "PR.PT"]} -investigative_searches = ["ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task"] +investigative_searches = ["ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] support_searches = ["ESCU - Baseline of DNS Query Length - MLTK"] data_models = ["Network_Resolution"] providing_technologies = none @@ -1280,7 +1344,7 @@ version = 1 reference = ["https://www.splunk.com/blog/2015/06/26/phishing-hits-a-new-level-of-quality/"] detection_searches = ["ESCU - Email Attachments With Lots Of Spaces - Rule", "ESCU - Monitor Email For Brand Abuse - Rule", "ESCU - Suspicious Email - UBA Anomaly - Rule", "ESCU - Suspicious Email Attachment Extensions - Rule"] mappings = {"cis20": ["CIS 12", "CIS 3", "CIS 7"], "kill_chain_phases": ["Delivery"], "mitre_attack": ["T1566", "T1566.001"], "nist": ["DE.AE", "PR.IP"]} -investigative_searches = ["ESCU - Get Email Info - Response Task", "ESCU - Get Emails From Specific Sender - Response Task", "ESCU - Get Notable History - Response Task"] +investigative_searches = ["ESCU - Get Emails From Specific Sender - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Email Info - Response Task"] support_searches = ["ESCU - DNSTwist Domain Names"] data_models = ["Email", "UEBA"] providing_technologies = none @@ -1317,7 +1381,7 @@ reference = ["https://redcanary.com/blog/introducing-atomictestharnesses/", "htt detection_searches = ["ESCU - Detect MSHTA Url in Command Line - Rule", "ESCU - Detect Prohibited Applications Spawning cmd exe - Rule", "ESCU - Detect Rundll32 Inline HTA Execution - Rule", "ESCU - Detect mshta inline hta execution - Rule", "ESCU - Detect mshta renamed - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Suspicious mshta child process - Rule", "ESCU - Suspicious mshta spawn - Rule"] mappings = {"cis20": ["CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Exploitation"], "mitre_attack": ["T1059.003", "T1218.005", "T1547.001"], "nist": ["DE.AE", "DE.CM", "PR.PT"]} investigative_searches = ["ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] -support_searches = ["ESCU - Previously seen command line arguments", "ESCU - Baseline of Command Line Length - MLTK"] +support_searches = ["ESCU - Baseline of Command Line Length - MLTK", "ESCU - Previously seen command line arguments"] data_models = ["Endpoint"] providing_technologies = none description = Monitor and detect techniques used by attackers who leverage the mshta.exe process to execute malicious code. @@ -1344,7 +1408,7 @@ version = 1 reference = ["https://attack.mitre.org/wiki/Technique/T1078", "https://owasp.org/www-community/attacks/Credential_stuffing", "https://searchsecurity.techtarget.com/answer/What-is-a-password-spraying-attack-and-how-does-it-work"] detection_searches = ["ESCU - Multiple Okta Users With Invalid Credentials From The Same IP - Rule", "ESCU - Okta Account Lockout Events - Rule", "ESCU - Okta Failed SSO Attempts - Rule", "ESCU - Okta User Logins From Multiple Cities - Rule"] mappings = {"cis20": ["CIS 16"], "mitre_attack": ["T1078.001"], "nist": ["DE.CM"]} -investigative_searches = ["ESCU - Investigate Okta Activity by IP Address - Response Task", "ESCU - Investigate User Activities In Okta - Response Task", "ESCU - Investigate Okta Activity by app - Response Task"] +investigative_searches = ["ESCU - Investigate Okta Activity by app - Response Task", "ESCU - Investigate Okta Activity by IP Address - Response Task", "ESCU - Investigate User Activities In Okta - Response Task"] support_searches = [] data_models = [] providing_technologies = none @@ -1394,7 +1458,7 @@ version = 2 reference = ["https://www.blackhat.com/docs/us-15/materials/us-15-Graeber-Abusing-Windows-Management-Instrumentation-WMI-To-Build-A-Persistent%20Asynchronous-And-Fileless-Backdoor-wp.pdf", "https://www.fireeye.com/blog/threat-research/2017/03/wmimplant_a_wmi_ba.html"] detection_searches = ["ESCU - Process Execution via WMI - Rule", "ESCU - Remote Process Instantiation via WMI - Rule", "ESCU - Remote WMI Command Attempt - Rule", "ESCU - Script Execution via WMI - Rule", "ESCU - WMI Permanent Event Subscription - Rule", "ESCU - WMI Permanent Event Subscription - Sysmon - Rule", "ESCU - WMI Temporary Event Subscription - Rule"] mappings = {"cis20": ["CIS 3", "CIS 5"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1047", "T1546.003"], "nist": ["PR.AC", "PR.AT", "PR.IP", "PR.PT"]} -investigative_searches = ["ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Sysmon WMI Activity for Host - Response Task", "ESCU - Get Notable History - Response Task"] +investigative_searches = ["ESCU - Get Sysmon WMI Activity for Host - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] support_searches = [] data_models = ["Endpoint"] providing_technologies = none @@ -1431,7 +1495,7 @@ reference = ["https://blog.rapid7.com/2020/04/02/dispelling-zoom-bugbears-what-y detection_searches = ["ESCU - Detect Prohibited Applications Spawning cmd exe - Rule", "ESCU - First Time Seen Child Process of Zoom - Rule"] mappings = {"cis20": ["CIS 3", "CIS 8"], "kill_chain_phases": ["Actions on Objectives", "Exploitation"], "mitre_attack": ["T1059.003", "T1068"], "nist": ["DE.CM", "PR.IP", "PR.PT"]} investigative_searches = ["ESCU - Get Process File Activity - Response Task"] -support_searches = ["ESCU - Previously Seen Zoom Child Processes - Initial", "ESCU - Previously Seen Zoom Child Processes - Update"] +support_searches = ["ESCU - Previously Seen Zoom Child Processes - Update", "ESCU - Previously Seen Zoom Child Processes - Initial"] data_models = ["Endpoint"] providing_technologies = none description = Attackers are using Zoom as an vector to increase privileges on a sytems. This story detects new child processes of zoom and provides investigative actions for this detection. @@ -1446,7 +1510,7 @@ id = 270a67a6-55d8-11eb-ae93-0242ac130002 version = 1 reference = ["https://attack.mitre.org/techniques/T1127/", "https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218/T1218.md", "https://lolbas-project.github.io/lolbas/Binaries/Microsoft.Workflow.Compiler/"] detection_searches = ["ESCU - Suspicious microsoft workflow compiler rename - Rule", "ESCU - Suspicious microsoft workflow compiler usage - Rule"] -mappings = {"cis20": ["CIS 8"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1127", "T1127, T1036.003"], "nist": ["DE.CM", "PR.PT"]} +mappings = {"cis20": ["CIS 8"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1036.003", "T1127"], "nist": ["DE.CM", "PR.PT"]} investigative_searches = [] support_searches = [] data_models = ["Endpoint"] @@ -1544,7 +1608,7 @@ version = 1 reference = ["https://www.fbi.gov/scams-and-safety/common-fraud-schemes/internet-fraud", "https://www.fbi.gov/news/stories/2017-internet-crime-report-released-050718"] detection_searches = ["ESCU - Web Fraud - Account Harvesting - Rule", "ESCU - Web Fraud - Anomalous User Clickspeed - Rule", "ESCU - Web Fraud - Password Sharing Across Accounts - Rule"] mappings = {"cis20": ["CIS 16", "CIS 6"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1078", "T1136"], "nist": ["DE.AE", "DE.CM", "DE.DP"]} -investigative_searches = ["ESCU - Get Web Session Information via session id - Response Task", "ESCU - Get Emails From Specific Sender - Response Task", "ESCU - Get Notable History - Response Task"] +investigative_searches = ["ESCU - Get Emails From Specific Sender - Response Task", "ESCU - Get Web Session Information via session id - Response Task", "ESCU - Get Notable History - Response Task"] support_searches = [] data_models = [] providing_technologies = none @@ -1667,7 +1731,7 @@ reference = ["https://attack.mitre.org/wiki/Technique/T1050", "https://attack.mi detection_searches = ["ESCU - First Time Seen Running Windows Service - Rule", "ESCU - Reg exe Manipulating Windows Services Registry Keys - Rule", "ESCU - Sc exe Manipulating Windows Services - Rule"] mappings = {"cis20": ["CIS 2", "CIS 3", "CIS 5", "CIS 8", "CIS 9"], "kill_chain_phases": ["Actions on Objectives", "Installation"], "mitre_attack": ["T1543.003", "T1569.002", "T1574.011"], "nist": ["DE.AE", "DE.CM", "ID.AM", "PR.AC", "PR.AT", "PR.DS", "PR.IP", "PR.PT"]} investigative_searches = ["ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] -support_searches = ["ESCU - Previously Seen Running Windows Services - Update", "ESCU - Previously Seen Running Windows Services - Initial"] +support_searches = ["ESCU - Previously Seen Running Windows Services - Initial", "ESCU - Previously Seen Running Windows Services - Update"] data_models = ["Endpoint"] providing_technologies = none description = Windows services are often used by attackers for persistence and the ability to load drivers or otherwise interact with the Windows kernel. This Analytic Story helps you monitor your environment for indications that Windows services are being modified or created in a suspicious manner. diff --git a/package/default/analyticstories.conf b/package/default/analyticstories.conf index d40b3ba8df..e29ce6a0fb 100644 --- a/package/default/analyticstories.conf +++ b/package/default/analyticstories.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security_content -# On Date: 2021-03-12T17:19:06 UTC +# On Date: 2021-03-25T19:21:00 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# @@ -14,7 +14,7 @@ version = 1 references = ["https://aws.amazon.com/blogs/security/aws-cloudtrail-now-tracks-cross-account-activity-to-its-origin/"] maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}] spec_version = 3 -searches = ["ESCU - aws detect sts get session token abuse - Rule", "ESCU - aws detect attach to role policy - Rule", "ESCU - aws detect permanent key creation - Rule", "ESCU - aws detect sts assume role abuse - Rule", "ESCU - aws detect role creation - Rule", "ESCU - AWS Investigate User Activities By AccessKeyId - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - aws detect role creation - Rule", "ESCU - aws detect sts assume role abuse - Rule", "ESCU - aws detect sts get session token abuse - Rule", "ESCU - aws detect permanent key creation - Rule", "ESCU - aws detect attach to role policy - Rule", "ESCU - AWS Investigate User Activities By AccessKeyId - Response Task", "ESCU - Get Notable History - Response Task"] description = Track when a user assumes an IAM role in another AWS account to obtain cross-account access to services and resources in that account. Accessing new roles could be an indication of malicious activity. narrative = Amazon Web Services (AWS) admins manage access to AWS resources and services across the enterprise using AWS's Identity and Access Management (IAM) functionality. IAM provides the ability to create and manage AWS users, groups, and roles-each with their own unique set of privileges and defined access to specific resources (such as EC2 instances, the AWS Management Console, API, or the command-line interface). Unlike conventional (human) users, IAM roles are assumable by anyone in the organization. They provide users with dynamically created temporary security credentials that expire within a set time period.\ Herein lies the rub. In between the time between when the temporary credentials are issued and when they expire is a period of opportunity, where a user could leverage the temporary credentials to wreak havoc-spin up or remove instances, create new users, elevate privileges, and other malicious activities-throughout the environment.\ @@ -27,13 +27,24 @@ version = 1 references = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf"] maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}] spec_version = 3 -searches = ["ESCU - Abnormally High AWS Instances Launched by User - Rule", "ESCU - EC2 Instance Started With Previously Unseen Instance Type - Rule", "ESCU - Abnormally High AWS Instances Launched by User - MLTK - Rule", "ESCU - EC2 Instance Started In Previously Unseen Region - Rule", "ESCU - EC2 Instance Started With Previously Unseen User - Rule", "ESCU - EC2 Instance Started With Previously Unseen AMI - Rule", "ESCU - Get Notable History - Response Task", "ESCU - Investigate AWS activities via region name - Response Task", "ESCU - Get EC2 Launch Details - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get EC2 Instance Details by instanceId - Response Task"] +searches = ["ESCU - Abnormally High AWS Instances Launched by User - Rule", "ESCU - EC2 Instance Started With Previously Unseen User - Rule", "ESCU - EC2 Instance Started In Previously Unseen Region - Rule", "ESCU - EC2 Instance Started With Previously Unseen AMI - Rule", "ESCU - EC2 Instance Started With Previously Unseen Instance Type - Rule", "ESCU - Abnormally High AWS Instances Launched by User - MLTK - Rule", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get EC2 Instance Details by instanceId - Response Task", "ESCU - Investigate AWS activities via region name - Response Task", "ESCU - Get EC2 Launch Details - Response Task", "ESCU - Get Notable History - Response Task"] description = Monitor your AWS EC2 instances for activities related to cryptojacking/cryptomining. New instances that originate from previously unseen regions, users who launch abnormally high numbers of instances, or EC2 instances started by previously unseen users are just a few examples of potentially malicious behavior. narrative = Cryptomining is an intentionally difficult, resource-intensive business. Its complexity was designed into the process to ensure that the number of blocks mined each day would remain steady. So, it's par for the course that ambitious, but unscrupulous, miners make amassing the computing power of large enterprises--a practice known as cryptojacking--a top priority. \ Cryptojacking has attracted an increasing amount of media attention since its explosion in popularity in the fall of 2017. The attacks have moved from in-browser exploits and mobile phones to enterprise cloud services, such as Amazon Web Services (AWS). It's difficult to determine exactly how widespread the practice has become, since bad actors continually evolve their ability to escape detection, including employing unlisted endpoints, moderating their CPU usage, and hiding the mining pool's IP address behind a free CDN. \ When malicious miners appropriate a cloud instance, often spinning up hundreds of new instances, the costs can become astronomical for the account holder. So, it is critically important to monitor your systems for suspicious activities that could indicate that your network has been infiltrated. \ This Analytic Story is focused on detecting suspicious new instances in your EC2 environment to help prevent such a disaster. It contains detection searches that will detect when a previously unused instance type or AMI is used. It also contains support searches to build lookup files to ensure proper execution of the detection searches. +[analytic_story://AWS IAM Privilege Escalation] +category = Cloud Security +last_updated = 2021-03-08 +version = 1 +references = ["https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation/", "https://www.cyberark.com/resources/threat-research-blog/the-cloud-shadow-admin-threat-10-permissions-to-protect", "https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws"] +maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] +spec_version = 3 +searches = ["ESCU - AWS Create Policy Version to allow all resources - Rule", "ESCU - AWS CreateAccessKey - Rule", "ESCU - AWS UpdateLoginProfile - Rule", "ESCU - AWS SetDefaultPolicyVersion - Rule", "ESCU - AWS CreateLoginProfile - Rule"] +description = This analytic story contains detections that query your AWS Cloudtrail for activities related to privilege escalation. +narrative = Amazon Web Services provides a neat feature called Identity and Access Management (IAM) that enables organizations to manage various AWS services and resources in a secure way. All IAM users have roles, groups and policies associated with them which governs and sets permissions to allow a user to access specific restrictions. \ However, if these IAM policies are misconfigured and have specific combinations of weak permissions; it can allow attackers to escalate their privileges and further compromise the organization. Rhino Security Labs have published comprehensive blogs detailing various AWS Escalation methods. By using this as an inspiration, Splunk’s research team wants to highlight how these attack vectors look in AWS Cloudtrail logs and provide you with detection queries to uncover these potentially malicious events via this Analytic Story. \ + [analytic_story://AWS Network ACL Activity] category = Cloud Security last_updated = 2018-05-21 @@ -41,7 +52,7 @@ version = 2 references = ["https://docs.aws.amazon.com/AmazonVPC/latest/UserGuide/VPC_Appendix_NACLs.html", "https://aws.amazon.com/blogs/security/how-to-help-prepare-for-ddos-attacks-by-reducing-your-attack-surface/"] maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - Detect Spike in blocked Outbound Traffic from your AWS - Rule", "ESCU - Detect Spike in Network ACL Activity - Rule", "ESCU - AWS Network Access Control List Created with All Open Ports - Rule", "ESCU - AWS Network Access Control List Deleted - Rule", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - AWS Network Interface details via resourceId - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - AWS Network ACL Details from ID - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task"] +searches = ["ESCU - Detect Spike in blocked Outbound Traffic from your AWS - Rule", "ESCU - AWS Network Access Control List Deleted - Rule", "ESCU - AWS Network Access Control List Created with All Open Ports - Rule", "ESCU - Detect Spike in Network ACL Activity - Rule", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - AWS Network Interface details via resourceId - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - AWS Network ACL Details from ID - Response Task"] description = Monitor your AWS network infrastructure for bad configurations and malicious activity. Investigative searches help you probe deeper, when the facts warrant it. narrative = AWS CloudTrail is an AWS service that helps you enable governance, compliance, and operational/risk auditing of your AWS account. Actions taken by a user, role, or an AWS service are recorded as events in CloudTrail. It is crucial for a company to monitor events and actions taken in the AWS Management Console, AWS Command Line Interface, and AWS SDKs and APIs to ensure that your servers are not vulnerable to attacks. This analytic story contains detection searches that leverage CloudTrail logs from AWS to check for bad configurations and malicious activity in your AWS network access controls. @@ -52,7 +63,7 @@ version = 1 references = ["https://aws.amazon.com/security-hub/features/"] maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - Detect Spike in AWS Security Hub Alerts for EC2 Instance - Rule", "ESCU - Detect Spike in AWS Security Hub Alerts for User - Rule", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get EC2 Launch Details - Response Task", "ESCU - Get EC2 Instance Details by instanceId - Response Task"] +searches = ["ESCU - Detect Spike in AWS Security Hub Alerts for User - Rule", "ESCU - Detect Spike in AWS Security Hub Alerts for EC2 Instance - Rule", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get EC2 Instance Details by instanceId - Response Task", "ESCU - Get EC2 Launch Details - Response Task"] description = This story is focused around detecting Security Hub alerts generated from AWS narrative = AWS Security Hub collects and consolidates findings from AWS security services enabled in your environment, such as intrusion detection findings from Amazon GuardDuty, vulnerability scans from Amazon Inspector, S3 bucket policy findings from Amazon Macie, publicly accessible and cross-account resources from IAM Access Analyzer, and resources lacking WAF coverage from AWS Firewall Manager. @@ -63,7 +74,7 @@ version = 1 references = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf"] maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}] spec_version = 3 -searches = ["ESCU - AWS Cloud Provisioning From Previously Unseen City - Rule", "ESCU - AWS Cloud Provisioning From Previously Unseen IP Address - Rule", "ESCU - AWS Cloud Provisioning From Previously Unseen Country - Rule", "ESCU - AWS Cloud Provisioning From Previously Unseen Region - Rule", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - AWS Investigate Security Hub alerts by dest - Response Task", "ESCU - Get All AWS Activity From Region - Response Task", "ESCU - Get All AWS Activity From Country - Response Task", "ESCU - Get All AWS Activity From City - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task"] +searches = ["ESCU - AWS Cloud Provisioning From Previously Unseen IP Address - Rule", "ESCU - AWS Cloud Provisioning From Previously Unseen Region - Rule", "ESCU - AWS Cloud Provisioning From Previously Unseen Country - Rule", "ESCU - AWS Cloud Provisioning From Previously Unseen City - Rule", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get All AWS Activity From City - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - AWS Investigate Security Hub alerts by dest - Response Task", "ESCU - Get All AWS Activity From Region - Response Task", "ESCU - Get All AWS Activity From Country - Response Task"] description = Monitor your AWS provisioning activities for behaviors originating from unfamiliar or unusual locations. These behaviors may indicate that malicious activities are occurring somewhere within your network. narrative = Because most enterprise AWS activities originate from familiar geographic locations, monitoring for activity from unknown or unusual regions is an important security measure. This indicator can be especially useful in environments where it is impossible to add specific IPs to an allow list because they vary. \ This Analytic Story was designed to provide you with flexibility in the precision you employ in specifying legitimate geographic regions. It can be as specific as an IP address or a city, or as broad as a region (think state) or an entire country. By determining how precise you want your geographical locations to be and monitoring for new locations that haven't previously accessed your environment, you can detect adversaries as they begin to probe your environment. Since there are legitimate reasons for activities from unfamiliar locations, this is not a standalone indicator. Nevertheless, location can be a relevant piece of information that you may wish to investigate further. @@ -75,7 +86,7 @@ version = 1 references = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf", "https://redlock.io/blog/cryptojacking-tesla"] maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - Detect API activity from users without MFA - Rule", "ESCU - Detect AWS API Activities From Unapproved Accounts - Rule", "ESCU - Detect new API calls from user roles - Rule", "ESCU - Detect Spike in AWS API Activity - Rule", "ESCU - Detect Spike in Security Group Activity - Rule", "ESCU - Investigate AWS User Activities by user field - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Detect API activity from users without MFA - Rule", "ESCU - Detect Spike in AWS API Activity - Rule", "ESCU - Detect AWS API Activities From Unapproved Accounts - Rule", "ESCU - Detect new API calls from user roles - Rule", "ESCU - Detect Spike in Security Group Activity - Rule", "ESCU - Investigate AWS User Activities by user field - Response Task", "ESCU - Get Notable History - Response Task"] description = Detect and investigate dormant user accounts for your AWS environment that have become active again. Because inactive and ad-hoc accounts are common attack targets, it's critical to enable governance within your environment. narrative = It seems obvious that it is critical to monitor and control the users who have access to your cloud infrastructure. Nevertheless, it's all too common for enterprises to lose track of ad-hoc accounts, leaving their servers vulnerable to attack. In fact, this was the very oversight that led to Tesla's cryptojacking attack in February, 2018.\ In addition to compromising the security of your data, when bad actors leverage your compute resources, it can incur monumental costs, since you will be billed for any new EC2 instances and increased bandwidth usage. \ @@ -89,7 +100,7 @@ version = 1 references = ["https://github.com/SpiderLabs/owasp-modsecurity-crs/blob/v3.2/dev/rules/REQUEST-944-APPLICATION-ATTACK-JAVA.conf"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}] spec_version = 3 -searches = ["ESCU - Suspicious Java Classes - Rule", "ESCU - Unusually Long Content-Type Length - Rule", "ESCU - Web Servers Executing Suspicious Processes - Rule", "ESCU - Investigate Web POSTs From src - Response Task", "ESCU - Investigate Suspicious Strings in HTTP Header - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Suspicious Java Classes - Rule", "ESCU - Web Servers Executing Suspicious Processes - Rule", "ESCU - Unusually Long Content-Type Length - Rule", "ESCU - Investigate Web POSTs From src - Response Task", "ESCU - Investigate Suspicious Strings in HTTP Header - Response Task", "ESCU - Get Notable History - Response Task"] description = Detect and investigate activities--such as unusually long `Content-Type` length, suspicious java classes and web servers executing suspicious processes--consistent with attempts to exploit Apache Struts vulnerabilities. narrative = In March of 2017, a remote code-execution vulnerability in the Jakarta Multipart parser in Apache Struts, a widely used open-source framework for creating Java web applications, was disclosed and assigned to CVE-2017-5638. About two months later, hackers exploited the flaw to carry out the world's 5th largest data breach. The target, credit giant Equifax, told investigators that it had become aware of the vulnerability two months before the attack. \ The exploit involved manipulating the `Content-Type HTTP` header to execute commands embedded in the header.\ @@ -124,7 +135,7 @@ version = 1 references = ["https://blog.qualys.com/vulnerabilities-research/2021/01/26/cve-2021-3156-heap-based-buffer-overflow-in-sudo-baron-samedit"] maintainers = [{"company": "Splunk", "email": "-", "name": "Shannon Davis"}] spec_version = 3 -searches = ["ESCU - Detect Baron Samedit CVE-2021-3156 - Rule", "ESCU - Detect Baron Samedit CVE-2021-3156 Segfault - Rule", "ESCU - Detect Baron Samedit CVE-2021-3156 via OSQuery - Rule"] +searches = ["ESCU - Detect Baron Samedit CVE-2021-3156 via OSQuery - Rule", "ESCU - Detect Baron Samedit CVE-2021-3156 Segfault - Rule", "ESCU - Detect Baron Samedit CVE-2021-3156 - Rule"] description = Uncover activity consistent with CVE-2021-3156. Discovered by the Qualys Research Team, this vulnerability has been found to affect sudo across multiple Linux distributions (Ubuntu 20.04 and prior, Debian 10 and prior, Fedora 33 and prior). As this vulnerability was committed to code in July 2011, there will be many distributions affected. Successful exploitation of this vulnerability allows any unprivileged user to gain root privileges on the vulnerable host. narrative = A non-privledged user is able to execute the sudoedit command to trigger a buffer overflow. After the successful buffer overflow, they are then able to gain root privileges on the affected host. The conditions needed to be run are a trailing "\" along with shell and edit flags. Monitoring the /var/log directory on Linux hosts using the Splunk Universal Forwarder will allow you to pick up this behavior when using the provided detection. @@ -135,12 +146,23 @@ version = 1 references = ["https://www.zerofox.com/blog/what-is-digital-risk-monitoring/", "https://securingtomorrow.mcafee.com/consumer/family-safety/what-is-typosquatting/", "https://blog.malwarebytes.com/cybercrime/2016/06/explained-typosquatting/"] maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}] spec_version = 3 -searches = ["ESCU - Monitor DNS For Brand Abuse - Rule", "ESCU - Monitor Email For Brand Abuse - Rule", "ESCU - Monitor Web Traffic For Brand Abuse - Rule", "ESCU - Get Email Info - Response Task", "ESCU - Get Emails From Specific Sender - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Monitor DNS For Brand Abuse - Rule", "ESCU - Monitor Web Traffic For Brand Abuse - Rule", "ESCU - Monitor Email For Brand Abuse - Rule", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Get Emails From Specific Sender - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Email Info - Response Task"] description = Detect and investigate activity that may indicate that an adversary is using faux domains to mislead users into interacting with malicious infrastructure. Monitor DNS, email, and web traffic for permutations of your brand name. narrative = While you can educate your users and customers about the risks and threats posed by typosquatting, phishing, and corporate espionage, human error is a persistent fact of life. Of course, your adversaries are all too aware of this reality and will happily leverage it for nefarious purposes whenever possible3phishing with lookalike addresses, embedding faux command-and-control domains in malware, and hosting malicious content on domains that closely mimic your corporate servers. This is where brand monitoring comes in.\ You can use our adaptation of `DNSTwist`, together with the support searches in this Analytic Story, to generate permutations of specified brands and external domains. Splunk can monitor email, DNS requests, and web traffic for these permutations and provide you with early warnings and situational awareness--powerful elements of an effective defense.\ Notable events will include IP addresses, URLs, and user data. Drilling down can provide you with even more actionable intelligence, including likely geographic information, contextual searches to help you scope the problem, and investigative searches. +[analytic_story://Clop Ransomware] +category = Malware +last_updated = 2021-03-17 +version = 1 +references = ["https://www.hhs.gov/sites/default/files/analyst-note-cl0p-tlp-white.pdf", "https://securityaffairs.co/wordpress/115250/data-breach/qualys-clop-ransomware.html", "https://www.darkreading.com/attacks-breaches/qualys-is-the-latest-victim-of-accellion-data-breach/d/d-id/1340323"] +maintainers = [{"company": "Teoderick Contreras, Splunk", "email": "-", "name": "Rod Soto"}] +spec_version = 3 +searches = ["ESCU - High Process Termination Frequency - Rule", "ESCU - Clop Ransomware Known Service Name - Rule", "ESCU - Common Ransomware Extensions - Rule", "ESCU - High File Deletion Frequency - Rule", "ESCU - Process Deleting Its Process File Path - Rule", "ESCU - Resize ShadowStorage volume - Rule", "ESCU - Suspicious wevtutil Usage - Rule", "ESCU - Ransomware Notes bulk creation - Rule", "ESCU - Create Service In Suspicious File Path - Rule", "ESCU - Deleting Shadow Copies - Rule", "ESCU - Clop Common Exec Parameter - Rule", "ESCU - Windows Event Log Cleared - Rule", "ESCU - Common Ransomware Notes - Rule"] +description = Leverage searches that allow you to detect and investigate unusual activities that might relate to the Clop ransomware, including looking for file writes associated with Clope, encrypting network shares, deleting and resizing shadow volume storage, registry key modification, deleting of security logs, and more. +narrative = Clop ransomware campaigns targeting healthcare and other vertical sectors, involve the use of ransomware payloads along with exfiltration of data per HHS bulletin. Malicious actors demand payment for ransome of data and threaten deletion and exposure of exfiltrated data. + [analytic_story://Cloud Cryptomining] category = Cloud Security last_updated = 2019-10-02 @@ -148,7 +170,7 @@ version = 1 references = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf"] maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}] spec_version = 3 -searches = ["ESCU - Cloud Compute Instance Created With Previously Unseen Image - Rule", "ESCU - Cloud Compute Instance Created In Previously Unused Region - Rule", "ESCU - Cloud Compute Instance Created With Previously Unseen Instance Type - Rule", "ESCU - Abnormally High Number Of Cloud Instances Launched - Rule", "ESCU - Cloud Compute Instance Created By Previously Unseen User - Rule", "ESCU - Get Notable History - Response Task", "ESCU - AWS Investigate Security Hub alerts by dest - Response Task", "ESCU - Investigate AWS activities via region name - Response Task", "ESCU - Get EC2 Launch Details - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get EC2 Instance Details by instanceId - Response Task"] +searches = ["ESCU - Cloud Compute Instance Created With Previously Unseen Image - Rule", "ESCU - Cloud Compute Instance Created By Previously Unseen User - Rule", "ESCU - Cloud Compute Instance Created In Previously Unused Region - Rule", "ESCU - Abnormally High Number Of Cloud Instances Launched - Rule", "ESCU - Cloud Compute Instance Created With Previously Unseen Instance Type - Rule", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get EC2 Instance Details by instanceId - Response Task", "ESCU - Investigate AWS activities via region name - Response Task", "ESCU - AWS Investigate Security Hub alerts by dest - Response Task", "ESCU - Get EC2 Launch Details - Response Task", "ESCU - Get Notable History - Response Task"] description = Monitor your cloud compute instances for activities related to cryptojacking/cryptomining. New instances that originate from previously unseen regions, users who launch abnormally high numbers of instances, or compute instances started by previously unseen users are just a few examples of potentially malicious behavior. narrative = Cryptomining is an intentionally difficult, resource-intensive business. Its complexity was designed into the process to ensure that the number of blocks mined each day would remain steady. So, it's par for the course that ambitious, but unscrupulous, miners make amassing the computing power of large enterprises--a practice known as cryptojacking--a top priority. \ Cryptojacking has attracted an increasing amount of media attention since its explosion in popularity in the fall of 2017. The attacks have moved from in-browser exploits and mobile phones to enterprise cloud services, such as Amazon Web Services (AWS), Google Cloud Platform (GCP), and Azure. It's difficult to determine exactly how widespread the practice has become, since bad actors continually evolve their ability to escape detection, including employing unlisted endpoints, moderating their CPU usage, and hiding the mining pool's IP address behind a free CDN. \ @@ -162,7 +184,7 @@ version = 1 references = ["https://www.cyberark.com/resources/threat-research-blog/golden-saml-newly-discovered-attack-technique-forges-authentication-to-cloud-apps", "https://www.fireeye.com/content/dam/fireeye-www/blog/pdfs/wp-m-unc2452-2021-000343-01.pdf", "https://us-cert.cisa.gov/ncas/alerts/aa21-008a"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rod Soto"}] spec_version = 3 -searches = ["ESCU - Detect Mimikatz Using Loaded Images - Rule", "ESCU - O365 Excessive SSO logon errors - Rule", "ESCU - Detect Mimikatz Via PowerShell And EventCode 4703 - Rule", "ESCU - O365 Added Service Principal - Rule", "ESCU - AWS SAML Access by Provider User and Principal - Rule", "ESCU - O365 New Federated Domain Added - Rule", "ESCU - Certutil exe certificate extraction - Rule", "ESCU - O365 Add App Role Assignment Grant User - Rule", "ESCU - Registry Keys Used For Privilege Escalation - Rule", "ESCU - Detect Rare Executables - Rule", "ESCU - AWS SAML Update identity provider - Rule"] +searches = ["ESCU - AWS SAML Access by Provider User and Principal - Rule", "ESCU - Registry Keys Used For Privilege Escalation - Rule", "ESCU - O365 New Federated Domain Added - Rule", "ESCU - O365 Excessive SSO logon errors - Rule", "ESCU - Detect Mimikatz Using Loaded Images - Rule", "ESCU - O365 Add App Role Assignment Grant User - Rule", "ESCU - Certutil exe certificate extraction - Rule", "ESCU - Detect Mimikatz Via PowerShell And EventCode 4703 - Rule", "ESCU - AWS SAML Update identity provider - Rule", "ESCU - O365 Added Service Principal - Rule", "ESCU - Detect Rare Executables - Rule"] description = This analytical story addresses events that indicate abuse of cloud federated credentials. These credentials are usually extracted from endpoint desktop or servers specially those servers that provide federation services such as Windows Active Directory Federation Services. Identity Federation relies on objects such as Oauth2 tokens, cookies or SAML assertions in order to provide seamless access between cloud and perimeter environments. If these objects are either hijacked or forged then attackers will be able to pivot into victim's cloud environements. narrative = This story is composed of detection searches based on endpoint that addresses the use of Mimikatz, Escalation of Privileges and Abnormal processes that may indicate the extraction of Federated directory objects such as passwords, Oauth2 tokens, certificates and keys. Cloud environment (AWS, Azure) related events are also addressed in specific cloud environment detection searches. @@ -173,7 +195,7 @@ version = 1 references = ["https://www.cobaltstrike.com/", "https://www.infocyte.com/blog/2020/09/02/cobalt-strike-the-new-favorite-among-thieves/", "https://bluescreenofjeff.com/2017-01-24-how-to-write-malleable-c2-profiles-for-cobalt-strike/", "https://blog.talosintelligence.com/2020/09/coverage-strikes-back-cobalt-strike-paper.html", "https://www.fireeye.com/blog/threat-research/2020/12/unauthorized-access-of-fireeye-red-team-tools.html", "https://github.com/MichaelKoczwara/Awesome-CobaltStrike-Defence", "https://github.com/zer0yu/Awesome-CobaltStrike"] maintainers = [{"company": "Splunk", "email": "-", "name": "Michael Haag"}] spec_version = 3 -searches = ["ESCU - Detect Regsvr32 Application Control Bypass - Rule", "ESCU - Suspicious SearchProtocolHost no Command Line Arguments - Rule", "ESCU - Suspicious MSBuild Rename - Rule", "ESCU - Suspicious DLLHost no Command Line Arguments - Rule", "ESCU - Suspicious Rundll32 no Command Line Arguments - Rule", "ESCU - Suspicious msbuild path - Rule", "ESCU - Suspicious microsoft workflow compiler rename - Rule", "ESCU - Suspicious Rundll32 StartW - Rule", "ESCU - Cobalt Strike Named Pipes - Rule", "ESCU - Suspicious GPUpdate no Command Line Arguments - Rule"] +searches = ["ESCU - Suspicious DLLHost no Command Line Arguments - Rule", "ESCU - Suspicious MSBuild Rename - Rule", "ESCU - Detect Regsvr32 Application Control Bypass - Rule", "ESCU - Suspicious SearchProtocolHost no Command Line Arguments - Rule", "ESCU - Suspicious msbuild path - Rule", "ESCU - Suspicious Rundll32 no Command Line Arguments - Rule", "ESCU - Suspicious Rundll32 StartW - Rule", "ESCU - Suspicious microsoft workflow compiler rename - Rule", "ESCU - Suspicious GPUpdate no Command Line Arguments - Rule", "ESCU - Cobalt Strike Named Pipes - Rule"] description = Cobalt Strike is threat emulation software. Red teams and penetration testers use Cobalt Strike to demonstrate the risk of a breach and evaluate mature security programs. Most recently, Cobalt Strike has become the choice tool by threat groups due to its ease of use and extensibility. narrative = This Analytic Story supports you to detect Tactics, Techniques and Procedures (TTPs) from Cobalt Strike. Cobalt Strike has many ways to be enhanced by using aggressor scripts, malleable C2 profiles, default attack packages, and much more. For endpoint behavior, Cobalt Strike is most commonly identified via named pipes, spawn to processes, and DLL function names. Many additional variables are provided for in memory operation of the beacon implant. On the network, depending on the malleable C2 profile used, it is near infinite in the amount of ways to conceal the C2 traffic with Cobalt Strike. Not every query may be specific to Cobalt Strike the tool, but the methodologies and techniques used by it.\ Splunk Threat Research reviewed all publicly available instances of Malleabe C2 Profiles and generated a list of the most commonly used spawnto and pipenames.\ @@ -193,7 +215,7 @@ version = 1 references = ["https://www.intego.com/mac-security-blog/osxcoldroot-and-the-rat-invasion/", "https://objective-see.com/blog/blog_0x2A.html", "https://www.bleepingcomputer.com/news/security/coldroot-rat-still-undetectable-despite-being-uploaded-on-github-two-years-ago/"] maintainers = [{"company": "Splunk", "email": "-", "name": "Jose Hernandez"}] spec_version = 3 -searches = ["ESCU - Processes Tapping Keyboard Events - Rule", "ESCU - Osquery pack - ColdRoot detection - Rule", "ESCU - Investigate Network Traffic From src ip - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Osquery pack - ColdRoot detection - Rule", "ESCU - Processes Tapping Keyboard Events - Rule", "ESCU - Investigate Network Traffic From src ip - Response Task", "ESCU - Get Notable History - Response Task"] description = Leverage searches that allow you to detect and investigate unusual activities that relate to the ColdRoot Remote Access Trojan that affects MacOS. An example of some of these activities are changing sensative binaries in the MacOS sub-system, detecting process names and executables associated with the RAT, detecting when a keyboard tab is installed on a MacOS machine and more. narrative = Conventional wisdom holds that Apple's MacOS operating system is significantly less vulnerable to attack than Windows machines. While that point is debatable, it is true that attacks against MacOS systems are much less common. However, this fact does not mean that Macs are impervious to breaches. To the contrary, research has shown that that Mac malware is increasing at an alarming rate. According to AV-test, in 2018, there were 86,865 new MacOS malware variants, up from 27,338 the year before—a 31% increase. In contrast, the independent research firm found that new Windows malware had increased from 65.17M to 76.86M during that same period, less than half the rate of growth. The bottom line is that while the numbers look a lot smaller than Windows, it's definitely time to take Mac security more seriously.\ This Analytic Story addresses the ColdRoot remote access trojan (RAT), which was uploaded to Github in 2016, but was still escaping detection by the first quarter of 2018, when a new, more feature-rich variant was discovered masquerading as an Apple audio driver. Among other capabilities, the Pascal-based ColdRoot can heist passwords from users' keychains and remotely control infected machines without detection. In the initial report of his findings, Patrick Wardle, Chief Research Officer for Digita Security, explained that the new ColdRoot RAT could start and kill processes on the breached system, spawn new remote-desktop sessions, take screen captures and assemble them into a live stream of the victim's desktop, and more.\ @@ -206,7 +228,7 @@ version = 1 references = ["https://attack.mitre.org/wiki/Collection", "https://attack.mitre.org/wiki/Technique/T1074"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}] spec_version = 3 -searches = ["ESCU - Email servers sending high volume traffic to hosts - Rule", "ESCU - Email files written outside of the Outlook directory - Rule", "ESCU - Hosts receiving high volume of network traffic from email server - Rule", "ESCU - Suspicious writes to System Volume Information - Rule", "ESCU - Suspicious writes to windows Recycle Bin - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Email servers sending high volume traffic to hosts - Rule", "ESCU - Hosts receiving high volume of network traffic from email server - Rule", "ESCU - Suspicious writes to System Volume Information - Rule", "ESCU - Suspicious writes to windows Recycle Bin - Rule", "ESCU - Email files written outside of the Outlook directory - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Monitor for and investigate activities--such as suspicious writes to the Windows Recycling Bin or email servers sending high amounts of traffic to specific hosts, for example--that may indicate that an adversary is harvesting and exfiltrating sensitive data. narrative = A common adversary goal is to identify and exfiltrate data of value from a target organization. This data may include email conversations and addresses, confidential company information, links to network design/infrastructure, important dates, and so on.\ Attacks are composed of three activities: identification, collection, and staging data for exfiltration. Identification typically involves scanning systems and observing user activity. Collection can involve the transfer of large amounts of data from various repositories. Staging/preparation includes moving data to a central location and compressing (and optionally encoding and/or encrypting) it. All of these activities provide opportunities for defenders to identify their presence. \ @@ -219,7 +241,7 @@ version = 1 references = ["https://attack.mitre.org/wiki/Command_and_Control", "https://searchsecurity.techtarget.com/feature/Command-and-control-servers-The-puppet-masters-that-govern-malware"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}] spec_version = 3 -searches = ["ESCU - DNS Query Length With High Standard Deviation - Rule", "ESCU - Detect Long DNS TXT Record Response - Rule", "ESCU - Excessive DNS Failures - Rule", "ESCU - Protocol or Port Mismatch - Rule", "ESCU - DNS Query Requests Resolved by Unauthorized DNS Servers - Rule", "ESCU - Detect Large Outbound ICMP Packets - Rule", "ESCU - Detection of DNS Tunnels - Rule", "ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - Clients Connecting to Multiple DNS Servers - Rule", "ESCU - DNS Query Length Outliers - MLTK - Rule", "ESCU - Prohibited Network Traffic Allowed - Rule", "ESCU - TOR Traffic - Rule", "ESCU - Detect Spike in blocked Outbound Traffic from your AWS - Rule", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - AWS Network Interface details via resourceId - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - AWS Network ACL Details from ID - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task"] +searches = ["ESCU - Clients Connecting to Multiple DNS Servers - Rule", "ESCU - DNS Query Length With High Standard Deviation - Rule", "ESCU - Detect Spike in blocked Outbound Traffic from your AWS - Rule", "ESCU - Excessive DNS Failures - Rule", "ESCU - DNS Query Length Outliers - MLTK - Rule", "ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - Protocol or Port Mismatch - Rule", "ESCU - Detect Long DNS TXT Record Response - Rule", "ESCU - TOR Traffic - Rule", "ESCU - Detect Large Outbound ICMP Packets - Rule", "ESCU - Prohibited Network Traffic Allowed - Rule", "ESCU - DNS Query Requests Resolved by Unauthorized DNS Servers - Rule", "ESCU - Detection of DNS Tunnels - Rule", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - AWS Network Interface details via resourceId - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - AWS Network ACL Details from ID - Response Task"] description = Detect and investigate tactics, techniques, and procedures leveraged by attackers to establish and operate command and control channels. Implants installed by attackers on compromised endpoints use these channels to receive instructions and send data back to the malicious operators. narrative = Threat actors typically architect and implement an infrastructure to use in various ways during the course of their attack campaigns. In some cases, they leverage this infrastructure for scanning and performing reconnaissance activities. In others, they may use this infrastructure to launch actual attacks. One of the most important functions of this infrastructure is to establish servers that will communicate with implants on compromised endpoints. These servers establish a command and control channel that is used to proxy data between the compromised endpoint and the attacker. These channels relay commands from the attacker to the compromised endpoint and the output of those commands back to the attacker.\ Because this communication is so critical for an adversary, they often use techniques designed to hide the true nature of the communications. There are many different techniques used to establish and communicate over these channels. This Analytic Story provides searches that look for a variety of the techniques used for these channels, as well as indications that these channels are active, by examining logs associated with border control devices and network-access control lists. @@ -254,7 +276,7 @@ version = 3 references = ["https://attack.mitre.org/wiki/Technique/T1003", "https://cyberwardog.blogspot.com/2017/03/chronicles-of-threat-hunter-hunting-for.html"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}] spec_version = 3 -searches = ["ESCU - Dump LSASS via procdump Rename - Rule", "ESCU - Detect Mimikatz Using Loaded Images - Rule", "ESCU - Creation of Shadow Copy with wmic and powershell - Rule", "ESCU - Dump LSASS via procdump - Rule", "ESCU - Unsigned Image Loaded by LSASS - Rule", "ESCU - Attempt To Set Default PowerShell Execution Policy To Unrestricted or Bypass - Rule", "ESCU - Creation of Shadow Copy - Rule", "ESCU - Credential Dumping via Copy Command from Shadow Copy - Rule", "ESCU - Ntdsutil Export NTDS - Rule", "ESCU - Detect Credential Dumping through LSASS access - Rule", "ESCU - Creation of lsass Dump with Taskmgr - Rule", "ESCU - Create Remote Thread into LSASS - Rule", "ESCU - Attempted Credential Dump From Registry via Reg exe - Rule", "ESCU - Access LSASS Memory for Dump Creation - Rule", "ESCU - Dump LSASS via comsvcs DLL - Rule", "ESCU - Credential Dumping via Symlink to Shadow Copy - Rule", "ESCU - Investigate Failed Logins for Multiple Destinations - Response Task", "ESCU - Investigate Previous Unseen User - Response Task", "ESCU - Investigate Pass the Hash Attempts - Response Task", "ESCU - Investigate Pass the Ticket Attempts - Response Task"] +searches = ["ESCU - Unsigned Image Loaded by LSASS - Rule", "ESCU - Dump LSASS via procdump Rename - Rule", "ESCU - Create Remote Thread into LSASS - Rule", "ESCU - Credential Dumping via Symlink to Shadow Copy - Rule", "ESCU - Dump LSASS via comsvcs DLL - Rule", "ESCU - Creation of Shadow Copy with wmic and powershell - Rule", "ESCU - Creation of lsass Dump with Taskmgr - Rule", "ESCU - Creation of Shadow Copy - Rule", "ESCU - Detect Credential Dumping through LSASS access - Rule", "ESCU - Detect Mimikatz Using Loaded Images - Rule", "ESCU - Credential Dumping via Copy Command from Shadow Copy - Rule", "ESCU - Ntdsutil Export NTDS - Rule", "ESCU - Attempted Credential Dump From Registry via Reg exe - Rule", "ESCU - Dump LSASS via procdump - Rule", "ESCU - Attempt To Set Default PowerShell Execution Policy To Unrestricted or Bypass - Rule", "ESCU - Access LSASS Memory for Dump Creation - Rule", "ESCU - Investigate Pass the Ticket Attempts - Response Task", "ESCU - Investigate Previous Unseen User - Response Task", "ESCU - Investigate Failed Logins for Multiple Destinations - Response Task", "ESCU - Investigate Pass the Hash Attempts - Response Task"] description = Uncover activity consistent with credential dumping, a technique wherein attackers compromise systems and attempt to obtain and exfiltrate passwords. The threat actors use these pilfered credentials to further escalate privileges and spread throughout a target environment. The included searches in this Analytic Story are designed to identify attempts to credential dumping. narrative = Credential dumping—gathering credentials from a target system, often hashed or encrypted—is a common attack technique. Even though the credentials may not be in plain text, an attacker can still exfiltrate the data and set to cracking it offline, on their own systems. The threat actors target a variety of sources to extract them, including the Security Accounts Manager (SAM), Local Security Authority (LSA), NTDS from Domain Controllers, or the Group Policy Preference (GPP) files.\ Once attackers obtain valid credentials, they use them to move throughout a target network with ease, discovering new systems and identifying assets of interest. Credentials obtained in this manner typically include those of privileged users, which may provide access to more sensitive information and system operations.\ @@ -267,7 +289,7 @@ version = 2 references = ["https://www.us-cert.gov/ncas/alerts/TA18-074A"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}] spec_version = 3 -searches = ["ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - Processes launching netsh - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Suspicious Reg exe Process - Rule", "ESCU - Sc exe Manipulating Windows Services - Rule", "ESCU - Detect New Local Admin account - Rule", "ESCU - Detect Outbound SMB Traffic - Rule", "ESCU - Single Letter Process On Endpoint - Rule", "ESCU - Scheduled Task Deleted Or Created via CMD - Rule", "ESCU - Create local admin accounts using net exe - Rule", "ESCU - Malicious PowerShell Process - Execution Policy Bypass - Rule", "ESCU - SMB Traffic Spike - Rule", "ESCU - First time seen command line argument - Rule", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Process File Activity - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Parent Process Info - Response Task"] +searches = ["ESCU - Sc exe Manipulating Windows Services - Rule", "ESCU - SMB Traffic Spike - Rule", "ESCU - Detect New Local Admin account - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - Detect Outbound SMB Traffic - Rule", "ESCU - Create local admin accounts using net exe - Rule", "ESCU - Scheduled Task Deleted Or Created via CMD - Rule", "ESCU - Single Letter Process On Endpoint - Rule", "ESCU - Suspicious Reg exe Process - Rule", "ESCU - First time seen command line argument - Rule", "ESCU - Malicious PowerShell Process - Execution Policy Bypass - Rule", "ESCU - Processes launching netsh - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Get Process File Activity - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Monitor for suspicious activities associated with DHS Technical Alert US-CERT TA18-074A. Some of the activities that adversaries used in these compromises included spearfishing attacks, malware, watering-hole domains, many and more. narrative = The frequency of nation-state cyber attacks has increased significantly over the last decade. Employing numerous tactics and techniques, these attacks continue to escalate in complexity. \ There is a wide range of motivations for these state-sponsored hacks, including stealing valuable corporate, military, or diplomatic dataѿall of which could confer advantages in various arenas. They may also target critical infrastructure. \ @@ -293,7 +315,7 @@ version = 1 references = ["https://www.fireeye.com/blog/threat-research/2017/09/apt33-insights-into-iranian-cyber-espionage.html", "https://umbrella.cisco.com/blog/2013/04/15/on-the-trail-of-malicious-dynamic-dns-domains/", "http://www.noip.com/blog/2014/07/11/dynamic-dns-can-use-2/", "https://www.splunk.com/blog/2015/08/04/detecting-dynamic-dns-domains-in-splunk.html"] maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - DNS record changed - Rule", "ESCU - Clients Connecting to Multiple DNS Servers - Rule", "ESCU - DNS Query Requests Resolved by Unauthorized DNS Servers - Rule", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - DNS Hijack Enrichment - Response Task"] +searches = ["ESCU - Clients Connecting to Multiple DNS Servers - Rule", "ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - DNS record changed - Rule", "ESCU - DNS Query Requests Resolved by Unauthorized DNS Servers - Rule", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - DNS Hijack Enrichment - Response Task"] description = Secure your environment against DNS hijacks with searches that help you detect and investigate unauthorized changes to DNS records. narrative = Dubbed the Achilles heel of the Internet (see https://www.f5.com/labs/articles/threat-intelligence/dns-is-still-the-achilles-heel-of-the-internet-25613), DNS plays a critical role in routing web traffic but is notoriously vulnerable to attack. One reason is its distributed nature. It relies on unstructured connections between millions of clients and servers over inherently insecure protocols.\ The gravity and extent of the importance of securing DNS from attacks is undeniable. The fallout of compromised DNS can be disastrous. Not only can hackers bring down an entire business, they can intercept confidential information, emails, and login credentials, as well. \ @@ -323,10 +345,21 @@ version = 1 references = ["https://www.cisecurity.org/controls/data-protection/", "https://www.sans.org/reading-room/whitepapers/dns/splunk-detect-dns-tunneling-37022", "https://umbrella.cisco.com/blog/2013/04/15/on-the-trail-of-malicious-dynamic-dns-domains/"] maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - Detection of DNS Tunnels - Rule", "ESCU - Detect USB device insertion - Rule", "ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task"] +searches = ["ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - Detect USB device insertion - Rule", "ESCU - Detection of DNS Tunnels - Rule", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Fortify your data-protection arsenal--while continuing to ensure data confidentiality and integrity--with searches that monitor for and help you investigate possible signs of data exfiltration. narrative = Attackers can leverage a variety of resources to compromise or exfiltrate enterprise data. Common exfiltration techniques include remote-access channels via low-risk, high-payoff active-collections operations and close-access operations using insiders and removable media. While this Analytic Story is not a comprehensive listing of all the methods by which attackers can exfiltrate data, it provides a useful starting point. +[analytic_story://Deobfuscate-Decode Files or Information] +category = Adversary Tactics +last_updated = 2021-03-24 +version = 1 +references = ["https://attack.mitre.org/techniques/T1140/"] +maintainers = [{"company": "Splunk", "email": "-", "name": "Michael Haag"}] +spec_version = 3 +searches = ["ESCU - CertUtil With Decode Argument - Rule"] +description = Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis. +narrative = An example of obfuscated files is `Certutil.exe` usage to encode a portable executable to a certificate file, which is base64 encoded, to hide the originating file. There are many utilities cross-platform to encode using XOR, using compressed .cab files to hide contents and scripting languages that may perform similar native Windows tasks. Triaging an event related will require the capability to review related process events and file modifications. Using a tool such as CyberChef will assist with identifying the encoding that was used, and potentially assist with decoding the contents. + [analytic_story://Detect Zerologon Attack] category = Adversary Tactics last_updated = 2020-09-18 @@ -334,7 +367,7 @@ version = 1 references = ["https://attack.mitre.org/wiki/Technique/T1003", "https://github.com/SecuraBV/CVE-2020-1472", "https://www.secura.com/blog/zero-logon", "https://nvd.nist.gov/vuln/detail/CVE-2020-1472"] maintainers = [{"company": "Jose Hernandez, Stan Miskowicz, David Dorsey, Shannon Davis Splunk", "email": "-", "name": "Rod Soto"}] spec_version = 3 -searches = ["ESCU - Detect Mimikatz Using Loaded Images - Rule", "ESCU - Detect Computer Changed with Anonymous Account - Rule", "ESCU - Detect Credential Dumping through LSASS access - Rule", "ESCU - Detect Zerologon via Zeek - Rule", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Detect Credential Dumping through LSASS access - Rule", "ESCU - Detect Zerologon via Zeek - Rule", "ESCU - Detect Computer Changed with Anonymous Account - Rule", "ESCU - Detect Mimikatz Using Loaded Images - Rule", "ESCU - Get Notable History - Response Task"] description = Uncover activity related to the execution of Zerologon CVE-2020-11472, a technique wherein attackers target a Microsoft Windows Domain Controller to reset its computer account password. The result from this attack is attackers can now provide themselves high privileges and take over Domain Controller. The included searches in this Analytic Story are designed to identify attempts to reset Domain Controller Computer Account via exploit code remotely or via the use of tool Mimikatz as payload carrier. narrative = This attack is a privilege escalation technique, where attacker targets a Netlogon secure channel connection to a domain controller, using Netlogon Remote Protocol (MS-NRPC). This vulnerability exposes vulnerable Windows Domain Controllers to be targeted via unaunthenticated RPC calls which eventually reset Domain Contoller computer account ($) providing the attacker the opportunity to exfil domain controller credential secrets and assign themselve high privileges that can lead to domain controller and potentially complete network takeover. The detection searches in this Analytic Story use Windows Event viewer events and Sysmon events to detect attack execution, these searches monitor access to the Local Security Authority Subsystem Service (LSASS) process which is an indicator of the use of Mimikatz tool which has bee updated to carry this attack payload. @@ -345,7 +378,7 @@ version = 2 references = ["https://attack.mitre.org/wiki/Technique/T1089", "https://blog.malwarebytes.com/cybercrime/2015/11/vonteera-adware-uses-certificates-to-disable-anti-malware/", "https://www.operationblockbuster.com/wp-content/uploads/2016/02/Operation-Blockbuster-Tools-Report.pdf"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}] spec_version = 3 -searches = ["ESCU - Attempt To Add Certificate To Untrusted Store - Rule", "ESCU - Attempt To Stop Security Service - Rule", "ESCU - Processes launching netsh - Rule", "ESCU - Unload Sysmon Filter Driver - Rule", "ESCU - Suspicious Reg exe Process - Rule", "ESCU - Sc exe Manipulating Windows Services - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Attempt To Add Certificate To Untrusted Store - Rule", "ESCU - Sc exe Manipulating Windows Services - Rule", "ESCU - Attempt To Stop Security Service - Rule", "ESCU - Unload Sysmon Filter Driver - Rule", "ESCU - Suspicious Reg exe Process - Rule", "ESCU - Processes launching netsh - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Looks for activities and techniques associated with the disabling of security tools on a Windows system, such as suspicious `reg.exe` processes, processes launching netsh, and many others. narrative = Attackers employ a variety of tactics in order to avoid detection and operate without barriers. This often involves modifying the configuration of security tools to get around them or explicitly disabling them to prevent them from running. This Analytic Story includes searches that look for activity consistent with attackers attempting to disable various security mechanisms. Such activity may involve monitoring for suspicious registry activity, as this is where much of the configuration for Windows and various other programs reside, or explicitly attempting to shut down security-related services. Other times, attackers attempt various tricks to prevent specific programs from running, such as adding the certificates with which the security tools are signed to a block list (which would prevent them from running). @@ -356,7 +389,7 @@ version = 2 references = ["https://www.fireeye.com/blog/threat-research/2017/09/apt33-insights-into-iranian-cyber-espionage.html", "https://umbrella.cisco.com/blog/2013/04/15/on-the-trail-of-malicious-dynamic-dns-domains/", "http://www.noip.com/blog/2014/07/11/dynamic-dns-can-use-2/", "https://www.splunk.com/blog/2015/08/04/detecting-dynamic-dns-domains-in-splunk.html"] maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - Detect web traffic to dynamic domain providers - Rule", "ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - Detect web traffic to dynamic domain providers - Rule", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Notable History - Response Task"] description = Detect and investigate hosts in your environment that may be communicating with dynamic domain providers. Attackers may leverage these services to help them avoid firewall blocks and deny lists. narrative = Dynamic DNS services (DDNS) are legitimate low-cost or free services that allow users to rapidly update domain resolutions to IP infrastructure. While their usage can be benign, malicious actors can abuse DDNS to host harmful payloads or interactive-command-and-control infrastructure. These attackers will manually update or automate domain resolution changes by routing dynamic domains to IP addresses that circumvent firewall blocks and deny lists and frustrate a network defender's analytic and investigative processes. These searches will look for DNS queries made from within your infrastructure to suspicious dynamic domains and then investigate more deeply, when appropriate. While this list of top-level dynamic domains is not exhaustive, it can be dynamically updated as new suspicious dynamic domains are identified. @@ -367,7 +400,7 @@ version = 1 references = ["https://www.us-cert.gov/ncas/alerts/TA18-201A", "https://www.first.org/resources/papers/conf2017/Advanced-Incident-Detection-and-Threat-Hunting-using-Sysmon-and-Splunk.pdf", "https://www.vkremez.com/2017/05/emotet-banking-trojan-malware-analysis.html"] maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Email Attachments With Lots Of Spaces - Rule", "ESCU - Suspicious Email Attachment Extensions - Rule", "ESCU - Prohibited Software On Endpoint - Rule", "ESCU - Detection of tools built by NirSoft - Rule", "ESCU - Detect Rare Executables - Rule", "ESCU - Detect Use of cmd exe to Launch Script Interpreters - Rule", "ESCU - SMB Traffic Spike - Rule", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get History Of Email Sources - Response Task"] +searches = ["ESCU - SMB Traffic Spike - Rule", "ESCU - Suspicious Email Attachment Extensions - Rule", "ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - Detection of tools built by NirSoft - Rule", "ESCU - Detect Use of cmd exe to Launch Script Interpreters - Rule", "ESCU - Detect Rare Executables - Rule", "ESCU - Prohibited Software On Endpoint - Rule", "ESCU - Email Attachments With Lots Of Spaces - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Detect rarely used executables, specific registry paths that may confer malware survivability and persistence, instances where cmd.exe is used to launch script interpreters, and other indicators that the Emotet financial malware has compromised your environment. narrative = The trojan downloader known as Emotet first surfaced in 2014, when it was discovered targeting the banking industry to steal credentials. However, according to a joint technical alert (TA) issued by three government agencies (https://www.us-cert.gov/ncas/alerts/TA18-201A), Emotet has evolved far beyond those beginnings to become what a ThreatPost article called a threat-delivery service(see https://threatpost.com/emotet-malware-evolves-beyond-banking-to-threat-delivery-service/134342/). For example, in early 2018, Emotet was found to be using its loader function to spread the Quakbot and Ransomware variants. \ According to the TA, the the malware continues to be among the most costly and destructive malware affecting the private and public sectors. Researchers have linked it to the threat group Mealybug, which has also been on the security communitys radar since 2014.\ @@ -391,7 +424,7 @@ version = 1 references = ["https://cloud.google.com/iam/docs/understanding-service-accounts"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rod Soto"}] spec_version = 3 -searches = ["ESCU - GCP Detect accounts with high risk roles by project - Rule", "ESCU - GCP Detect high risk permissions by resource and account - Rule", "ESCU - gcp detect oauth token abuse - Rule", "ESCU - GCP Detect gcploit framework - Rule", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - gcp detect oauth token abuse - Rule", "ESCU - GCP Detect accounts with high risk roles by project - Rule", "ESCU - GCP Detect gcploit framework - Rule", "ESCU - GCP Detect high risk permissions by resource and account - Rule", "ESCU - Get Notable History - Response Task"] description = Track when a user assumes an IAM role in another GCP account to obtain cross-account access to services and resources in that account. Accessing new roles could be an indication of malicious activity. narrative = Google Cloud Platform (GCP) admins manage access to GCP resources and services across the enterprise using GCP Identity and Access Management (IAM) functionality. IAM provides the ability to create and manage GCP users, groups, and roles-each with their own unique set of privileges and defined access to specific resources (such as Compute instances, the GCP Management Console, API, or the command-line interface). Unlike conventional (human) users, IAM roles are potentially assumable by anyone in the organization. They provide users with dynamically created temporary security credentials that expire within a set time period.\ In between the time between when the temporary credentials are issued and when they expire is a period of opportunity, where a user could leverage the temporary credentials to wreak havoc-spin up or remove instances, create new users, elevate privileges, and other malicious activities-throughout the environment.\ @@ -404,7 +437,7 @@ version = 1 references = ["https://www.splunk.com/en_us/blog/security/detecting-hafnium-exchange-server-zero-day-activity-in-splunk.html", "https://www.volexity.com/blog/2021/03/02/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities/", "https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/", "https://blog.rapid7.com/2021/03/03/rapid7s-insightidr-enables-detection-and-response-to-microsoft-exchange-0-day/"] maintainers = [{"company": "Splunk", "email": "-", "name": "Michael Haag"}] spec_version = 3 -searches = ["ESCU - Dump LSASS via procdump Rename - Rule", "ESCU - Detect Exchange Web Shell - Rule", "ESCU - Dump LSASS via procdump - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - Attempt To Set Default PowerShell Execution Policy To Unrestricted or Bypass - Rule", "ESCU - Ntdsutil Export NTDS - Rule", "ESCU - Unified Messaging Service Spawning a Process - Rule", "ESCU - Detect New Local Admin account - Rule", "ESCU - Email servers sending high volume traffic to hosts - Rule", "ESCU - Nishang PowershellTCPOneLine - Rule", "ESCU - Any Powershell DownloadString - Rule", "ESCU - Malicious PowerShell Process - Connect To Internet With Hidden Window - Rule", "ESCU - Malicious PowerShell Process - Execution Policy Bypass - Rule", "ESCU - Dump LSASS via comsvcs DLL - Rule", "ESCU - W3WP Spawning Shell - Rule"] +searches = ["ESCU - Email servers sending high volume traffic to hosts - Rule", "ESCU - Dump LSASS via procdump Rename - Rule", "ESCU - Detect Exchange Web Shell - Rule", "ESCU - Dump LSASS via comsvcs DLL - Rule", "ESCU - W3WP Spawning Shell - Rule", "ESCU - Detect New Local Admin account - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - Nishang PowershellTCPOneLine - Rule", "ESCU - Any Powershell DownloadString - Rule", "ESCU - Unified Messaging Service Spawning a Process - Rule", "ESCU - Ntdsutil Export NTDS - Rule", "ESCU - Dump LSASS via procdump - Rule", "ESCU - Malicious PowerShell Process - Connect To Internet With Hidden Window - Rule", "ESCU - Attempt To Set Default PowerShell Execution Policy To Unrestricted or Bypass - Rule", "ESCU - Malicious PowerShell Process - Execution Policy Bypass - Rule"] description = HAFNIUM group was identified by Microsoft as exploiting 4 Microsoft Exchange CVEs in the wild - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065. narrative = On Tuesday, March 2, 2021, Microsoft released a set of security patches for its mail server, Microsoft Exchange. These patches respond to a group of vulnerabilities known to impact Exchange 2013, 2016, and 2019. It is important to note that an Exchange 2010 security update has also been issued, though the CVEs do not reference that version as being vulnerable.\ While the CVEs do not shed much light on the specifics of the vulnerabilities or exploits, the first vulnerability (CVE-2021-26855) has a remote network attack vector that allows the attacker, a group Microsoft named HAFNIUM, to authenticate as the Exchange server. Three additional vulnerabilities (CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065) were also identified as part of this activity. When chained together along with CVE-2021-26855 for initial access, the attacker would have complete control over the Exchange server. This includes the ability to run code as SYSTEM and write to any path on the server.\ @@ -417,7 +450,7 @@ version = 2 references = ["https://www.us-cert.gov/HIDDEN-COBRA-North-Korean-Malicious-Cyber-Activity", "https://www.operationblockbuster.com/wp-content/uploads/2016/02/Operation-Blockbuster-Destructive-Malware-Report.pdf"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}] spec_version = 3 -searches = ["ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - DNS Query Length With High Standard Deviation - Rule", "ESCU - Create or delete windows shares using net exe - Rule", "ESCU - Remote Desktop Network Traffic - Rule", "ESCU - Suspicious File Write - Rule", "ESCU - Detect Outbound SMB Traffic - Rule", "ESCU - DNS Query Length Outliers - MLTK - Rule", "ESCU - Remote Desktop Process Running On System - Rule", "ESCU - SMB Traffic Spike - Rule", "ESCU - First time seen command line argument - Rule", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Outbound Emails to Hidden Cobra Threat Actors - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Investigate Successful Remote Desktop Authentications - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task"] +searches = ["ESCU - SMB Traffic Spike - Rule", "ESCU - DNS Query Length Outliers - MLTK - Rule", "ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - Suspicious File Write - Rule", "ESCU - Remote Desktop Process Running On System - Rule", "ESCU - Create or delete windows shares using net exe - Rule", "ESCU - Detect Outbound SMB Traffic - Rule", "ESCU - Remote Desktop Network Traffic - Rule", "ESCU - First time seen command line argument - Rule", "ESCU - DNS Query Length With High Standard Deviation - Rule", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Investigate Successful Remote Desktop Authentications - Response Task", "ESCU - Get Outbound Emails to Hidden Cobra Threat Actors - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Monitor for and investigate activities, including the creation or deletion of hidden shares and file writes, that may be evidence of infiltration by North Korean government-sponsored cybercriminals. Details of this activity were reported in DHS Report TA-18-149A. narrative = North Korea's government-sponsored "cyber army" has been slowly building momentum and gaining sophistication over the last 15 years or so. As a result, the group's activity, which the US government refers to as "Hidden Cobra," has surreptitiously crept onto the collective radar as a preeminent global threat.\ These state-sponsored actors are thought to be responsible for everything from a hack on a South Korean nuclear plant to an attack on Sony in anticipation of its release of the movie "The Interview" at the end of 2014. They're also notorious for cyberespionage. In recent years, the group seems to be focused on financial crimes, such as cryptojacking.\ @@ -431,10 +464,21 @@ version = 1 references = ["https://blog.malwarebytes.com/cybercrime/2016/09/hosts-file-hijacks/"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}] spec_version = 3 -searches = ["ESCU - Windows hosts file modification - Rule", "ESCU - Clients Connecting to Multiple DNS Servers - Rule", "ESCU - DNS Query Requests Resolved by Unauthorized DNS Servers - Rule", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Clients Connecting to Multiple DNS Servers - Rule", "ESCU - Windows hosts file modification - Rule", "ESCU - DNS Query Requests Resolved by Unauthorized DNS Servers - Rule", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Notable History - Response Task"] description = Detect evidence of tactics used to redirect traffic from a host to a destination other than the one intended--potentially one that is part of an adversary's attack infrastructure. An example is redirecting communications regarding patches and updates or misleading users into visiting a malicious website. narrative = Attackers will often attempt to manipulate client communications for nefarious purposes. In some cases, an attacker may endeavor to modify a local host file to redirect communications with resources (such as antivirus or system-update services) to prevent clients from receiving patches or updates. In other cases, an attacker might use this tactic to have the client connect to a site that looks like the intended site, but instead installs malware or collects information from the victim. Additionally, an attacker may redirect a victim in order to execute a MITM attack and observe communications. +[analytic_story://Ingress Tool Transfer] +category = Adversary Tactics +last_updated = 2021-03-24 +version = 1 +references = ["https://attack.mitre.org/techniques/T1105/"] +maintainers = [{"company": "Splunk", "email": "-", "name": "Michael Haag"}] +spec_version = 3 +searches = ["ESCU - Suspicious Curl Network Connection - Rule", "ESCU - CertUtil Download With URLCache and Split Arguments - Rule", "ESCU - CertUtil Download With VerifyCtl and Split Arguments - Rule"] +description = Adversaries may transfer tools or other files from an external system into a compromised environment. Files may be copied from an external adversary controlled system through the command and control channel to bring tools into the victim network or through alternate protocols with another tool such as FTP. +narrative = Ingress tool transfer is a Technique under tactic Command and Control. Behaviors will include the use of living off the land binaries to download implants or binaries over alternate communication ports. It is imperative to baseline applications on endpoints to understand what generates network activity, to where, and what is its native behavior. These utilities, when abused, will write files to disk in world writeable paths.\ During triage, review the reputation of the remote public destination IP or domain. Capture any files written to disk and perform analysis. Review other parrallel processes for additional behaviors. + [analytic_story://JBoss Vulnerability] category = Vulnerability last_updated = 2017-09-14 @@ -467,7 +511,7 @@ version = 1 references = ["https://github.com/splunk/cloud-datamodel-security-research"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rod Soto"}] spec_version = 3 -searches = ["ESCU - Kubernetes Azure scan fingerprint - Rule", "ESCU - GCP Kubernetes cluster pod scan detection - Rule", "ESCU - Kubernetes Azure pod scan fingerprint - Rule", "ESCU - GCP Kubernetes cluster scan detection - Rule", "ESCU - Amazon EKS Kubernetes Pod scan detection - Rule", "ESCU - Amazon EKS Kubernetes cluster scan detection - Rule", "ESCU - GCP Kubernetes activity by src ip - Response Task", "ESCU - Amazon EKS Kubernetes activity by src ip - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Amazon EKS Kubernetes Pod scan detection - Rule", "ESCU - Kubernetes Azure scan fingerprint - Rule", "ESCU - Kubernetes Azure pod scan fingerprint - Rule", "ESCU - GCP Kubernetes cluster pod scan detection - Rule", "ESCU - Amazon EKS Kubernetes cluster scan detection - Rule", "ESCU - GCP Kubernetes cluster scan detection - Rule", "ESCU - GCP Kubernetes activity by src ip - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Amazon EKS Kubernetes activity by src ip - Response Task"] description = This story addresses detection against Kubernetes cluster fingerprint scan and attack by providing information on items such as source ip, user agent, cluster names. narrative = Kubernetes is the most used container orchestration platform, this orchestration platform contains sensitve information and management priviledges of production workloads, microservices and applications. These searches allow operator to detect suspicious unauthenticated requests from the internet to kubernetes cluster. @@ -478,7 +522,7 @@ version = 1 references = ["https://www.splunk.com/en_us/blog/security/approaching-kubernetes-security-detecting-kubernetes-scan-with-splunk.html"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rod Soto"}] spec_version = 3 -searches = ["ESCU - Kubernetes GCP detect sensitive object access - Rule", "ESCU - Kubernetes GCP detect service accounts forbidden failure access - Rule", "ESCU - Kubernetes Azure detect sensitive object access - Rule", "ESCU - Kubernetes AWS detect suspicious kubectl calls - Rule", "ESCU - Kubernetes AWS detect service accounts forbidden failure access - Rule", "ESCU - Kubernetes Azure detect suspicious kubectl calls - Rule", "ESCU - Kubernetes Azure detect service accounts forbidden failure access - Rule", "ESCU - Kubernetes GCP detect suspicious kubectl calls - Rule", "ESCU - AWS EKS Kubernetes cluster sensitive object access - Rule", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Kubernetes GCP detect sensitive object access - Rule", "ESCU - AWS EKS Kubernetes cluster sensitive object access - Rule", "ESCU - Kubernetes AWS detect service accounts forbidden failure access - Rule", "ESCU - Kubernetes GCP detect suspicious kubectl calls - Rule", "ESCU - Kubernetes Azure detect service accounts forbidden failure access - Rule", "ESCU - Kubernetes AWS detect suspicious kubectl calls - Rule", "ESCU - Kubernetes Azure detect sensitive object access - Rule", "ESCU - Kubernetes Azure detect suspicious kubectl calls - Rule", "ESCU - Kubernetes GCP detect service accounts forbidden failure access - Rule", "ESCU - Get Notable History - Response Task"] description = This story addresses detection and response of accounts acccesing Kubernetes cluster sensitive objects such as configmaps or secrets providing information on items such as user user, group. object, namespace and authorization reason. narrative = Kubernetes is the most used container orchestration platform, this orchestration platform contains sensitive objects within its architecture, specifically configmaps and secrets, if accessed by an attacker can lead to further compromise. These searches allow operator to detect suspicious requests against Kubernetes sensitive objects. @@ -489,7 +533,7 @@ version = 1 references = ["https://www.splunk.com/en_us/blog/security/approaching-kubernetes-security-detecting-kubernetes-scan-with-splunk.html"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rod Soto"}] spec_version = 3 -searches = ["ESCU - Kubernetes GCP detect sensitive role access - Rule", "ESCU - Kubernetes Azure detect RBAC authorization by account - Rule", "ESCU - Kubernetes AWS detect sensitive role access - Rule", "ESCU - Kubernetes AWS detect RBAC authorization by account - Rule", "ESCU - Kubernetes Azure detect sensitive role access - Rule", "ESCU - Kubernetes GCP detect RBAC authorizations by account - Rule", "ESCU - Kubernetes Azure detect most active service accounts by pod namespace - Rule", "ESCU - Kubernetes AWS detect most active service accounts by pod - Rule", "ESCU - Kubernetes GCP detect most active service accounts by pod - Rule", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Kubernetes Azure detect sensitive role access - Rule", "ESCU - Kubernetes Azure detect most active service accounts by pod namespace - Rule", "ESCU - Kubernetes GCP detect most active service accounts by pod - Rule", "ESCU - Kubernetes Azure detect RBAC authorization by account - Rule", "ESCU - Kubernetes AWS detect most active service accounts by pod - Rule", "ESCU - Kubernetes AWS detect RBAC authorization by account - Rule", "ESCU - Kubernetes GCP detect RBAC authorizations by account - Rule", "ESCU - Kubernetes GCP detect sensitive role access - Rule", "ESCU - Kubernetes AWS detect sensitive role access - Rule", "ESCU - Get Notable History - Response Task"] description = This story addresses detection and response around Sensitive Role usage within a Kubernetes clusters against cluster resources and namespaces. narrative = Kubernetes is the most used container orchestration platform, this orchestration platform contains sensitive roles within its architecture, specifically configmaps and secrets, if accessed by an attacker can lead to further compromise. These searches allow operator to detect suspicious requests against Kubernetes role activities @@ -500,7 +544,7 @@ version = 2 references = ["https://www.fireeye.com/blog/executive-perspective/2015/08/malware_lateral_move.html"] maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}] spec_version = 3 -searches = ["ESCU - Kerberoasting spn request with RC4 encryption - Rule", "ESCU - Detect Activity Related to Pass the Hash Attacks - Rule", "ESCU - Remote Desktop Network Traffic - Rule", "ESCU - Remote Desktop Process Running On System - Rule", "ESCU - Schtasks scheduling job on remote system - Rule", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Investigate Successful Remote Desktop Authentications - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get History Of Email Sources - Response Task"] +searches = ["ESCU - Remote Desktop Process Running On System - Rule", "ESCU - Kerberoasting spn request with RC4 encryption - Rule", "ESCU - Remote Desktop Network Traffic - Rule", "ESCU - Schtasks scheduling job on remote system - Rule", "ESCU - Detect Activity Related to Pass the Hash Attacks - Rule", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Investigate Successful Remote Desktop Authentications - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Detect and investigate tactics, techniques, and procedures around how attackers move laterally within the enterprise. Because lateral movement can expose the adversary to detection, it should be an important focus for security analysts. narrative = Once attackers gain a foothold within an enterprise, they will seek to expand their accesses and leverage techniques that facilitate lateral movement. Attackers will often spend quite a bit of time and effort moving laterally. Because lateral movement renders an attacker the most vulnerable to detection, it's an excellent focus for detection and investigation.\ Indications of lateral movement can include the abuse of system utilities (such as `psexec.exe`), unauthorized use of remote desktop services, `file/admin$` shares, WMI, PowerShell, pass-the-hash, or the abuse of scheduled tasks. Organizations must be extra vigilant in detecting lateral movement techniques and look for suspicious activity in and around high-value strategic network assets, such as Active Directory, which are often considered the primary target or "crown jewels" to a persistent threat actor.\ @@ -515,7 +559,7 @@ version = 4 references = ["https://blogs.mcafee.com/mcafee-labs/malware-employs-powershell-to-infect-systems/", "https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/"] maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}] spec_version = 3 -searches = ["ESCU - Attempt To Set Default PowerShell Execution Policy To Unrestricted or Bypass - Rule", "ESCU - Malicious PowerShell Process - Encoded Command - Rule", "ESCU - Malicious PowerShell Process - Multiple Suspicious Command-Line Arguments - Rule", "ESCU - Any Powershell DownloadFile - Rule", "ESCU - Malicious PowerShell Process With Obfuscation Techniques - Rule", "ESCU - Any Powershell DownloadString - Rule", "ESCU - Malicious PowerShell Process - Connect To Internet With Hidden Window - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Malicious PowerShell Process - Multiple Suspicious Command-Line Arguments - Rule", "ESCU - Malicious PowerShell Process - Encoded Command - Rule", "ESCU - Any Powershell DownloadString - Rule", "ESCU - Malicious PowerShell Process With Obfuscation Techniques - Rule", "ESCU - Any Powershell DownloadFile - Rule", "ESCU - Malicious PowerShell Process - Connect To Internet With Hidden Window - Rule", "ESCU - Attempt To Set Default PowerShell Execution Policy To Unrestricted or Bypass - Rule", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Attackers are finding stealthy ways "live off the land," leveraging utilities and tools that come standard on the endpoint--such as PowerShell--to achieve their goals without downloading binary files. These searches can help you detect and investigate PowerShell command-line options that may be indicative of malicious intent. narrative = The searches in this Analytic Story monitor for parameters often used for malicious purposes. It is helpful to understand how often the notable events generated by this story occur, as well as the commonalities between some of these events. These factors may provide clues about whether this is a common occurrence of minimal concern or a rare event that may require more extensive investigation. Likewise, it is important to determine whether the issue is restricted to a single user/system or is broader in scope.\ The following factors may assist you in determining whether the event is malicious: \ @@ -535,7 +579,7 @@ version = 1 references = ["https://www.carbonblack.com/2016/03/04/tracking-locky-ransomware-using-carbon-black/"] maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}] spec_version = 3 -searches = ["ESCU - Extended Period Without Successful Netbackup Backups - Rule", "ESCU - Unsuccessful Netbackup backups - Rule", "ESCU - All backup logs for host - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Unsuccessful Netbackup backups - Rule", "ESCU - Extended Period Without Successful Netbackup Backups - Rule", "ESCU - All backup logs for host - Response Task", "ESCU - Get Notable History - Response Task"] description = Address common concerns when monitoring your backup processes. These searches can help you reduce risks from ransomware, device theft, or denial of physical access to a host by backing up data on endpoints. narrative = Having backups is a standard best practice that helps ensure continuity of business operations. Having mature backup processes can also help you reduce the risks of many security-related incidents and streamline your response processes. The detection searches in this Analytic Story will help you identify systems that have backup failures, as well as systems that have not been backed up for an extended period of time. The story will also return the notable event history and all of the backup logs for an endpoint. @@ -571,7 +615,7 @@ version = 2 references = ["https://www.microsoft.com/security/blog/2021/03/04/goldmax-goldfinder-sibot-analyzing-nobelium-malware/", "https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html", "https://msrc-blog.microsoft.com/2020/12/13/customer-guidance-on-recent-nation-state-cyber-attacks/"] maintainers = [{"company": "Michael Haag, Splunk", "email": "-", "name": "Patrick Bareiss"}] spec_version = 3 -searches = ["ESCU - Supernova Webshell - Rule", "ESCU - Malicious PowerShell Process - Encoded Command - Rule", "ESCU - Detect Prohibited Applications Spawning cmd exe - Rule", "ESCU - Sc exe Manipulating Windows Services - Rule", "ESCU - Sunburst Correlation DLL and Network Event - Rule", "ESCU - Detect Outbound SMB Traffic - Rule", "ESCU - Detect Rundll32 Inline HTA Execution - Rule", "ESCU - Scheduled Task Deleted Or Created via CMD - Rule", "ESCU - Windows AdFind Exe - Rule", "ESCU - TOR Traffic - Rule", "ESCU - First Time Seen Running Windows Service - Rule", "ESCU - Schtasks scheduling job on remote system - Rule"] +searches = ["ESCU - Malicious PowerShell Process - Encoded Command - Rule", "ESCU - Sc exe Manipulating Windows Services - Rule", "ESCU - Supernova Webshell - Rule", "ESCU - Sunburst Correlation DLL and Network Event - Rule", "ESCU - Windows AdFind Exe - Rule", "ESCU - Detect Prohibited Applications Spawning cmd exe - Rule", "ESCU - Detect Rundll32 Inline HTA Execution - Rule", "ESCU - First Time Seen Running Windows Service - Rule", "ESCU - Detect Outbound SMB Traffic - Rule", "ESCU - TOR Traffic - Rule", "ESCU - Scheduled Task Deleted Or Created via CMD - Rule", "ESCU - Schtasks scheduling job on remote system - Rule"] description = Sunburst is a trojanized updates to SolarWinds Orion IT monitoring and management software. It was discovered by FireEye in December 2020. The actors behind this campaign gained access to numerous public and private organizations around the world. narrative = This Analytic Story supports you to detect Tactics, Techniques and Procedures (TTPs) of the NOBELIUM Group. The threat actor behind sunburst compromised the SolarWinds.Orion.Core.BusinessLayer.dll, is a SolarWinds digitally-signed component of the Orion software framework that contains a backdoor that communicates via HTTP to third party servers. The detections in this Analytic Story are focusing on the dll loading events, file create events and network events to detect This malware. @@ -582,7 +626,7 @@ version = 1 references = ["https://docs.microsoft.com/en-us/previous-versions/tn-archive/bb490939(v=technet.10)", "https://htmlpreview.github.io/?https://github.com/MatthewDemaske/blogbackup/blob/master/netshell.html", "http://blog.jpcert.or.jp/2016/01/windows-commands-abused-by-attackers.html"] maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - Processes launching netsh - Rule", "ESCU - Processes created by netsh - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Processes created by netsh - Rule", "ESCU - Processes launching netsh - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Detect activities and various techniques associated with the abuse of `netsh.exe`, which can disable local firewall settings or set up a remote connection to a host from an infected system. narrative = It is a common practice for attackers of all types to leverage native Windows tools and functionality to execute commands for malicious reasons. One such tool on Windows OS is `netsh.exe`,a command-line scripting utility that allows you to--either locally or remotely--display or modify the network configuration of a computer that is currently running. `Netsh.exe` can be used to discover and disable local firewall settings. It can also be used to set up a remote connection to a host from an infected system.\ To get started, run the detection search to identify parent processes of `netsh.exe`. @@ -594,7 +638,7 @@ version = 1 references = ["https://i.blackhat.com/USA-20/Thursday/us-20-Bienstock-My-Cloud-Is-APTs-Cloud-Investigating-And-Defending-Office-365.pdf"] maintainers = [{"company": "Splunk", "email": "-", "name": "Patrick Bareiss"}] spec_version = 3 -searches = ["ESCU - O365 Suspicious Rights Delegation - Rule", "ESCU - O365 Disable MFA - Rule", "ESCU - O365 Excessive SSO logon errors - Rule", "ESCU - O365 Suspicious User Email Forwarding - Rule", "ESCU - O365 PST export alert - Rule", "ESCU - O365 Added Service Principal - Rule", "ESCU - O365 New Federated Domain Added - Rule", "ESCU - O365 Add App Role Assignment Grant User - Rule", "ESCU - High Number of Login Failures from a single source - Rule", "ESCU - O365 Bypass MFA via Trusted IP - Rule", "ESCU - O365 Suspicious Admin Email Forwarding - Rule", "ESCU - O365 Excessive Authentication Failures Alert - Rule"] +searches = ["ESCU - O365 PST export alert - Rule", "ESCU - O365 Bypass MFA via Trusted IP - Rule", "ESCU - O365 New Federated Domain Added - Rule", "ESCU - O365 Excessive SSO logon errors - Rule", "ESCU - O365 Suspicious Admin Email Forwarding - Rule", "ESCU - O365 Disable MFA - Rule", "ESCU - O365 Add App Role Assignment Grant User - Rule", "ESCU - O365 Suspicious User Email Forwarding - Rule", "ESCU - O365 Suspicious Rights Delegation - Rule", "ESCU - O365 Added Service Principal - Rule", "ESCU - High Number of Login Failures from a single source - Rule", "ESCU - O365 Excessive Authentication Failures Alert - Rule"] description = This story is focused around detecting Office 365 Attacks. narrative = More and more companies are using Microsofts Office 365 cloud offering. Therefore, we see more and more attacks against Office 365. This story provides various detections for Office 365 attacks. @@ -605,7 +649,7 @@ version = 2 references = ["https://www.symantec.com/blogs/threat-intelligence/orangeworm-targets-healthcare-us-europe-asia", "https://www.infosecurity-magazine.com/news/healthcare-targeted-by-hacker/"] maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}] spec_version = 3 -searches = ["ESCU - Sc exe Manipulating Windows Services - Rule", "ESCU - First Time Seen Running Windows Service - Rule", "ESCU - First time seen command line argument - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - First Time Seen Running Windows Service - Rule", "ESCU - First time seen command line argument - Rule", "ESCU - Sc exe Manipulating Windows Services - Rule", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Detect activities and various techniques associated with the Orangeworm Attack Group, a group that frequently targets the healthcare industry. narrative = In May of 2018, the attack group Orangeworm was implicated for installing a custom backdoor called Trojan.Kwampirs within large international healthcare corporations in the United States, Europe, and Asia. This malware provides the attackers with remote access to the target system, decrypting and extracting a copy of its main DLL payload from its resource section. Before writing the payload to disk, it inserts a randomly generated string into the middle of the decrypted payload in an attempt to evade hash-based detections.\ Awareness of the Orangeworm group first surfaced in January, 2015. It has conducted targeted attacks against related industries, as well, such as pharmaceuticals and healthcare IT solution providers.\ @@ -619,7 +663,7 @@ version = 1 references = ["https://www.fireeye.com/blog/threat-research/2019/04/spear-phishing-campaign-targets-ukraine-government.html"] maintainers = [{"company": "Splunk", "email": "-", "name": "Splunk Research Team"}] spec_version = 3 -searches = ["ESCU - Process Creating LNK file in Suspicious Location - Rule", "ESCU - Detect Oulook exe writing a zip file - Rule", "ESCU - Get Parent Process Info - Response Task"] +searches = ["ESCU - Detect Oulook exe writing a zip file - Rule", "ESCU - Process Creating LNK file in Suspicious Location - Rule", "ESCU - Get Parent Process Info - Response Task"] description = Detect signs of malicious payloads that may indicate that your environment has been breached via a phishing attack. narrative = Despite its simplicity, phishing remains the most pervasive and dangerous cyberthreat. In fact, research shows that as many as [91% of all successful attacks](https://digitalguardian.com/blog/91-percent-cyber-attacks-start-phishing-email-heres-how-protect-against-phishing) are initiated via a phishing email. \ As most people know, these emails use fraudulent domains, [email scraping](https://www.cyberscoop.com/emotet-trojan-phishing-scraping-templates-cofense-geodo/), familiar contact names inserted as senders, and other tactics to lure targets into clicking a malicious link, opening an attachment with a [nefarious payload](https://www.cyberscoop.com/emotet-trojan-phishing-scraping-templates-cofense-geodo/), or entering sensitive personal information that perpetrators may intercept. This attack technique requires a relatively low level of skill and allows adversaries to easily cast a wide net. Worse, because its success relies on the gullibility of humans, it's impossible to completely "automate" it out of your environment. However, you can use ES and ESCU to detect and investigate potentially malicious payloads injected into your environment subsequent to a phishing attack. \ @@ -637,7 +681,7 @@ version = 1 references = ["https://www.infosecurity-magazine.com/news/scope-of-mudcarp-attacks-highlight-1/", "http://blog.amossys.fr/badflick-is-not-so-bad.html"] maintainers = [{"company": "iDefense", "email": "-", "name": "iDefense Cyber Espionage Team"}] spec_version = 3 -searches = ["ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Unusually Long Command Line - Rule", "ESCU - Malicious PowerShell Process - Connect To Internet With Hidden Window - Rule", "ESCU - Unusually Long Command Line - MLTK - Rule", "ESCU - First time seen command line argument - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Malicious PowerShell Process - Connect To Internet With Hidden Window - Rule", "ESCU - Unusually Long Command Line - Rule", "ESCU - First time seen command line argument - Rule", "ESCU - Unusually Long Command Line - MLTK - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Monitor your environment for suspicious behaviors that resemble the techniques employed by the MUDCARP threat group. narrative = This story was created as a joint effort between iDefense and Splunk.\ iDefense analysts have recently discovered a Windows executable file that, upon execution, spoofs a decryption tool and then drops a file that appears to be the custom-built javascript backdoor, "Orz," which is associated with the threat actors known as MUDCARP (as well as "temp.Periscope" and "Leviathan"). The file is executed using Wscript.\ @@ -675,7 +719,7 @@ version = 1 references = ["http://www.novetta.com/2015/02/advanced-methods-to-detect-advanced-cyber-attacks-protocol-abuse/"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}] spec_version = 3 -searches = ["ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - Protocol or Port Mismatch - Rule", "ESCU - TOR Traffic - Rule", "ESCU - Prohibited Network Traffic Allowed - Rule", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Parent Process Info - Response Task"] +searches = ["ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - Protocol or Port Mismatch - Rule", "ESCU - Prohibited Network Traffic Allowed - Rule", "ESCU - TOR Traffic - Rule", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Detect instances of prohibited network traffic allowed in the environment, as well as protocols running on non-standard ports. Both of these types of behaviors typically violate policy and can be leveraged by attackers. narrative = A traditional security best practice is to control the ports, protocols, and services allowed within your environment. By limiting the services and protocols to those explicitly approved by policy, administrators can minimize the attack surface. The combined effect allows both network defenders and security controls to focus and not be mired in superfluous traffic or data types. Looking for deviations to policy can identify attacker activity that abuses services and protocols to run on alternate or non-standard ports in the attempt to avoid detection or frustrate forensic analysts. @@ -686,7 +730,7 @@ version = 1 references = ["https://www.carbonblack.com/2017/06/28/carbon-black-threat-research-technical-analysis-petya-notpetya-ransomware/", "https://www.splunk.com/blog/2017/06/27/closing-the-detection-to-mitigation-gap-or-to-petya-or-notpetya-whocares-.html"] maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}] spec_version = 3 -searches = ["ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - USN Journal Deletion - Rule", "ESCU - Schtasks used for forcing a reboot - Rule", "ESCU - Suspicious Scheduled Task from Public Directory - Rule", "ESCU - Common Ransomware Notes - Rule", "ESCU - TOR Traffic - Rule", "ESCU - WBAdmin Delete System Backups - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Unusually Long Command Line - MLTK - Rule", "ESCU - SMB Traffic Spike - Rule", "ESCU - Windows Event Log Cleared - Rule", "ESCU - Spike in File Writes - Rule", "ESCU - BCDEdit Failure Recovery Modification - Rule", "ESCU - Scheduled tasks used in BadRabbit ransomware - Rule", "ESCU - Deleting Shadow Copies - Rule", "ESCU - Suspicious wevtutil Usage - Rule", "ESCU - System Processes Run From Unexpected Locations - Rule", "ESCU - Common Ransomware Extensions - Rule", "ESCU - Remote Process Instantiation via WMI - Rule", "ESCU - Unusually Long Command Line - Rule", "ESCU - Prohibited Network Traffic Allowed - Rule", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Backup Logs For Endpoint - Response Task", "ESCU - Get Sysmon WMI Activity for Host - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get History Of Email Sources - Response Task"] +searches = ["ESCU - SMB Traffic Spike - Rule", "ESCU - Common Ransomware Notes - Rule", "ESCU - Unusually Long Command Line - MLTK - Rule", "ESCU - Scheduled tasks used in BadRabbit ransomware - Rule", "ESCU - Common Ransomware Extensions - Rule", "ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - Suspicious wevtutil Usage - Rule", "ESCU - Windows Event Log Cleared - Rule", "ESCU - Prohibited Network Traffic Allowed - Rule", "ESCU - USN Journal Deletion - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Schtasks used for forcing a reboot - Rule", "ESCU - Suspicious Scheduled Task from Public Directory - Rule", "ESCU - BCDEdit Failure Recovery Modification - Rule", "ESCU - TOR Traffic - Rule", "ESCU - Deleting Shadow Copies - Rule", "ESCU - Remote Process Instantiation via WMI - Rule", "ESCU - WBAdmin Delete System Backups - Rule", "ESCU - Unusually Long Command Line - Rule", "ESCU - Spike in File Writes - Rule", "ESCU - System Processes Run From Unexpected Locations - Rule", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Sysmon WMI Activity for Host - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Backup Logs For Endpoint - Response Task"] description = Leverage searches that allow you to detect and investigate unusual activities that might relate to ransomware--spikes in SMB traffic, suspicious wevtutil usage, the presence of common ransomware extensions, and system processes run from unexpected locations, and many others. narrative = Ransomware is an ever-present risk to the enterprise, wherein an infected host encrypts business-critical data, holding it hostage until the victim pays the attacker a ransom. There are many types and varieties of ransomware that can affect an enterprise. Attackers can deploy ransomware to enterprises through spearphishing campaigns and driveby downloads, as well as through traditional remote service-based exploitation. In the case of the WannaCry campaign, there was self-propagating wormable functionality that was used to maximize infection. Fortunately, organizations can apply several techniques--such as those in this Analytic Story--to detect and or mitigate the effects of ransomware. @@ -708,7 +752,7 @@ version = 1 references = ["https://www.fireeye.com/blog/executive-perspective/2015/09/the_new_route_toper.html", "https://www.cisco.com/c/en/us/about/security-center/event-response/synful-knock.html"] maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - Detect Port Security Violation - Rule", "ESCU - Detect IPv6 Network Infrastructure Threats - Rule", "ESCU - Detect New Login Attempts to Routers - Rule", "ESCU - Detect Rogue DHCP Server - Rule", "ESCU - Detect ARP Poisoning - Rule", "ESCU - Detect Traffic Mirroring - Rule", "ESCU - Detect Software Download To Network Device - Rule", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Detect IPv6 Network Infrastructure Threats - Rule", "ESCU - Detect Traffic Mirroring - Rule", "ESCU - Detect Software Download To Network Device - Rule", "ESCU - Detect Rogue DHCP Server - Rule", "ESCU - Detect Port Security Violation - Rule", "ESCU - Detect ARP Poisoning - Rule", "ESCU - Detect New Login Attempts to Routers - Rule", "ESCU - Get Notable History - Response Task"] description = Validate the security configuration of network infrastructure and verify that only authorized users and systems are accessing critical assets. Core routing and switching infrastructure are common strategic targets for attackers. narrative = Networking devices, such as routers and switches, are often overlooked as resources that attackers will leverage to subvert an enterprise. Advanced threats actors have shown a proclivity to target these critical assets as a means to siphon and redirect network traffic, flash backdoored operating systems, and implement cryptographic weakened algorithms to more easily decrypt network traffic.\ This Analytic Story helps you gain a better understanding of how your network devices are interacting with your hosts. By compromising your network devices, attackers can obtain direct access to the company's internal infrastructure— effectively increasing the attack surface and accessing private services/data. @@ -720,7 +764,7 @@ version = 1 references = ["https://www.splunk.com/en_us/blog/security/detecting-ryuk-using-splunk-attack-range.html", "https://www.crowdstrike.com/blog/big-game-hunting-with-ryuk-another-lucrative-targeted-ransomware/", "https://us-cert.cisa.gov/ncas/alerts/aa20-302a"] maintainers = [{"company": "Splunk", "email": "-", "name": "Jose Hernandez"}] spec_version = 3 -searches = ["ESCU - Spike in File Writes - Rule", "ESCU - BCDEdit Failure Recovery Modification - Rule", "ESCU - Remote Desktop Network Bruteforce - Rule", "ESCU - Suspicious Scheduled Task from Public Directory - Rule", "ESCU - Windows connhost exe started forcefully - Rule", "ESCU - Remote Desktop Network Traffic - Rule", "ESCU - Windows DisableAntiSpyware Registry - Rule", "ESCU - Ryuk Test Files Detected - Rule", "ESCU - Ryuk Wake on LAN Command - Rule", "ESCU - Common Ransomware Notes - Rule", "ESCU - NLTest Domain Trust Discovery - Rule", "ESCU - Windows Security Account Manager Stopped - Rule", "ESCU - Common Ransomware Extensions - Rule", "ESCU - WBAdmin Delete System Backups - Rule", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Ryuk Test Files Detected - Rule", "ESCU - Common Ransomware Extensions - Rule", "ESCU - Ryuk Wake on LAN Command - Rule", "ESCU - Windows connhost exe started forcefully - Rule", "ESCU - WBAdmin Delete System Backups - Rule", "ESCU - NLTest Domain Trust Discovery - Rule", "ESCU - Windows DisableAntiSpyware Registry - Rule", "ESCU - Suspicious Scheduled Task from Public Directory - Rule", "ESCU - BCDEdit Failure Recovery Modification - Rule", "ESCU - Remote Desktop Network Bruteforce - Rule", "ESCU - Remote Desktop Network Traffic - Rule", "ESCU - Common Ransomware Notes - Rule", "ESCU - Spike in File Writes - Rule", "ESCU - Windows Security Account Manager Stopped - Rule", "ESCU - Get Notable History - Response Task"] description = Leverage searches that allow you to detect and investigate unusual activities that might relate to the Ryuk ransomware, including looking for file writes associated with Ryuk, Stopping Security Access Manager, DisableAntiSpyware registry key modification, suspicious psexec use, and more. narrative = Cybersecurity Infrastructure Security Agency (CISA) released Alert (AA20-302A) on October 28th called “Ransomware Activity Targeting the Healthcare and Public Health Sector.” This alert details TTPs associated with ongoing and possible imminent attacks against the Healthcare sector, and is a joint advisory in coordination with other U.S. Government agencies. The objective of these malicious campaigns is to infiltrate targets in named sectors and to drop ransomware payloads, which will likely cause disruption of service and increase risk of actual harm to the health and safety of patients at hospitals, even with the aggravant of an ongoing COVID-19 pandemic. This document specifically refers to several crimeware exploitation frameworks, emphasizing the use of Ryuk ransomware as payload. The Ryuk ransomware payload is not new. It has been well documented and identified in multiple variants. Payloads need a carrier, and for Ryuk it has often been exploitation frameworks such as Cobalt Strike, or popular crimeware frameworks such as Emotet or Trickbot. @@ -743,7 +787,7 @@ version = 1 references = ["https://www.crowdstrike.com/blog/an-in-depth-analysis-of-samsam-ransomware-and-boss-spider/", "https://nakedsecurity.sophos.com/2018/07/31/samsam-the-almost-6-million-ransomware/", "https://thehackernews.com/2018/07/samsam-ransomware-attacks.html"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}] spec_version = 3 -searches = ["ESCU - Spike in File Writes - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - Remote Desktop Network Bruteforce - Rule", "ESCU - Detect malicious requests to exploit JBoss servers - Rule", "ESCU - Deleting Shadow Copies - Rule", "ESCU - Remote Desktop Network Traffic - Rule", "ESCU - Prohibited Software On Endpoint - Rule", "ESCU - Samsam Test File Write - Rule", "ESCU - Batch File Write to System32 - Rule", "ESCU - Detect attackers scanning for vulnerable JBoss servers - Rule", "ESCU - Common Ransomware Notes - Rule", "ESCU - Common Ransomware Extensions - Rule", "ESCU - File with Samsam Extension - Rule", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Backup Logs For Endpoint - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Investigate Successful Remote Desktop Authentications - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get History Of Email Sources - Response Task"] +searches = ["ESCU - Detect malicious requests to exploit JBoss servers - Rule", "ESCU - Detect attackers scanning for vulnerable JBoss servers - Rule", "ESCU - Common Ransomware Extensions - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - File with Samsam Extension - Rule", "ESCU - Samsam Test File Write - Rule", "ESCU - Batch File Write to System32 - Rule", "ESCU - Prohibited Software On Endpoint - Rule", "ESCU - Remote Desktop Network Bruteforce - Rule", "ESCU - Deleting Shadow Copies - Rule", "ESCU - Remote Desktop Network Traffic - Rule", "ESCU - Common Ransomware Notes - Rule", "ESCU - Spike in File Writes - Rule", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Investigate Successful Remote Desktop Authentications - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Backup Logs For Endpoint - Response Task"] description = Leverage searches that allow you to detect and investigate unusual activities that might relate to the SamSam ransomware, including looking for file writes associated with SamSam, RDP brute force attacks, the presence of files with SamSam ransomware extensions, suspicious psexec use, and more. narrative = The first version of the SamSam ransomware (a.k.a. Samas or SamsamCrypt) was launched in 2015 by a group of Iranian threat actors. The malicious software has affected and continues to affect thousands of victims and has raised almost $6M in ransom.\ Although categorized under the heading of ransomware, SamSam campaigns have some importance distinguishing characteristics. Most notable is the fact that conventional ransomware is a numbers game. Perpetrators use a "spray-and-pray" approach with phishing campaigns or other mechanisms, charging a small ransom (typically under $1,000). The goal is to find a large number of victims willing to pay these mini-ransoms, adding up to a lucrative payday. They use relatively simple methods for infecting systems.\ @@ -759,7 +803,7 @@ version = 1 references = ["https://redcanary.com/blog/clipping-silver-sparrows-wings/", "https://www.sentinelone.com/blog/5-things-you-need-to-know-about-silver-sparrow/"] maintainers = [{"company": "Splunk", "email": "-", "name": "Michael Haag"}] spec_version = 3 -searches = ["ESCU - Suspicious Curl Network Connection - Rule", "ESCU - Suspicious PlistBuddy Usage - Rule", "ESCU - Suspicious PlistBuddy Usage via OSquery - Rule", "ESCU - Suspicious SQLite3 LSQuarantine Behavior - Rule"] +searches = ["ESCU - Suspicious PlistBuddy Usage - Rule", "ESCU - Suspicious Curl Network Connection - Rule", "ESCU - Suspicious SQLite3 LSQuarantine Behavior - Rule", "ESCU - Suspicious PlistBuddy Usage via OSquery - Rule"] description = Silver Sparrow, identified by Red Canary Intelligence, is a new forward looking MacOS (Intel and M1) malicious software downloader utilizing JavaScript for execution and a launchAgent to establish persistence. narrative = Silver Sparrow works is a dropper and uses typical persistence mechanisms on a Mac. It is cross platform, covering both Intel and Apple M1 architecture. To this date, no implant has been downloaded for malicious purposes. During installation of the update.pkg or updater.pkg file, the malicious software utilizes JavaScript to generate files and scripts on disk for persistence.These files later download a implant from an S3 bucket every hour. This analytic assists with identifying different types of macOS malware families establishing LaunchAgent persistence. Per SentinelOne source, it is predicted that Silver Sparrow is likely selling itself as a mechanism to 3rd party “affiliates” or pay-per-install (PPI) partners, typically seen as commodity adware/malware. Additional indicators and behaviors may be found within the references. @@ -815,7 +859,7 @@ version = 1 references = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf"] maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - Abnormally High AWS Instances Launched by User - Rule", "ESCU - Abnormally High AWS Instances Terminated by User - Rule", "ESCU - Abnormally High AWS Instances Launched by User - MLTK - Rule", "ESCU - EC2 Instance Started In Previously Unseen Region - Rule", "ESCU - EC2 Instance Started With Previously Unseen User - Rule", "ESCU - Abnormally High AWS Instances Terminated by User - MLTK - Rule", "ESCU - Get Notable History - Response Task", "ESCU - AWS Investigate Security Hub alerts by dest - Response Task", "ESCU - Investigate AWS activities via region name - Response Task", "ESCU - Get EC2 Launch Details - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get EC2 Instance Details by instanceId - Response Task"] +searches = ["ESCU - Abnormally High AWS Instances Terminated by User - MLTK - Rule", "ESCU - Abnormally High AWS Instances Launched by User - Rule", "ESCU - EC2 Instance Started With Previously Unseen User - Rule", "ESCU - EC2 Instance Started In Previously Unseen Region - Rule", "ESCU - Abnormally High AWS Instances Terminated by User - Rule", "ESCU - Abnormally High AWS Instances Launched by User - MLTK - Rule", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get EC2 Instance Details by instanceId - Response Task", "ESCU - Investigate AWS activities via region name - Response Task", "ESCU - AWS Investigate Security Hub alerts by dest - Response Task", "ESCU - Get EC2 Launch Details - Response Task", "ESCU - Get Notable History - Response Task"] description = Use the searches in this Analytic Story to monitor your AWS EC2 instances for evidence of anomalous activity and suspicious behaviors, such as EC2 instances that originate from unusual locations or those launched by previously unseen users (among others). Included investigative searches will help you probe more deeply, when the information warrants it. narrative = AWS CloudTrail is an AWS service that helps you enable governance, compliance, and risk auditing within your AWS account. Actions taken by a user, role, or an AWS service are recorded as events in CloudTrail. It is crucial for a company to monitor events and actions taken in the AWS Console, AWS command-line interface, and AWS SDKs and APIs to ensure that your EC2 instances are not vulnerable to attacks. This Analytic Story identifies suspicious activities in your AWS EC2 instances and helps you respond and investigate those activities. @@ -826,7 +870,7 @@ version = 1 references = ["https://docs.aws.amazon.com/IAM/latest/UserGuide/cloudtrail-integration.html"] maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - Detect AWS Console Login by User from New Country - Rule", "ESCU - Detect new user AWS Console Login - Rule", "ESCU - Detect AWS Console Login by User from New City - Rule", "ESCU - Detect AWS Console Login by User from New Region - Rule", "ESCU - AWS Investigate User Activities By ARN - Response Task"] +searches = ["ESCU - Detect new user AWS Console Login - Rule", "ESCU - Detect AWS Console Login by User from New Country - Rule", "ESCU - Detect AWS Console Login by User from New City - Rule", "ESCU - Detect AWS Console Login by User from New Region - Rule", "ESCU - AWS Investigate User Activities By ARN - Response Task"] description = Monitor your AWS authentication events using your CloudTrail logs. Searches within this Analytic Story will help you stay aware of and investigate suspicious logins. narrative = It is important to monitor and control who has access to your AWS infrastructure. Detecting suspicious logins to your AWS infrastructure will provide good starting points for investigations. Abusive behaviors caused by compromised credentials can lead to direct monetary costs, as you will be billed for any EC2 instances created by the attacker. @@ -837,7 +881,7 @@ version = 2 references = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf", "https://www.tripwire.com/state-of-security/security-data-protection/cloud/public-aws-s3-buckets-writable/"] maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - Detect New Open S3 Buckets over AWS CLI - Rule", "ESCU - Detect S3 access from a new IP - Rule", "ESCU - Detect New Open S3 buckets - Rule", "ESCU - Detect Spike in S3 Bucket deletion - Rule", "ESCU - Get Notable History - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - AWS S3 Bucket details via bucketName - Response Task", "ESCU - Investigate AWS activities via region name - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task"] +searches = ["ESCU - Detect S3 access from a new IP - Rule", "ESCU - Detect New Open S3 Buckets over AWS CLI - Rule", "ESCU - Detect Spike in S3 Bucket deletion - Rule", "ESCU - Detect New Open S3 buckets - Rule", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - AWS S3 Bucket details via bucketName - Response Task", "ESCU - Investigate AWS activities via region name - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - Get Notable History - Response Task"] description = Use the searches in this Analytic Story to monitor your AWS S3 buckets for evidence of anomalous activity and suspicious behaviors, such as detecting open S3 buckets and buckets being accessed from a new IP. The contextual and investigative searches will give you more information, when required. narrative = As cloud computing has exploded, so has the number of creative attacks on virtual environments. And as the number-two cloud-service provider, Amazon Web Services (AWS) has certainly had its share.\ Amazon's "shared responsibility" model dictates that the company has responsibility for the environment outside of the VM and the customer is responsible for the security inside of the S3 container. As such, it's important to stay vigilant for activities that may belie suspicious behavior inside of your environment.\ @@ -850,7 +894,7 @@ version = 1 references = ["https://rhinosecuritylabs.com/aws/hiding-cloudcobalt-strike-beacon-c2-using-amazon-apis/"] maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - Detect Spike in blocked Outbound Traffic from your AWS - Rule", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - AWS Network Interface details via resourceId - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - AWS Network ACL Details from ID - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task"] +searches = ["ESCU - Detect Spike in blocked Outbound Traffic from your AWS - Rule", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - AWS Network Interface details via resourceId - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - AWS Network ACL Details from ID - Response Task"] description = Leverage these searches to monitor your AWS network traffic for evidence of anomalous activity and suspicious behaviors, such as a spike in blocked outbound traffic in your virtual private cloud (VPC). narrative = A virtual private cloud (VPC) is an on-demand managed cloud-computing service that isolates computing resources for each client. Inside the VPC container, the environment resembles a physical network. \ Amazon's VPC service enables you to launch EC2 instances and leverage other Amazon resources. The traffic that flows in and out of this VPC can be controlled via network access-control rules and security groups. Amazon also has a feature called VPC Flow Logs that enables you to log IP traffic going to and from the network interfaces in your VPC. This data is stored using Amazon CloudWatch Logs.\ @@ -864,7 +908,7 @@ version = 1 references = ["https://aws.amazon.com/blogs/security/aws-cloudtrail-now-tracks-cross-account-activity-to-its-origin/", "https://docs.aws.amazon.com/IAM/latest/UserGuide/cloudtrail-integration.html"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}] spec_version = 3 -searches = ["ESCU - Detect AWS Console Login by User from New City - Rule", "ESCU - AWS Cross Account Activity From Previously Unseen Account - Rule", "ESCU - Detect AWS Console Login by New User - Rule", "ESCU - Detect AWS Console Login by User from New Country - Rule", "ESCU - Detect AWS Console Login by User from New Region - Rule", "ESCU - Investigate AWS User Activities by user field - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Detect AWS Console Login by User from New City - Rule", "ESCU - Detect AWS Console Login by New User - Rule", "ESCU - AWS Cross Account Activity From Previously Unseen Account - Rule", "ESCU - Detect AWS Console Login by User from New Country - Rule", "ESCU - Detect AWS Console Login by User from New Region - Rule", "ESCU - Investigate AWS User Activities by user field - Response Task", "ESCU - Get Notable History - Response Task"] description = Monitor your cloud authentication events. Searches within this Analytic Story leverage the recent cloud updates to the Authentication data model to help you stay aware of and investigate suspicious login activity. narrative = It is important to monitor and control who has access to your cloud infrastructure. Detecting suspicious logins will provide good starting points for investigations. Abusive behaviors caused by compromised credentials can lead to direct monetary costs, as you will be billed for any compute activity whether legitimate or otherwise.\ This Analytic Story has data model versions of cloud searches leveraging Authentication data, including those looking for suspicious login activity, and cross-account activity for AWS. @@ -876,7 +920,7 @@ version = 1 references = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf"] maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}] spec_version = 3 -searches = ["ESCU - Abnormally High Number Of Cloud Instances Launched - Rule", "ESCU - Abnormally High Number Of Cloud Instances Destroyed - Rule", "ESCU - Cloud Instance Modified By Previously Unseen User - Rule", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task"] +searches = ["ESCU - Abnormally High Number Of Cloud Instances Destroyed - Rule", "ESCU - Abnormally High Number Of Cloud Instances Launched - Rule", "ESCU - Cloud Instance Modified By Previously Unseen User - Rule", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task"] description = Monitor your cloud infrastructure provisioning activities for behaviors originating from unfamiliar or unusual locations. These behaviors may indicate that malicious activities are occurring somewhere within your cloud environment. narrative = Monitoring your cloud infrastructure logs allows you enable governance, compliance, and risk auditing. It is crucial for a company to monitor events and actions taken in the their cloud environments to ensure that your instances are not vulnerable to attacks. This Analytic Story identifies suspicious activities in your cloud compute instances and helps you respond and investigate those activities. @@ -887,7 +931,7 @@ version = 1 references = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf"] maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}] spec_version = 3 -searches = ["ESCU - Cloud Provisioning Activity From Previously Unseen City - Rule", "ESCU - Cloud Provisioning Activity From Previously Unseen Region - Rule", "ESCU - Cloud Provisioning Activity From Previously Unseen Country - Rule", "ESCU - Cloud Provisioning Activity From Previously Unseen IP Address - Rule", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Cloud Provisioning Activity From Previously Unseen Region - Rule", "ESCU - Cloud Provisioning Activity From Previously Unseen IP Address - Rule", "ESCU - Cloud Provisioning Activity From Previously Unseen City - Rule", "ESCU - Cloud Provisioning Activity From Previously Unseen Country - Rule", "ESCU - Get Notable History - Response Task"] description = Monitor your cloud infrastructure provisioning activities for behaviors originating from unfamiliar or unusual locations. These behaviors may indicate that malicious activities are occurring somewhere within your cloud environment. narrative = Because most enterprise cloud infrastructure activities originate from familiar geographic locations, monitoring for activity from unknown or unusual regions is an important security measure. This indicator can be especially useful in environments where it is impossible to add specific IPs to an allow list because they vary.\ This Analytic Story was designed to provide you with flexibility in the precision you employ in specifying legitimate geographic regions. It can be as specific as an IP address or a city, or as broad as a region (think state) or an entire country. By determining how precise you want your geographical locations to be and monitoring for new locations that haven't previously accessed your environment, you can detect adversaries as they begin to probe your environment. Since there are legitimate reasons for activities from unfamiliar locations, this is not a standalone indicator. Nevertheless, location can be a relevant piece of information that you may wish to investigate further. @@ -911,7 +955,7 @@ version = 2 references = ["https://attack.mitre.org/wiki/Technique/T1059", "https://www.microsoft.com/en-us/wdsi/threats/macro-malware", "https://www.fireeye.com/content/dam/fireeye-www/services/pdfs/mandiant-apt1-report.pdf"] maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - Unusually Long Command Line - Rule", "ESCU - Detect Prohibited Applications Spawning cmd exe - Rule", "ESCU - Unusually Long Command Line - MLTK - Rule", "ESCU - System Processes Run From Unexpected Locations - Rule", "ESCU - Detect Use of cmd exe to Launch Script Interpreters - Rule", "ESCU - First time seen command line argument - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Detect Prohibited Applications Spawning cmd exe - Rule", "ESCU - Detect Use of cmd exe to Launch Script Interpreters - Rule", "ESCU - Unusually Long Command Line - Rule", "ESCU - First time seen command line argument - Rule", "ESCU - Unusually Long Command Line - MLTK - Rule", "ESCU - System Processes Run From Unexpected Locations - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Leveraging the Windows command-line interface (CLI) is one of the most common attack techniques--one that is also detailed in the MITRE ATT&CK framework. Use this Analytic Story to help you identify unusual or suspicious use of the CLI on Windows systems. narrative = The ability to execute arbitrary commands via the Windows CLI is a primary goal for the adversary. With access to the shell, an attacker can easily run scripts and interact with the target system. Often, attackers may only have limited access to the shell or may obtain access in unusual ways. In addition, malware may execute and interact with the CLI in ways that would be considered unusual and inconsistent with typical user activity. This provides defenders with opportunities to identify suspicious use and investigate, as appropriate. This Analytic Story contains various searches to help identify this suspicious activity, as well as others to aid you in deeper investigation. @@ -922,7 +966,7 @@ version = 1 references = ["http://blogs.splunk.com/2015/10/01/random-words-on-entropy-and-dns/", "http://www.darkreading.com/analytics/security-monitoring/got-malware-three-signs-revealed-in-dns-traffic/d/d-id/1139680", "https://live.paloaltonetworks.com/t5/Threat-Vulnerability-Articles/What-are-suspicious-DNS-queries/ta-p/71454"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}] spec_version = 3 -searches = ["ESCU - DNS Query Length With High Standard Deviation - Rule", "ESCU - Detect Long DNS TXT Record Response - Rule", "ESCU - Excessive DNS Failures - Rule", "ESCU - DNS Query Requests Resolved by Unauthorized DNS Servers - Rule", "ESCU - Detection of DNS Tunnels - Rule", "ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - Clients Connecting to Multiple DNS Servers - Rule", "ESCU - DNS Query Length Outliers - MLTK - Rule", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task"] +searches = ["ESCU - Clients Connecting to Multiple DNS Servers - Rule", "ESCU - DNS Query Length With High Standard Deviation - Rule", "ESCU - Excessive DNS Failures - Rule", "ESCU - DNS Query Length Outliers - MLTK - Rule", "ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - Detect Long DNS TXT Record Response - Rule", "ESCU - DNS Query Requests Resolved by Unauthorized DNS Servers - Rule", "ESCU - Detection of DNS Tunnels - Rule", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Attackers often attempt to hide within or otherwise abuse the domain name system (DNS). You can thwart attempts to manipulate this omnipresent protocol by monitoring for these types of abuses. narrative = Although DNS is one of the fundamental underlying protocols that make the Internet work, it is often ignored (perhaps because of its complexity and effectiveness). However, attackers have discovered ways to abuse the protocol to meet their objectives. One potential abuse involves manipulating DNS to hijack traffic and redirect it to an IP address under the attacker's control. This could inadvertently send users intending to visit google.com, for example, to an unrelated malicious website. Another technique involves using the DNS protocol for command-and-control activities with the attacker's malicious code or to covertly exfiltrate data. The searches within this Analytic Story look for these types of abuses. @@ -933,7 +977,7 @@ version = 1 references = ["https://www.splunk.com/blog/2015/06/26/phishing-hits-a-new-level-of-quality/"] maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - Suspicious Email Attachment Extensions - Rule", "ESCU - Monitor Email For Brand Abuse - Rule", "ESCU - Suspicious Email - UBA Anomaly - Rule", "ESCU - Email Attachments With Lots Of Spaces - Rule", "ESCU - Get Email Info - Response Task", "ESCU - Get Emails From Specific Sender - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Email Attachments With Lots Of Spaces - Rule", "ESCU - Monitor Email For Brand Abuse - Rule", "ESCU - Suspicious Email - UBA Anomaly - Rule", "ESCU - Suspicious Email Attachment Extensions - Rule", "ESCU - Get Emails From Specific Sender - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Email Info - Response Task"] description = Email remains one of the primary means for attackers to gain an initial foothold within the modern enterprise. Detect and investigate suspicious emails in your environment with the help of the searches in this Analytic Story. narrative = It is a common practice for attackers of all types to leverage targeted spearphishing campaigns and mass mailers to deliver weaponized email messages and attachments. Fortunately, there are a number of ways to monitor email data in Splunk to detect suspicious content.\ Once a phishing message has been detected, the next steps are to answer the following questions: \ @@ -959,7 +1003,7 @@ version = 2 references = ["https://redcanary.com/blog/introducing-atomictestharnesses/", "https://redcanary.com/blog/windows-registry-attacks-threat-detection/", "https://attack.mitre.org/techniques/T1218/005/", "https://medium.com/@mbromileyDFIR/malware-monday-aebb456356c5"] maintainers = [{"company": "Michael Haag, Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - Suspicious mshta spawn - Rule", "ESCU - Suspicious mshta child process - Rule", "ESCU - Detect mshta renamed - Rule", "ESCU - Detect MSHTA Url in Command Line - Rule", "ESCU - Detect Prohibited Applications Spawning cmd exe - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Detect Rundll32 Inline HTA Execution - Rule", "ESCU - Detect mshta inline hta execution - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Detect mshta renamed - Rule", "ESCU - Detect Prohibited Applications Spawning cmd exe - Rule", "ESCU - Suspicious mshta spawn - Rule", "ESCU - Detect MSHTA Url in Command Line - Rule", "ESCU - Detect Rundll32 Inline HTA Execution - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Suspicious mshta child process - Rule", "ESCU - Detect mshta inline hta execution - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Monitor and detect techniques used by attackers who leverage the mshta.exe process to execute malicious code. narrative = One common adversary tactic is to bypass application control solutions via the mshta.exe process, which loads Microsoft HTML applications (mshtml.dll) with the .hta suffix. In these cases, attackers use the trusted Windows utility to proxy execution of malicious files, whether an .hta application, javascript, or VBScript.\ The searches in this story help you detect and investigate suspicious activity that may indicate that an attacker is leveraging mshta.exe to execute malicious code.\ @@ -982,7 +1026,7 @@ version = 1 references = ["https://attack.mitre.org/wiki/Technique/T1078", "https://owasp.org/www-community/attacks/Credential_stuffing", "https://searchsecurity.techtarget.com/answer/What-is-a-password-spraying-attack-and-how-does-it-work"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}] spec_version = 3 -searches = ["ESCU - Multiple Okta Users With Invalid Credentials From The Same IP - Rule", "ESCU - Okta Account Lockout Events - Rule", "ESCU - Okta Failed SSO Attempts - Rule", "ESCU - Okta User Logins From Multiple Cities - Rule", "ESCU - Investigate Okta Activity by IP Address - Response Task", "ESCU - Investigate User Activities In Okta - Response Task", "ESCU - Investigate Okta Activity by app - Response Task"] +searches = ["ESCU - Okta Account Lockout Events - Rule", "ESCU - Okta User Logins From Multiple Cities - Rule", "ESCU - Okta Failed SSO Attempts - Rule", "ESCU - Multiple Okta Users With Invalid Credentials From The Same IP - Rule", "ESCU - Investigate Okta Activity by app - Response Task", "ESCU - Investigate Okta Activity by IP Address - Response Task", "ESCU - Investigate User Activities In Okta - Response Task"] description = Monitor your Okta environment for suspicious activities. Due to the Covid outbreak, many users are migrating over to leverage cloud services more and more. Okta is a popular tool to manage multiple users and the web-based applications they need to stay productive. The searches in this story will help monitor your Okta environment for suspicious activities and associated user behaviors. narrative = Okta is the leading single sign on (SSO) provider, allowing users to authenticate once to Okta, and from there access a variety of web-based applications. These applications are assigned to users and allow administrators to centrally manage which users are allowed to access which applications. It also provides centralized logging to help understand how the applications are used and by whom. \ While SSO is a major convenience for users, it also provides attackers with an opportunity. If the attacker can gain access to Okta, they can access a variety of applications. As such monitoring the environment is important. \ @@ -995,7 +1039,7 @@ version = 1 references = ["https://attack.mitre.org/techniques/T1218/010/", "https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md", "https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"] maintainers = [{"company": "Splunk", "email": "-", "name": "Michael Haag"}] spec_version = 3 -searches = ["ESCU - Suspicious Regsvr32 Register Suspicious Path - Rule", "ESCU - Detect Regsvr32 Application Control Bypass - Rule"] +searches = ["ESCU - Detect Regsvr32 Application Control Bypass - Rule", "ESCU - Suspicious Regsvr32 Register Suspicious Path - Rule"] description = Monitor and detect techniques used by attackers who leverage the regsvr32.exe process to execute malicious code. narrative = One common adversary tactic is to bypass application control solutions via the regsvr32.exe process. This particular bypass was popularized with "SquiblyDoo" using the "scrobj.dll" dll to load .sct scriptlets. This technique is still widely used by adversaries to bypass detection and prevention controls. The file extension of the DLL is irrelevant (it may load a .txt file extension for example). The searches in this story help you detect and investigate suspicious activity that may indicate that an adversary is leveraging regsvr32.exe to execute malicious code. Validate execution Determine if regsvr32.exe executed. Validate the OriginalFileName of regsvr32.exe and further PE metadata. If executed outside of c:\windows\system32 or c:\windows\syswow64, it should be highly suspect. Determine if script code was executed with regsvr32. Situational Awareness - The objective of this step is meant to identify suspicious behavioral indicators related to executed of Script code by regsvr32.exe. Parent process. Is the parent process a known LOLBin? Is the parent process an Office Application? Module loads. Is regsvr32 loading any suspicious .DLLs? Unsigned or signed from non-standard paths. Network connections. Any network connections? Review the reputation of the remote IP or domain. Retrieval of Script Code - confirm the executed script code is benign or malicious. @@ -1006,7 +1050,7 @@ version = 1 references = ["https://attack.mitre.org/techniques/T1218/011/", "https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md", "https://lolbas-project.github.io/lolbas/Binaries/Rundll32"] maintainers = [{"company": "Splunk", "email": "-", "name": "Michael Haag"}] spec_version = 3 -searches = ["ESCU - Suspicious Rundll32 Rename - Rule", "ESCU - Suspicious Rundll32 no Command Line Arguments - Rule", "ESCU - Suspicious Rundll32 dllregisterserver - Rule", "ESCU - Suspicious Rundll32 StartW - Rule", "ESCU - Detect Rundll32 Application Control Bypass - syssetup - Rule", "ESCU - Detect Rundll32 Application Control Bypass - advpack - Rule", "ESCU - Dump LSASS via comsvcs DLL - Rule", "ESCU - Detect Rundll32 Application Control Bypass - setupapi - Rule"] +searches = ["ESCU - Detect Rundll32 Application Control Bypass - syssetup - Rule", "ESCU - Dump LSASS via comsvcs DLL - Rule", "ESCU - Suspicious Rundll32 Rename - Rule", "ESCU - Detect Rundll32 Application Control Bypass - advpack - Rule", "ESCU - Detect Rundll32 Application Control Bypass - setupapi - Rule", "ESCU - Suspicious Rundll32 dllregisterserver - Rule", "ESCU - Suspicious Rundll32 no Command Line Arguments - Rule", "ESCU - Suspicious Rundll32 StartW - Rule"] description = Monitor and detect techniques used by attackers who leverage rundll32.exe to execute arbitrary malicious code. narrative = One common adversary tactic is to bypass application control solutions via the rundll32.exe process. Natively, rundll32.exe will load DLLs and is a great example of a Living off the Land Binary. Rundll32.exe may load malicious DLLs by ordinals, function names or directly. The queries in this story focus on loading default DLLs, syssetup.dll, ieadvpack.dll, advpack.dll and setupapi.dll from disk that may be abused by adversaries. Additionally, two analytics developed to assist with identifying DLLRegisterServer, Start and StartW functions being called. The searches in this story help you detect and investigate suspicious activity that may indicate that an adversary is leveraging rundll32.exe to execute malicious code. @@ -1017,7 +1061,7 @@ version = 2 references = ["https://www.blackhat.com/docs/us-15/materials/us-15-Graeber-Abusing-Windows-Management-Instrumentation-WMI-To-Build-A-Persistent%20Asynchronous-And-Fileless-Backdoor-wp.pdf", "https://www.fireeye.com/blog/threat-research/2017/03/wmimplant_a_wmi_ba.html"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}] spec_version = 3 -searches = ["ESCU - WMI Temporary Event Subscription - Rule", "ESCU - Script Execution via WMI - Rule", "ESCU - Remote Process Instantiation via WMI - Rule", "ESCU - WMI Permanent Event Subscription - Sysmon - Rule", "ESCU - Process Execution via WMI - Rule", "ESCU - WMI Permanent Event Subscription - Rule", "ESCU - Remote WMI Command Attempt - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Sysmon WMI Activity for Host - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Remote WMI Command Attempt - Rule", "ESCU - Remote Process Instantiation via WMI - Rule", "ESCU - Script Execution via WMI - Rule", "ESCU - WMI Permanent Event Subscription - Rule", "ESCU - WMI Temporary Event Subscription - Rule", "ESCU - WMI Permanent Event Subscription - Sysmon - Rule", "ESCU - Process Execution via WMI - Rule", "ESCU - Get Sysmon WMI Activity for Host - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Attackers are increasingly abusing Windows Management Instrumentation (WMI), a framework and associated utilities available on all modern Windows operating systems. Because WMI can be leveraged to manage both local and remote systems, it is important to identify the processes executed and the user context within which the activity occurred. narrative = WMI is a Microsoft infrastructure for management data and operations on Windows operating systems. It includes of a set of utilities that can be leveraged to manage both local and remote Windows systems. Attackers are increasingly turning to WMI abuse in their efforts to conduct nefarious tasks, such as reconnaissance, detection of antivirus and virtual machines, code execution, lateral movement, persistence, and data exfiltration. \ The detection searches included in this Analytic Story are used to look for suspicious use of WMI commands that attackers may leverage to interact with remote systems. The searches specifically look for the use of WMI to run processes on remote systems.\ @@ -1030,7 +1074,7 @@ version = 1 references = ["https://redcanary.com/blog/windows-registry-attacks-threat-detection/", "https://attack.mitre.org/wiki/Technique/T1112"] maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - Registry Keys for Creating SHIM Databases - Rule", "ESCU - Remote Registry Key modifications - Rule", "ESCU - Disabling Remote User Account Control - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Monitor Registry Keys for Print Monitors - Rule", "ESCU - Registry Keys Used For Privilege Escalation - Rule", "ESCU - Reg exe used to hide files directories via registry keys - Rule", "ESCU - Suspicious Changes to File Associations - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Registry Keys for Creating SHIM Databases - Rule", "ESCU - Registry Keys Used For Privilege Escalation - Rule", "ESCU - Remote Registry Key modifications - Rule", "ESCU - Suspicious Changes to File Associations - Rule", "ESCU - Disabling Remote User Account Control - Rule", "ESCU - Monitor Registry Keys for Print Monitors - Rule", "ESCU - Reg exe used to hide files directories via registry keys - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Monitor and detect registry changes initiated from remote locations, which can be a sign that an attacker has infiltrated your system. narrative = Attackers are developing increasingly sophisticated techniques for hijacking target servers, while evading detection. One such technique that has become progressively more common is registry modification.\ The registry is a key component of the Windows operating system. It has a hierarchical database called "registry" that contains settings, options, and values for executables. Once the threat actor gains access to a machine, they can use reg.exe to modify their account to obtain administrator-level privileges, maintain persistence, and move laterally within the environment.\ @@ -1043,7 +1087,7 @@ version = 1 references = ["https://blog.rapid7.com/2020/04/02/dispelling-zoom-bugbears-what-you-need-to-know-about-the-latest-zoom-vulnerabilities/", "https://threatpost.com/two-zoom-zero-day-flaws-uncovered/154337/"] maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}] spec_version = 3 -searches = ["ESCU - First Time Seen Child Process of Zoom - Rule", "ESCU - Detect Prohibited Applications Spawning cmd exe - Rule", "ESCU - Get Process File Activity - Response Task"] +searches = ["ESCU - Detect Prohibited Applications Spawning cmd exe - Rule", "ESCU - First Time Seen Child Process of Zoom - Rule", "ESCU - Get Process File Activity - Response Task"] description = Attackers are using Zoom as an vector to increase privileges on a sytems. This story detects new child processes of zoom and provides investigative actions for this detection. narrative = Zoom is a leader in modern enterprise video communications and its usage has increased dramatically with a large amount of the population under stay-at-home orders due to the COVID-19 pandemic. With increased usage has come increased scrutiny and several security flaws have been found with this application on both Windows and macOS systems.\ Current detections focus on finding new child processes of this application on a per host basis. Investigative searches are included to gather information needed during an investigation. @@ -1055,7 +1099,7 @@ version = 1 references = ["https://attack.mitre.org/techniques/T1127/", "https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218/T1218.md", "https://lolbas-project.github.io/lolbas/Binaries/Microsoft.Workflow.Compiler/"] maintainers = [{"company": "Splunk", "email": "-", "name": "Michael Haag"}] spec_version = 3 -searches = ["ESCU - Suspicious microsoft workflow compiler rename - Rule", "ESCU - Suspicious microsoft workflow compiler usage - Rule"] +searches = ["ESCU - Suspicious microsoft workflow compiler usage - Rule", "ESCU - Suspicious microsoft workflow compiler rename - Rule"] description = Monitor and detect behaviors used by attackers who leverage trusted developer utilities to execute malicious code. narrative = Adversaries may take advantage of trusted developer utilities to proxy execution of malicious payloads. There are many utilities used for software development related tasks that can be used to execute code in various forms to assist in development, debugging, and reverse engineering. These utilities may often be signed with legitimate certificates that allow them to execute on a system and proxy execution of malicious code through a trusted process that effectively bypasses application control solutions.\ The searches in this story help you detect and investigate suspicious activity that may indicate that an adversary is leveraging microsoft.workflow.compiler.exe to execute malicious code. @@ -1067,7 +1111,7 @@ version = 1 references = ["https://attack.mitre.org/techniques/T1127/001/", "https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127.001/T1127.001.md", "https://github.com/infosecn1nja/MaliciousMacroMSBuild", "https://github.com/xorrior/RandomPS-Scripts/blob/master/Invoke-ExecuteMSBuild.ps1", "https://lolbas-project.github.io/lolbas/Binaries/Msbuild/", "https://github.com/MHaggis/CBR-Queries/blob/master/msbuild.md"] maintainers = [{"company": "Splunk", "email": "-", "name": "Michael Haag"}] spec_version = 3 -searches = ["ESCU - Suspicious MSBuild Rename - Rule", "ESCU - Suspicious MSBuild Spawn - Rule", "ESCU - Suspicious msbuild path - Rule"] +searches = ["ESCU - Suspicious msbuild path - Rule", "ESCU - Suspicious MSBuild Rename - Rule", "ESCU - Suspicious MSBuild Spawn - Rule"] description = Monitor and detect techniques used by attackers who leverage the msbuild.exe process to execute malicious code. narrative = Adversaries may use MSBuild to proxy execution of code through a trusted Windows utility. MSBuild.exe (Microsoft Build Engine) is a software build platform used by Visual Studio and is native to Windows. It handles XML formatted project files that define requirements for loading and building various platforms and configurations.\ The inline task capability of MSBuild that was introduced in .NET version 4 allows for C# code to be inserted into an XML project file. MSBuild will compile and execute the inline task. MSBuild.exe is a signed Microsoft binary, so when it is used this way it can execute arbitrary code and bypass application control defenses that are configured to allow MSBuild.exe execution.\ @@ -1103,7 +1147,7 @@ version = 2 references = ["https://www.fireeye.com/blog/threat-research/2017/08/monitoring-windows-console-activity-part-two.html", "https://www.splunk.com/pdfs/technical-briefs/advanced-threat-detection-and-response-tech-brief.pdf", "https://www.sans.org/reading-room/whitepapers/logging/detecting-security-incidents-windows-workstation-event-logs-34262"] maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - Detect processes used for System Network Configuration Discovery - Rule", "ESCU - Unusually Long Command Line - Rule", "ESCU - Uncommon Processes On Endpoint - Rule", "ESCU - System Processes Run From Unexpected Locations - Rule", "ESCU - Detect Rare Executables - Rule", "ESCU - Unusually Long Command Line - MLTK - Rule", "ESCU - RunDLL Loading DLL By Ordinal - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Uncommon Processes On Endpoint - Rule", "ESCU - Detect processes used for System Network Configuration Discovery - Rule", "ESCU - RunDLL Loading DLL By Ordinal - Rule", "ESCU - Detect Rare Executables - Rule", "ESCU - Unusually Long Command Line - Rule", "ESCU - Unusually Long Command Line - MLTK - Rule", "ESCU - System Processes Run From Unexpected Locations - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Quickly identify systems running new or unusual processes in your environment that could be indicators of suspicious activity. Processes run from unusual locations, those with conspicuously long command lines, and rare executables are all examples of activities that may warrant deeper investigation. narrative = Being able to profile a host's processes within your environment can help you more quickly identify processes that seem out of place when compared to the rest of the population of hosts or asset types.\ This Analytic Story lets you identify processes that are either a) not typically seen running or b) have some sort of suspicious command-line arguments associated with them. This Analytic Story will also help you identify the user running these processes and the associated process activity on the host.\ @@ -1127,7 +1171,7 @@ version = 1 references = ["https://www.fbi.gov/scams-and-safety/common-fraud-schemes/internet-fraud", "https://www.fbi.gov/news/stories/2017-internet-crime-report-released-050718"] maintainers = [{"company": "Splunk", "email": "-", "name": "Jim Apger"}] spec_version = 3 -searches = ["ESCU - Web Fraud - Password Sharing Across Accounts - Rule", "ESCU - Web Fraud - Account Harvesting - Rule", "ESCU - Web Fraud - Anomalous User Clickspeed - Rule", "ESCU - Get Web Session Information via session id - Response Task", "ESCU - Get Emails From Specific Sender - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Web Fraud - Account Harvesting - Rule", "ESCU - Web Fraud - Anomalous User Clickspeed - Rule", "ESCU - Web Fraud - Password Sharing Across Accounts - Rule", "ESCU - Get Emails From Specific Sender - Response Task", "ESCU - Get Web Session Information via session id - Response Task", "ESCU - Get Notable History - Response Task"] description = Monitor your environment for activity consistent with common attack techniques bad actors use when attempting to compromise web servers or other web-related assets. narrative = The Federal Bureau of Investigations (FBI) defines Internet fraud as the use of Internet services or software with Internet access to defraud victims or to otherwise take advantage of them. According to the Bureau, Internet crime schemes are used to steal millions of dollars each year from victims and continue to plague the Internet through various methods. The agency includes phishing scams, data breaches, Denial of Service (DOS) attacks, email account compromise, malware, spoofing, and ransomware in this category.\ These crimes are not the fraud itself, but rather the attack techniques commonly employed by fraudsters in their pursuit of data that enables them to commit malicious actssuch as obtaining and using stolen credit cards. They represent a serious problem that is steadily increasing and not likely to go away anytime soon.\ @@ -1143,7 +1187,7 @@ version = 1 references = ["https://research.checkpoint.com/2020/resolving-your-way-into-domain-admin-exploiting-a-17-year-old-bug-in-windows-dns-servers/", "https://support.microsoft.com/en-au/help/4569509/windows-dns-server-remote-code-execution-vulnerability"] maintainers = [{"company": "Splunk", "email": "-", "name": "Shannon Davis"}] spec_version = 3 -searches = ["ESCU - Detect Windows DNS SIGRed via Zeek - Rule", "ESCU - Detect Windows DNS SIGRed via Splunk Stream - Rule", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Detect Windows DNS SIGRed via Splunk Stream - Rule", "ESCU - Detect Windows DNS SIGRed via Zeek - Rule", "ESCU - Get Notable History - Response Task"] description = Uncover activity consistent with CVE-2020-1350, or SIGRed. Discovered by Checkpoint researchers, this vulnerability affects Windows 2003 to 2019, and is triggered by a malicious DNS response (only affects DNS over TCP). An attacker can use the malicious payload to cause a buffer overflow on the vulnerable system, leading to compromise. The included searches in this Analytic Story are designed to identify the large response payload for SIG and KEY DNS records which can be used for the exploit. narrative = When a client requests a DNS record for a particular domain, that request gets routed first through the client's locally configured DNS server, then to any DNS server(s) configured as forwarders, and then onto the target domain's own DNS server(s). If a attacker wanted to, they could host a malicious DNS server that responds to the initial request with a specially crafted large response (~65KB). This response would flow through to the client's local DNS server, which if not patched for CVE-2020-1350, would cause the buffer overflow. The detection searches in this Analytic Story use wire data to detect the malicious behavior. Searches for Splunk Stream and Zeek are included. The Splunk Stream search correlates across stream:dns and stream:tcp, while the Zeek search correlates across bro:dns:json and bro:conn:json. These correlations are required to pick up both the DNS record types (SIG and KEY) along with the payload size (>65KB). @@ -1154,7 +1198,7 @@ version = 1 references = ["https://attack.mitre.org/wiki/Defense_Evasion"] maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}] spec_version = 3 -searches = ["ESCU - Remote Registry Key modifications - Rule", "ESCU - Disabling Remote User Account Control - Rule", "ESCU - Eventvwr UAC Bypass - Rule", "ESCU - Suspicious Reg exe Process - Rule", "ESCU - FodHelper UAC Bypass - Rule", "ESCU - Hiding Files And Directories With Attrib exe - Rule", "ESCU - Reg exe used to hide files directories via registry keys - Rule", "ESCU - Windows DisableAntiSpyware Registry - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Remote Registry Key modifications - Rule", "ESCU - Windows DisableAntiSpyware Registry - Rule", "ESCU - Disabling Remote User Account Control - Rule", "ESCU - Suspicious Reg exe Process - Rule", "ESCU - FodHelper UAC Bypass - Rule", "ESCU - Reg exe used to hide files directories via registry keys - Rule", "ESCU - Hiding Files And Directories With Attrib exe - Rule", "ESCU - Eventvwr UAC Bypass - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Detect tactics used by malware to evade defenses on Windows endpoints. A few of these include suspicious `reg.exe` processes, files hidden with `attrib.exe` and disabling user-account control, among many others narrative = Defense evasion is a tactic--identified in the MITRE ATT&CK framework--that adversaries employ in a variety of ways to bypass or defeat defensive security measures. There are many techniques enumerated by the MITRE ATT&CK framework that are applicable in this context. This Analytic Story includes searches designed to identify the use of such techniques on Windows platforms. @@ -1165,7 +1209,7 @@ version = 1 references = ["https://blog.malwarebytes.com/cybercrime/2013/12/file-extensions-2/", "https://attack.mitre.org/wiki/Technique/T1042"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}] spec_version = 3 -searches = ["ESCU - Execution of File with Multiple Extensions - Rule", "ESCU - Suspicious Changes to File Associations - Rule", "ESCU - Execution of File With Spaces Before Extension - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Execution of File With Spaces Before Extension - Rule", "ESCU - Suspicious Changes to File Associations - Rule", "ESCU - Execution of File with Multiple Extensions - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Detect and investigate suspected abuse of file extensions and Windows file associations. Some of the malicious behaviors involved may include inserting spaces before file extensions or prepending the file extension with a different one, among other techniques. narrative = Attackers use a variety of techniques to entice users to run malicious code or to persist on an endpoint. One way to accomplish these goals is to leverage file extensions and the mechanism Windows uses to associate files with specific applications. \ Since its earliest days, Windows has used extensions to identify file types. Users have become familiar with these extensions and their application associations. For example, if users see that a file ends in `.doc` or `.docx`, they will assume that it is a Microsoft Word document and expect that double-clicking will open it using `winword.exe`. The user will typically also presume that the `.docx` file is safe. \ @@ -1180,7 +1224,7 @@ version = 2 references = ["https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/", "https://zeltser.com/security-incident-log-review-checklist/", "http://journeyintoir.blogspot.com/2013/01/re-introducing-usnjrnl.html"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}] spec_version = 3 -searches = ["ESCU - Suspicious wevtutil Usage - Rule", "ESCU - Windows Event Log Cleared - Rule", "ESCU - USN Journal Deletion - Rule", "ESCU - Deleting Shadow Copies - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Suspicious wevtutil Usage - Rule", "ESCU - USN Journal Deletion - Rule", "ESCU - Windows Event Log Cleared - Rule", "ESCU - Deleting Shadow Copies - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Adversaries often try to cover their tracks by manipulating Windows logs. Use these searches to help you monitor for suspicious activity surrounding log files--an essential component of an effective defense. narrative = Because attackers often modify system logs to cover their tracks and/or to thwart the investigative process, log monitoring is an industry-recognized best practice. While there are legitimate reasons to manipulate system logs, it is still worthwhile to keep track of who manipulated the logs, when they manipulated them, and in what way they manipulated them (determining which accesses, tools, or utilities were employed). Even if no malicious activity is detected, the knowledge of an attempt to manipulate system logs may be indicative of a broader security risk that should be thoroughly investigated.\ The Analytic Story gives users two different ways to detect manipulation of Windows Event Logs and one way to detect deletion of the Update Sequence Number (USN) Change Journal. The story helps determine the history of the host and the users who have accessed it. Finally, the story aides in investigation by retrieving all the information on the process that caused these events (if the process has been identified). @@ -1192,7 +1236,7 @@ version = 2 references = ["http://www.fuzzysecurity.com/tutorials/19.html", "https://www.fireeye.com/blog/threat-research/2010/07/malware-persistence-windows-registry.html", "http://resources.infosecinstitute.com/common-malware-persistence-mechanisms/", "https://www.fireeye.com/blog/threat-research/2017/05/fin7-shim-databases-persistence.html", "https://www.youtube.com/watch?v=dq2Hv7J9fvk"] maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - Shim Database Installation With Suspicious Parameters - Rule", "ESCU - Registry Keys for Creating SHIM Databases - Rule", "ESCU - Remote Registry Key modifications - Rule", "ESCU - Schtasks used for forcing a reboot - Rule", "ESCU - Suspicious Scheduled Task from Public Directory - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Sc exe Manipulating Windows Services - Rule", "ESCU - Certutil exe certificate extraction - Rule", "ESCU - Detect Path Interception By Creation Of program exe - Rule", "ESCU - Monitor Registry Keys for Print Monitors - Rule", "ESCU - Reg exe Manipulating Windows Services Registry Keys - Rule", "ESCU - Hiding Files And Directories With Attrib exe - Rule", "ESCU - Reg exe used to hide files directories via registry keys - Rule", "ESCU - Shim Database File Creation - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Registry Keys for Creating SHIM Databases - Rule", "ESCU - Sc exe Manipulating Windows Services - Rule", "ESCU - Detect Path Interception By Creation Of program exe - Rule", "ESCU - Remote Registry Key modifications - Rule", "ESCU - Shim Database File Creation - Rule", "ESCU - Reg exe Manipulating Windows Services Registry Keys - Rule", "ESCU - Certutil exe certificate extraction - Rule", "ESCU - Shim Database Installation With Suspicious Parameters - Rule", "ESCU - Schtasks used for forcing a reboot - Rule", "ESCU - Suspicious Scheduled Task from Public Directory - Rule", "ESCU - Monitor Registry Keys for Print Monitors - Rule", "ESCU - Reg exe used to hide files directories via registry keys - Rule", "ESCU - Hiding Files And Directories With Attrib exe - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Monitor for activities and techniques associated with maintaining persistence on a Windows system--a sign that an adversary may have compromised your environment. narrative = Maintaining persistence is one of the first steps taken by attackers after the initial compromise. Attackers leverage various custom and built-in tools to ensure survivability and persistent access within a compromised enterprise. This Analytic Story provides searches to help you identify various behaviors used by attackers to maintain persistent access to a Windows environment. @@ -1203,7 +1247,7 @@ version = 2 references = ["https://attack.mitre.org/tactics/TA0004/"] maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}] spec_version = 3 -searches = ["ESCU - Child Processes of Spoolsv exe - Rule", "ESCU - Registry Keys Used For Privilege Escalation - Rule", "ESCU - Overwriting Accessibility Binaries - Rule", "ESCU - Uncommon Processes On Endpoint - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Child Processes of Spoolsv exe - Rule", "ESCU - Registry Keys Used For Privilege Escalation - Rule", "ESCU - Uncommon Processes On Endpoint - Rule", "ESCU - Overwriting Accessibility Binaries - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Monitor for and investigate activities that may be associated with a Windows privilege-escalation attack, including unusual processes running on endpoints, modified registry keys, and more. narrative = Privilege escalation is a "land-and-expand" technique, wherein an adversary gains an initial foothold on a host and then exploits its weaknesses to increase his privileges. The motivation is simple: certain actions on a Windows machine--such as installing software--may require higher-level privileges than those the attacker initially acquired. By increasing his privilege level, the attacker can gain the control required to carry out his malicious ends. This Analytic Story provides searches to detect and investigate behaviors that attackers may use to elevate their privileges in your environment. @@ -1214,7 +1258,7 @@ version = 3 references = ["https://attack.mitre.org/wiki/Technique/T1050", "https://attack.mitre.org/wiki/Technique/T1031"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}] spec_version = 3 -searches = ["ESCU - Reg exe Manipulating Windows Services Registry Keys - Rule", "ESCU - Sc exe Manipulating Windows Services - Rule", "ESCU - First Time Seen Running Windows Service - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - First Time Seen Running Windows Service - Rule", "ESCU - Sc exe Manipulating Windows Services - Rule", "ESCU - Reg exe Manipulating Windows Services Registry Keys - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Windows services are often used by attackers for persistence and the ability to load drivers or otherwise interact with the Windows kernel. This Analytic Story helps you monitor your environment for indications that Windows services are being modified or created in a suspicious manner. narrative = The Windows operating system uses a services architecture to allow for running code in the background, similar to a UNIX daemon. Attackers will often leverage Windows services for persistence, hiding in plain sight, seeking the ability to run privileged code that can interact with the kernel. In many cases, attackers will create a new service to host their malicious code. Attackers have also been observed modifying unnecessary or unused services to point to their own code, as opposed to what was intended. In these cases, attackers often use tools to create or modify services in ways that are not typical for most environments, providing opportunities for detection. @@ -1266,6 +1310,36 @@ known_false_positives = This is a strictly behavioral search, so we define "fals This search will fire any time a new region is seen in the **GeoIP** database for any kind of provisioning activity. If you typically do all provisioning from tools inside of your region, there should be few false positives. If you are located in regions where the free version of **MaxMind GeoIP** that ships by default with Splunk has weak resolution (particularly small countries in less economically powerful regions), this may be much less valuable to you. providing_technologies = [] +[savedsearch://ESCU - AWS Create Policy Version to allow all resources - Rule] +type = detection +asset_type = AWS Account +confidence = medium +explanation = This search looks for CloudTrail events where a user created a policy version that allows them to access any resource in their account +how_to_implement = You must install splunk AWS add on and Splunk App for AWS. This search works with cloudtrail logs. +annotations = {"cis20": ["CIS 13"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1078.004"], "nist": ["PR.DS", "PR.AC", "DE.CM"]} +known_false_positives = While this search has no known false positives, it is possible that an AWS admin has legitimately created a policy to allow a user to access all resources. That said, AWS strongly advises against granting full control to all AWS resources +providing_technologies = [] + +[savedsearch://ESCU - AWS CreateAccessKey - Rule] +type = detection +asset_type = AWS Account +confidence = medium +explanation = This search looks for CloudTrail events where a user A who has already permission to create access keys, makes an API call to create access keys for another user B. Attackers have been know to use this technique for Privilege Escalation in case new victim(user B) has more permissions than old victim(user B) +how_to_implement = You must install splunk AWS add on and Splunk App for AWS. This search works with cloudtrail logs. +annotations = {"cis20": ["CIS 13"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1136.003"], "nist": ["PR.DS", "PR.AC", "DE.CM"]} +known_false_positives = While this search has no known false positives, it is possible that an AWS admin has legitimately created keys for another user. +providing_technologies = [] + +[savedsearch://ESCU - AWS CreateLoginProfile - Rule] +type = detection +asset_type = AWS Account +confidence = medium +explanation = This search looks for CloudTrail events where a user A(victim A) creates a login profile for user B, followed by a AWS Console login event from user B from the same src_ip as user B. This correlated event can be indicative of privilege escalation since both events happened from the same src_ip +how_to_implement = You must install splunk AWS add on and Splunk App for AWS. This search works with cloudtrail logs. +annotations = {"cis20": ["CIS 13"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1136.003"], "nist": ["PR.DS", "PR.AC", "DE.CM"]} +known_false_positives = While this search has no known false positives, it is possible that an AWS admin has legitimately created a login profile for another user. +providing_technologies = [] + [savedsearch://ESCU - AWS Cross Account Activity From Previously Unseen Account - Rule] type = detection asset_type = AWS Instance @@ -1346,6 +1420,26 @@ annotations = {"mitre_attack": ["T1078"]} known_false_positives = Updating a SAML provider or creating a new one may not necessarily be malicious however it needs to be closely monitored. providing_technologies = [] +[savedsearch://ESCU - AWS SetDefaultPolicyVersion - Rule] +type = detection +asset_type = AWS Account +confidence = medium +explanation = This search looks for CloudTrail events where a user has set a default policy versions. Attackers have been know to use this technique for Privilege Escalation in case the previous versions of the policy had permissions to access more resources than the current version of the policy +how_to_implement = You must install splunk AWS add on and Splunk App for AWS. This search works with cloudtrail logs. +annotations = {"cis20": ["CIS 13"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1078.004"], "nist": ["PR.DS", "PR.AC", "DE.CM"]} +known_false_positives = While this search has no known false positives, it is possible that an AWS admin has legitimately set a default policy to allow a user to access all resources. That said, AWS strongly advises against granting full control to all AWS resources +providing_technologies = [] + +[savedsearch://ESCU - AWS UpdateLoginProfile - Rule] +type = detection +asset_type = AWS Account +confidence = medium +explanation = This search looks for CloudTrail events where a user A who has already permission to update login profile, makes an API call to update login profile for another user B . Attackers have been know to use this technique for Privilege Escalation in case new victim(user B) has more permissions than old victim(user B) +how_to_implement = You must install splunk AWS add on and Splunk App for AWS. This search works with cloudtrail logs. +annotations = {"cis20": ["CIS 13"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1136.003"], "nist": ["PR.DS", "PR.AC", "DE.CM"]} +known_false_positives = While this search has no known false positives, it is possible that an AWS admin has legitimately created keys for another user. +providing_technologies = [] + [savedsearch://ESCU - Abnormally High AWS Instances Launched by User - Rule] type = detection asset_type = AWS Instance @@ -1480,7 +1574,7 @@ providing_technologies = [] type = detection asset_type = Endpoint confidence = medium -explanation = Attempt to add a certificate to the certificate store +explanation = Attempt To Add Certificate To Untrusted Store how_to_implement = You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 8"], "kill_chain_phases": ["Installation", "Actions on Objectives"], "mitre_attack": ["T1553.004"], "nist": ["PR.PT", "DE.CM", "PR.IP"]} known_false_positives = There may be legitimate reasons for administrators to add a certificate to the untrusted certificate store. In such cases, this will typically be done on a large number of systems. @@ -1536,6 +1630,36 @@ annotations = {"cis20": ["CIS 8"], "kill_chain_phases": ["Delivery"], "mitre_att known_false_positives = It is possible for this search to generate a notable event for a batch file write to a path that includes the string "system32", but is not the actual Windows system directory. As such, you should confirm the path of the batch file identified by the search. In addition, a false positive may be generated by an administrator copying a legitimate batch file in this directory tree. You should confirm that the activity is legitimate and modify the search to add exclusions, as necessary. providing_technologies = [] +[savedsearch://ESCU - CertUtil Download With URLCache and Split Arguments - Rule] +type = detection +asset_type = +confidence = medium +explanation = Certutil.exe may download a file from a remote destination using `-urlcache`. This behavior does require a URL to be passed on the command-line. In addition, `-f` (force) and `-split` (Split embedded ASN.1 elements, and save to files) will be used. It is not entirely common for `certutil.exe` to contact public IP space. However, it is uncommon for `certutil.exe` to write files to world writeable paths.\ During triage, capture any files on disk and review. Review the reputation of the remote IP or domain in question. +how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. +annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1105"]} +known_false_positives = Limited false positives in most environments, however tune as needed based on parent-child relationship or network connection. +providing_technologies = [] + +[savedsearch://ESCU - CertUtil Download With VerifyCtl and Split Arguments - Rule] +type = detection +asset_type = +confidence = medium +explanation = Certutil.exe may download a file from a remote destination using `-VerifyCtl`. This behavior does require a URL to be passed on the command-line. In addition, `-f` (force) and `-split` (Split embedded ASN.1 elements, and save to files) will be used. It is not entirely common for `certutil.exe` to contact public IP space. \ During triage, capture any files on disk and review. Review the reputation of the remote IP or domain in question. Using `-VerifyCtl`, the file will either be written to the current working directory or `%APPDATA%\..\LocalLow\Microsoft\CryptnetUrlCache\Content\`. +how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. +annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1105"]} +known_false_positives = Limited false positives in most environments, however tune as needed based on parent-child relationship or network connection. +providing_technologies = [] + +[savedsearch://ESCU - CertUtil With Decode Argument - Rule] +type = detection +asset_type = +confidence = medium +explanation = CertUtil.exe may be used to `encode` and `decode` a file, including PE and script code. Encoding will convert a file to base64 with `-----BEGIN CERTIFICATE-----` and `-----END CERTIFICATE-----` tags. Malicious usage will include decoding a encoded file that was downloaded. Once decoded, it will be loaded by a parallel process. Note that there are two additional command switches that may be used - `encodehex` and `decodehex`. Similarly, the file will be encoded in HEX and later decoded for further execution. During triage, identify the source of the file being decoded. Review its contents or execution behavior for further analysis. +how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. +annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1140"]} +known_false_positives = Typically seen used to `encode` files, but it is possible to see legitimate use of `decode`. Filter based on parent-child relationship, file paths, endpoint or user. +providing_technologies = [] + [savedsearch://ESCU - Certutil exe certificate extraction - Rule] type = detection asset_type = Endpoint @@ -1568,6 +1692,26 @@ annotations = {"cis20": ["CIS 9", "CIS 12", "CIS 13"], "kill_chain_phases": ["Co known_false_positives = It's possible that an enterprise has more than five DNS servers that are configured in a round-robin rotation. Please customize the search, as appropriate. providing_technologies = [] +[savedsearch://ESCU - Clop Common Exec Parameter - Rule] +type = detection +asset_type = +confidence = medium +explanation = The following analytics are designed to identifies some CLOP ransomware variant that using arguments to execute its main code or feature of its code. In this variant if the parameter is "runrun", CLOP ransomware will try to encrypt files in network shares and if it is "temp.dat", it will try to read from some stream pipe or file start encrypting files within the infected local machines. This technique can be also identified as an anti-sandbox technique to make its code non-responsive since it is waiting for some parameter to execute properly. +how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. +annotations = {"kill_chain_phases": ["Obfuscation"], "mitre_attack": ["T1204"]} +known_false_positives = Operators can execute third party tools using these parameters. +providing_technologies = [] + +[savedsearch://ESCU - Clop Ransomware Known Service Name - Rule] +type = detection +asset_type = +confidence = medium +explanation = This detection is to identify the common service name created by the CLOP ransomware as part of its persistence and high privilege code execution in the infected machine. Ussually CLOP ransomware use StartServiceCtrlDispatcherW API in creating this service entry. +how_to_implement = To successfully implement this search, you need to be ingesting logs with the Service name, Service File Name Service Start type, and Service Type from your endpoints. +annotations = {"kill_chain_phases": ["Privilege Escalation"], "mitre_attack": ["T1543"]} +known_false_positives = unknown +providing_technologies = [] + [savedsearch://ESCU - Cloud API Calls From Previously Unseen User Roles - Rule] type = detection asset_type = AWS Instance @@ -1727,6 +1871,16 @@ annotations = {"cis20": ["CIS 8", "CIS 16"], "kill_chain_phases": ["Actions on O known_false_positives = Other tools can access LSASS for legitimate reasons and generate an event. In these cases, tweaking the search may help eliminate noise. providing_technologies = [] +[savedsearch://ESCU - Create Service In Suspicious File Path - Rule] +type = detection +asset_type = +confidence = medium +explanation = This detection is to identify a creation of "user mode service" where the service file path is located in non-common service folder in windows. +how_to_implement = To successfully implement this search, you need to be ingesting logs with the Service name, Service File Name Service Start type, and Service Type from your endpoints. +annotations = {"kill_chain_phases": ["Privilege Escalation"], "mitre_attack": ["T1569.001, T1569.002"]} +known_false_positives = unknown +providing_technologies = [] + [savedsearch://ESCU - Create local admin accounts using net exe - Rule] type = detection asset_type = Endpoint @@ -2041,7 +2195,7 @@ providing_technologies = [] type = detection asset_type = confidence = medium -explanation = The following query identifies suspicious .aspx created in 3 paths identified by Microsoft as known drop locations for Exchange exploitation related to HAFNIUM group. Paths include: `\HttpProxy\owa\auth\`, `\inetpub\wwwroot\aspnet_client\`, and `\HttpProxy\OAB\`. Upon triage, the suspicious .aspx file will have a randomized name of 8 characters long. Review the file for suspect commands. Identify additional log sources, IIS included, to review source and other potential exploitation. +explanation = The following query identifies suspicious .aspx created in 3 paths identified by Microsoft as known drop locations for Exchange exploitation related to HAFNIUM group. Paths include: `\HttpProxy\owa\auth\`, `\inetpub\wwwroot\aspnet_client\`, and `\HttpProxy\OAB\`. Upon triage, the suspicious .aspx file will likely look obvious on the surface. inspect the contents for script code inside. Identify additional log sources, IIS included, to review source and other potential exploitation. how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node and `Filesystem` node. annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1505.003"]} known_false_positives = The query is structured in a way that `action` (read, create) is not defined. Review the results of this query, filter, and tune as necessary. It may be necessary to generate this query specific to your endpoint product. @@ -3000,6 +3154,16 @@ annotations = {"cis20": ["CIS 8"], "kill_chain_phases": ["Actions on Objectives" known_false_positives = Some applications and users may legitimately use attrib.exe to interact with the files. providing_technologies = [] +[savedsearch://ESCU - High File Deletion Frequency - Rule] +type = detection +asset_type = +confidence = medium +explanation = This search looks for high frequency of file deletion relative to process name and process id. These events usually happen when the ransomware tries to encrypt the files with the ransomware file extensions and sysmon treat the original files to be deleted as soon it was replace as encrypted data. +how_to_implement = To successfully implement this search, you need to be ingesting logs with the deleted target file name, process name and process id from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. +annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1485"]} +known_false_positives = user may delete bunch of pictures or files in a folder. +providing_technologies = [] + [savedsearch://ESCU - High Number of Login Failures from a single source - Rule] type = detection asset_type = Office 365 @@ -3010,6 +3174,16 @@ annotations = {"cis20": ["CIS 16"], "kill_chain_phases": ["Actions on Objectives known_false_positives = unknown providing_technologies = [] +[savedsearch://ESCU - High Process Termination Frequency - Rule] +type = detection +asset_type = +confidence = medium +explanation = This analytics are designed to indentify a high frequency of process termination on a machine which is a common behavior of ransomware malware before encrypting files. This technique is designed to avoid an exception error while accessing (docs, images, database and etc..) in the infected machine for encryption. +how_to_implement = To successfully implement this search, you need to be ingesting logs with the Image (process full path of terminated process) from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. +annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1486"]} +known_false_positives = admin or user tool that can terminate multiple process. +providing_technologies = [] + [savedsearch://ESCU - Hosts receiving high volume of network traffic from email server - Rule] type = detection asset_type = Endpoint @@ -3487,7 +3661,7 @@ type = detection asset_type = Office 365 confidence = medium explanation = This search detects when an admin configured a forwarding rule for multiple mailboxes to the same destination. -how_to_implement = +how_to_implement = You must install splunk Microsoft Office 365 add-on. This search works with o365:management:activity annotations = {"cis20": ["CIS 16"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1114.003"], "nist": ["DE.DP", "DE.AE"]} known_false_positives = unknown providing_technologies = [] @@ -3497,7 +3671,7 @@ type = detection asset_type = Office 365 confidence = medium explanation = This search detects the assignment of rights to accesss content from another mailbox. This is usually only assigned to a service account. -how_to_implement = +how_to_implement = You must install splunk Microsoft Office 365 add-on. This search works with o365:management:activity annotations = {"cis20": ["CIS 16"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1114.002"], "nist": ["DE.DP", "DE.AE"]} known_false_positives = Service Accounts providing_technologies = [] @@ -3507,7 +3681,7 @@ type = detection asset_type = Office 365 confidence = medium explanation = This search detects when multiple user configured a forwarding rule to the same destination. -how_to_implement = +how_to_implement = You must install splunk Microsoft Office 365 add-on. This search works with o365:management:activity annotations = {"cis20": ["CIS 16"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1114.003"], "nist": ["DE.DP", "DE.AE"]} known_false_positives = unknown providing_technologies = [] @@ -3582,6 +3756,16 @@ annotations = {"cis20": ["CIS 7", "CIS 8"], "kill_chain_phases": ["Installation" known_false_positives = This detection should yield little or no false positive results. It is uncommon for LNK files to be executed from temporary or user directories. providing_technologies = [] +[savedsearch://ESCU - Process Deleting Its Process File Path - Rule] +type = detection +asset_type = +confidence = medium +explanation = This detection is to identify a suspicious process that tries to delete the process file path related to its process. This technique is known to be defense evasion once a certain condition of malware is satisfied or not. Clop ransomware use this technique where it will try to delete its process file path using a .bat command if the keyboard layout is not the layout it tries to infect. +how_to_implement = You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. +annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1003.002"]} +known_false_positives = unknown +providing_technologies = [] + [savedsearch://ESCU - Process Execution via WMI - Rule] type = detection asset_type = Endpoint @@ -3662,6 +3846,16 @@ annotations = {"cis20": ["CIS 9", "CIS 14"], "kill_chain_phases": ["Reconnaissan known_false_positives = Some networks may use kerberized FTP or telnet servers, however, this is rare. providing_technologies = [] +[savedsearch://ESCU - Ransomware Notes bulk creation - Rule] +type = detection +asset_type = +confidence = medium +explanation = The following analytics identifies a big number of instance of ransomware notes (filetype e.g .txt, .html, .hta) file creation to the infected machine. This behavior is a good sensor if the ransomware note filename is quite new for security industry or the ransomware note filename is not in your lookup table list for monitoring. +how_to_implement = You must be ingesting data that records the filesystem activity from your hosts to populate the Endpoint file-system data model node. If you are using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which you want to collect data. +annotations = {"kill_chain_phases": ["Obfuscation"], "mitre_attack": ["T1486"]} +known_false_positives = unknown +providing_technologies = [] + [savedsearch://ESCU - Reg exe Manipulating Windows Services Registry Keys - Rule] type = detection asset_type = Endpoint @@ -3772,6 +3966,16 @@ annotations = {"cis20": ["CIS 3", "CIS 5"], "kill_chain_phases": ["Actions on Ob known_false_positives = Administrators may use this legitimately to gather info from remote systems. providing_technologies = [] +[savedsearch://ESCU - Resize ShadowStorage volume - Rule] +type = detection +asset_type = +confidence = medium +explanation = The following analytics identifies the resizing of shadowstorage by ransomware malware to avoid the shadow volumes being made again. this technique is an alternative by ransomware attacker than deleting the shadowstorage which is known alert in defensive team. one example of ransomware that use this technique is CLOP ransomware where it drops a .bat file that will resize the shadowstorage to minimum size as much as possible +how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. +annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1490"]} +known_false_positives = network admin can resize the shadowstorage for valid purposes. +providing_technologies = [] + [savedsearch://ESCU - RunDLL Loading DLL By Ordinal - Rule] type = detection asset_type = Endpoint @@ -4227,7 +4431,7 @@ asset_type = Endpoint confidence = medium explanation = The following analytic identifies a renamed instance of microsoft.workflow.compiler.exe. Microsoft.workflow.compiler.exe is natively found in C:\Windows\Microsoft.NET\Framework64\v4.0.30319 and is rarely utilized. When investigating, identify the executed code on disk and review. A spawned child process from microsoft.workflow.compiler.exe is uncommon. In any instance, microsoft.workflow.compiler.exe spawning from an Office product or any living off the land binary is highly suspect. how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. -annotations = {"cis20": ["CIS 8"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1127, T1036.003"], "nist": ["PR.PT", "DE.CM"]} +annotations = {"cis20": ["CIS 8"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1127", "T1036.003"], "nist": ["PR.PT", "DE.CM"]} known_false_positives = Although unlikely, some legitimate applications may use a moved copy of microsoft.workflow.compiler.exe, triggering a false positive. providing_technologies = [] diff --git a/package/default/app.conf b/package/default/app.conf index 0621f791a2..47133c14dc 100644 --- a/package/default/app.conf +++ b/package/default/app.conf @@ -4,7 +4,7 @@ is_configured = false state = enabled state_change_requires_restart = false -build = 22604 +build = 25386 [triggers] reload.analytic_stories = simple @@ -19,7 +19,7 @@ reload.content-version = simple [launcher] author = Splunk -version = 3.17.0 +version = 3.18.0 description = Explore the Analytic Stories included with ES Content Updates. [ui] diff --git a/package/default/collections.conf b/package/default/collections.conf index 5bdaf1ca5f..f4284e2876 100644 --- a/package/default/collections.conf +++ b/package/default/collections.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security_content -# On Date: 2021-03-12T17:19:06 UTC +# On Date: 2021-03-25T19:21:00 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# diff --git a/package/default/content-version.conf b/package/default/content-version.conf index f9a49beb45..e45a39998e 100644 --- a/package/default/content-version.conf +++ b/package/default/content-version.conf @@ -1,2 +1,2 @@ [content-version] -version = 3.17.0 +version = 3.18.0 diff --git a/package/default/es_investigations.conf b/package/default/es_investigations.conf index d0295bd719..9d37ea4966 100644 --- a/package/default/es_investigations.conf +++ b/package/default/es_investigations.conf @@ -11,28 +11,35 @@ label = AWS Cryptomining description = Monitor your AWS EC2 instances for activities related to cryptojacking/cryptomining. New instances that originate from previously unseen regions, users who launch abnormally high numbers of instances, or EC2 instances started by previously unseen users are just a few examples of potentially malicious behavior. disabled = 0 -panels = ["panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_investigate_aws_activities_via_region_name___response_task", "panel://workbench_panel_get_ec2_launch_details___response_task", "panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_get_ec2_instance_details_by_instanceid___response_task"] +panels = ["panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_get_ec2_instance_details_by_instanceid___response_task", "panel://workbench_panel_investigate_aws_activities_via_region_name___response_task", "panel://workbench_panel_get_ec2_launch_details___response_task", "panel://workbench_panel_get_notable_history___response_task"] + +[panel_group://workbench_panel_group_aws_iam_privilege_escalation] +label = AWS IAM Privilege Escalation +description = This analytic story contains detections that query your AWS Cloudtrail for activities related to privilege escalation. +disabled = 0 + +panels = ["panel://workbench_panel_get_notable_history___response_task"] [panel_group://workbench_panel_group_aws_network_acl_activity] label = AWS Network ACL Activity description = Monitor your AWS network infrastructure for bad configurations and malicious activity. Investigative searches help you probe deeper, when the facts warrant it. disabled = 0 -panels = ["panel://workbench_panel_get_dns_server_history_for_a_host___response_task", "panel://workbench_panel_aws_network_interface_details_via_resourceid___response_task", "panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_get_all_aws_activity_from_ip_address___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_dns_traffic_ratio___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_aws_network_acl_details_from_id___response_task", "panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_get_process_responsible_for_the_dns_traffic___response_task"] +panels = ["panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_get_dns_server_history_for_a_host___response_task", "panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_get_process_responsible_for_the_dns_traffic___response_task", "panel://workbench_panel_get_dns_traffic_ratio___response_task", "panel://workbench_panel_get_all_aws_activity_from_ip_address___response_task", "panel://workbench_panel_aws_network_interface_details_via_resourceid___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_aws_network_acl_details_from_id___response_task"] [panel_group://workbench_panel_group_aws_security_hub_alerts] label = AWS Security Hub Alerts description = This story is focused around detecting Security Hub alerts generated from AWS disabled = 0 -panels = ["panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_get_ec2_launch_details___response_task", "panel://workbench_panel_get_ec2_instance_details_by_instanceid___response_task"] +panels = ["panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_get_ec2_instance_details_by_instanceid___response_task", "panel://workbench_panel_get_ec2_launch_details___response_task"] [panel_group://workbench_panel_group_aws_suspicious_provisioning_activities] label = AWS Suspicious Provisioning Activities description = Monitor your AWS provisioning activities for behaviors originating from unfamiliar or unusual locations. These behaviors may indicate that malicious activities are occurring somewhere within your network. disabled = 0 -panels = ["panel://workbench_panel_get_all_aws_activity_from_ip_address___response_task", "panel://workbench_panel_aws_investigate_security_hub_alerts_by_dest___response_task", "panel://workbench_panel_get_all_aws_activity_from_region___response_task", "panel://workbench_panel_get_all_aws_activity_from_country___response_task", "panel://workbench_panel_get_all_aws_activity_from_city___response_task", "panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task"] +panels = ["panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_get_all_aws_activity_from_city___response_task", "panel://workbench_panel_get_all_aws_activity_from_ip_address___response_task", "panel://workbench_panel_aws_investigate_security_hub_alerts_by_dest___response_task", "panel://workbench_panel_get_all_aws_activity_from_region___response_task", "panel://workbench_panel_get_all_aws_activity_from_country___response_task"] [panel_group://workbench_panel_group_aws_user_monitoring] label = AWS User Monitoring @@ -67,14 +74,21 @@ label = Brand Monitoring description = Detect and investigate activity that may indicate that an adversary is using faux domains to mislead users into interacting with malicious infrastructure. Monitor DNS, email, and web traffic for permutations of your brand name. disabled = 0 -panels = ["panel://workbench_panel_get_email_info___response_task", "panel://workbench_panel_get_emails_from_specific_sender___response_task", "panel://workbench_panel_get_process_responsible_for_the_dns_traffic___response_task", "panel://workbench_panel_get_notable_history___response_task"] +panels = ["panel://workbench_panel_get_process_responsible_for_the_dns_traffic___response_task", "panel://workbench_panel_get_emails_from_specific_sender___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_email_info___response_task"] + +[panel_group://workbench_panel_group_clop_ransomware] +label = Clop Ransomware +description = Leverage searches that allow you to detect and investigate unusual activities that might relate to the Clop ransomware, including looking for file writes associated with Clope, encrypting network shares, deleting and resizing shadow volume storage, registry key modification, deleting of security logs, and more. +disabled = 0 + +panels = ["panel://workbench_panel_get_notable_history___response_task"] [panel_group://workbench_panel_group_cloud_cryptomining] label = Cloud Cryptomining description = Monitor your cloud compute instances for activities related to cryptojacking/cryptomining. New instances that originate from previously unseen regions, users who launch abnormally high numbers of instances, or compute instances started by previously unseen users are just a few examples of potentially malicious behavior. disabled = 0 -panels = ["panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_aws_investigate_security_hub_alerts_by_dest___response_task", "panel://workbench_panel_investigate_aws_activities_via_region_name___response_task", "panel://workbench_panel_get_ec2_launch_details___response_task", "panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_get_ec2_instance_details_by_instanceid___response_task"] +panels = ["panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_get_ec2_instance_details_by_instanceid___response_task", "panel://workbench_panel_investigate_aws_activities_via_region_name___response_task", "panel://workbench_panel_aws_investigate_security_hub_alerts_by_dest___response_task", "panel://workbench_panel_get_ec2_launch_details___response_task", "panel://workbench_panel_get_notable_history___response_task"] [panel_group://workbench_panel_group_cloud_federated_credential_abuse] label = Cloud Federated Credential Abuse @@ -109,7 +123,7 @@ label = Command and Control description = Detect and investigate tactics, techniques, and procedures leveraged by attackers to establish and operate command and control channels. Implants installed by attackers on compromised endpoints use these channels to receive instructions and send data back to the malicious operators. disabled = 0 -panels = ["panel://workbench_panel_get_dns_server_history_for_a_host___response_task", "panel://workbench_panel_aws_network_interface_details_via_resourceid___response_task", "panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_get_all_aws_activity_from_ip_address___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_dns_traffic_ratio___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_aws_network_acl_details_from_id___response_task", "panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_process_responsible_for_the_dns_traffic___response_task"] +panels = ["panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_get_dns_server_history_for_a_host___response_task", "panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_get_process_responsible_for_the_dns_traffic___response_task", "panel://workbench_panel_get_dns_traffic_ratio___response_task", "panel://workbench_panel_get_all_aws_activity_from_ip_address___response_task", "panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_aws_network_interface_details_via_resourceid___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_aws_network_acl_details_from_id___response_task"] [panel_group://workbench_panel_group_common_phishing_frameworks] label = Common Phishing Frameworks @@ -130,14 +144,14 @@ label = Credential Dumping description = Uncover activity consistent with credential dumping, a technique wherein attackers compromise systems and attempt to obtain and exfiltrate passwords. The threat actors use these pilfered credentials to further escalate privileges and spread throughout a target environment. The included searches in this Analytic Story are designed to identify attempts to credential dumping. disabled = 0 -panels = ["panel://workbench_panel_investigate_failed_logins_for_multiple_destinations___response_task", "panel://workbench_panel_investigate_previous_unseen_user___response_task", "panel://workbench_panel_investigate_pass_the_hash_attempts___response_task", "panel://workbench_panel_investigate_pass_the_ticket_attempts___response_task"] +panels = ["panel://workbench_panel_investigate_pass_the_ticket_attempts___response_task", "panel://workbench_panel_investigate_previous_unseen_user___response_task", "panel://workbench_panel_investigate_failed_logins_for_multiple_destinations___response_task", "panel://workbench_panel_investigate_pass_the_hash_attempts___response_task"] [panel_group://workbench_panel_group_dhs_report_ta18_074a] label = DHS Report TA18-074A description = Monitor for suspicious activities associated with DHS Technical Alert US-CERT TA18-074A. Some of the activities that adversaries used in these compromises included spearfishing attacks, malware, watering-hole domains, many and more. disabled = 0 -panels = ["panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_process_file_activity___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_parent_process_info___response_task"] +panels = ["panel://workbench_panel_get_process_file_activity___response_task", "panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task"] [panel_group://workbench_panel_group_dns_amplification_attacks] label = DNS Amplification Attacks @@ -165,7 +179,14 @@ label = Data Protection description = Fortify your data-protection arsenal--while continuing to ensure data confidentiality and integrity--with searches that monitor for and help you investigate possible signs of data exfiltration. disabled = 0 -panels = ["panel://workbench_panel_get_dns_server_history_for_a_host___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_dns_traffic_ratio___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_process_responsible_for_the_dns_traffic___response_task"] +panels = ["panel://workbench_panel_get_dns_server_history_for_a_host___response_task", "panel://workbench_panel_get_process_responsible_for_the_dns_traffic___response_task", "panel://workbench_panel_get_dns_traffic_ratio___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task"] + +[panel_group://workbench_panel_group_deobfuscate_decode_files_or_information] +label = Deobfuscate-Decode Files or Information +description = Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis. +disabled = 0 + +panels = ["panel://workbench_panel_get_notable_history___response_task"] [panel_group://workbench_panel_group_detect_zerologon_attack] label = Detect Zerologon Attack @@ -186,14 +207,14 @@ label = Dynamic DNS description = Detect and investigate hosts in your environment that may be communicating with dynamic domain providers. Attackers may leverage these services to help them avoid firewall blocks and deny lists. disabled = 0 -panels = ["panel://workbench_panel_get_dns_server_history_for_a_host___response_task", "panel://workbench_panel_get_process_responsible_for_the_dns_traffic___response_task", "panel://workbench_panel_get_dns_traffic_ratio___response_task", "panel://workbench_panel_get_notable_history___response_task"] +panels = ["panel://workbench_panel_get_process_responsible_for_the_dns_traffic___response_task", "panel://workbench_panel_get_dns_traffic_ratio___response_task", "panel://workbench_panel_get_dns_server_history_for_a_host___response_task", "panel://workbench_panel_get_notable_history___response_task"] [panel_group://workbench_panel_group_emotet_malware__dhs_report_ta18_201a_] label = Emotet Malware DHS Report TA18-201A description = Detect rarely used executables, specific registry paths that may confer malware survivability and persistence, instances where cmd.exe is used to launch script interpreters, and other indicators that the Emotet financial malware has compromised your environment. disabled = 0 -panels = ["panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_history_of_email_sources___response_task"] +panels = ["panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_get_history_of_email_sources___response_task", "panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task"] [panel_group://workbench_panel_group_f5_tmui_rce_cve_2020_5902] label = F5 TMUI RCE CVE-2020-5902 @@ -221,7 +242,7 @@ label = Hidden Cobra Malware description = Monitor for and investigate activities, including the creation or deletion of hidden shares and file writes, that may be evidence of infiltration by North Korean government-sponsored cybercriminals. Details of this activity were reported in DHS Report TA-18-149A. disabled = 0 -panels = ["panel://workbench_panel_get_dns_server_history_for_a_host___response_task", "panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_outbound_emails_to_hidden_cobra_threat_actors___response_task", "panel://workbench_panel_get_dns_traffic_ratio___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_investigate_successful_remote_desktop_authentications___response_task", "panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_history_of_email_sources___response_task", "panel://workbench_panel_get_process_responsible_for_the_dns_traffic___response_task"] +panels = ["panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_get_dns_server_history_for_a_host___response_task", "panel://workbench_panel_get_process_responsible_for_the_dns_traffic___response_task", "panel://workbench_panel_get_dns_traffic_ratio___response_task", "panel://workbench_panel_get_history_of_email_sources___response_task", "panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_investigate_successful_remote_desktop_authentications___response_task", "panel://workbench_panel_get_outbound_emails_to_hidden_cobra_threat_actors___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task"] [panel_group://workbench_panel_group_host_redirection] label = Host Redirection @@ -230,6 +251,13 @@ disabled = 0 panels = ["panel://workbench_panel_get_dns_server_history_for_a_host___response_task", "panel://workbench_panel_get_notable_history___response_task"] +[panel_group://workbench_panel_group_ingress_tool_transfer] +label = Ingress Tool Transfer +description = Adversaries may transfer tools or other files from an external system into a compromised environment. Files may be copied from an external adversary controlled system through the command and control channel to bring tools into the victim network or through alternate protocols with another tool such as FTP. +disabled = 0 + +panels = ["panel://workbench_panel_get_notable_history___response_task"] + [panel_group://workbench_panel_group_jboss_vulnerability] label = JBoss Vulnerability description = In March of 2016, adversaries were seen using JexBoss--an open-source utility used for testing and exploiting JBoss application servers. These searches help detect evidence of these attacks, such as network connections to external resources or web services spawning atypical child processes, among others. @@ -242,7 +270,7 @@ label = Kubernetes Scanning Activity description = This story addresses detection against Kubernetes cluster fingerprint scan and attack by providing information on items such as source ip, user agent, cluster names. disabled = 0 -panels = ["panel://workbench_panel_gcp_kubernetes_activity_by_src_ip___response_task", "panel://workbench_panel_amazon_eks_kubernetes_activity_by_src_ip___response_task", "panel://workbench_panel_get_notable_history___response_task"] +panels = ["panel://workbench_panel_gcp_kubernetes_activity_by_src_ip___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_amazon_eks_kubernetes_activity_by_src_ip___response_task"] [panel_group://workbench_panel_group_kubernetes_sensitive_object_access_activity] label = Kubernetes Sensitive Object Access Activity @@ -263,14 +291,14 @@ label = Lateral Movement description = Detect and investigate tactics, techniques, and procedures around how attackers move laterally within the enterprise. Because lateral movement can expose the adversary to detection, it should be an important focus for security analysts. disabled = 0 -panels = ["panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_investigate_successful_remote_desktop_authentications___response_task", "panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_history_of_email_sources___response_task"] +panels = ["panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_get_history_of_email_sources___response_task", "panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_investigate_successful_remote_desktop_authentications___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task"] [panel_group://workbench_panel_group_malicious_powershell] label = Malicious PowerShell description = Attackers are finding stealthy ways "live off the land," leveraging utilities and tools that come standard on the endpoint--such as PowerShell--to achieve their goals without downloading binary files. These searches can help you detect and investigate PowerShell command-line options that may be indicative of malicious intent. disabled = 0 -panels = ["panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_history_of_email_sources___response_task", "panel://workbench_panel_get_notable_history___response_task"] +panels = ["panel://workbench_panel_get_history_of_email_sources___response_task", "panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task"] [panel_group://workbench_panel_group_monitor_backup_solution] label = Monitor Backup Solution @@ -319,7 +347,7 @@ label = Orangeworm Attack Group description = Detect activities and various techniques associated with the Orangeworm Attack Group, a group that frequently targets the healthcare industry. disabled = 0 -panels = ["panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_history_of_email_sources___response_task", "panel://workbench_panel_get_notable_history___response_task"] +panels = ["panel://workbench_panel_get_history_of_email_sources___response_task", "panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task"] [panel_group://workbench_panel_group_phishing_payloads] label = Phishing Payloads @@ -333,21 +361,21 @@ label = Possible Backdoor Activity Associated With MUDCARP Espionage Campaigns description = Monitor your environment for suspicious behaviors that resemble the techniques employed by the MUDCARP threat group. disabled = 0 -panels = ["panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_history_of_email_sources___response_task", "panel://workbench_panel_get_notable_history___response_task"] +panels = ["panel://workbench_panel_get_history_of_email_sources___response_task", "panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task"] [panel_group://workbench_panel_group_prohibited_traffic_allowed_or_protocol_mismatch] label = Prohibited Traffic Allowed or Protocol Mismatch description = Detect instances of prohibited network traffic allowed in the environment, as well as protocols running on non-standard ports. Both of these types of behaviors typically violate policy and can be leveraged by attackers. disabled = 0 -panels = ["panel://workbench_panel_get_dns_server_history_for_a_host___response_task", "panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_parent_process_info___response_task"] +panels = ["panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_get_dns_server_history_for_a_host___response_task", "panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task"] [panel_group://workbench_panel_group_ransomware] label = Ransomware description = Leverage searches that allow you to detect and investigate unusual activities that might relate to ransomware--spikes in SMB traffic, suspicious wevtutil usage, the presence of common ransomware extensions, and system processes run from unexpected locations, and many others. disabled = 0 -panels = ["panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_backup_logs_for_endpoint___response_task", "panel://workbench_panel_get_sysmon_wmi_activity_for_host___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_history_of_email_sources___response_task"] +panels = ["panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_get_sysmon_wmi_activity_for_host___response_task", "panel://workbench_panel_get_history_of_email_sources___response_task", "panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_backup_logs_for_endpoint___response_task"] [panel_group://workbench_panel_group_ransomware_cloud] label = Ransomware Cloud @@ -382,7 +410,7 @@ label = SamSam Ransomware description = Leverage searches that allow you to detect and investigate unusual activities that might relate to the SamSam ransomware, including looking for file writes associated with SamSam, RDP brute force attacks, the presence of files with SamSam ransomware extensions, suspicious psexec use, and more. disabled = 0 -panels = ["panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_backup_logs_for_endpoint___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_investigate_successful_remote_desktop_authentications___response_task", "panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_history_of_email_sources___response_task"] +panels = ["panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_get_history_of_email_sources___response_task", "panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_investigate_successful_remote_desktop_authentications___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_backup_logs_for_endpoint___response_task"] [panel_group://workbench_panel_group_silver_sparrow] label = Silver Sparrow @@ -417,7 +445,7 @@ label = Suspicious AWS EC2 Activities description = Use the searches in this Analytic Story to monitor your AWS EC2 instances for evidence of anomalous activity and suspicious behaviors, such as EC2 instances that originate from unusual locations or those launched by previously unseen users (among others). Included investigative searches will help you probe more deeply, when the information warrants it. disabled = 0 -panels = ["panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_aws_investigate_security_hub_alerts_by_dest___response_task", "panel://workbench_panel_investigate_aws_activities_via_region_name___response_task", "panel://workbench_panel_get_ec2_launch_details___response_task", "panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_get_ec2_instance_details_by_instanceid___response_task"] +panels = ["panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_get_ec2_instance_details_by_instanceid___response_task", "panel://workbench_panel_investigate_aws_activities_via_region_name___response_task", "panel://workbench_panel_aws_investigate_security_hub_alerts_by_dest___response_task", "panel://workbench_panel_get_ec2_launch_details___response_task", "panel://workbench_panel_get_notable_history___response_task"] [panel_group://workbench_panel_group_suspicious_aws_login_activities] label = Suspicious AWS Login Activities @@ -431,14 +459,14 @@ label = Suspicious AWS S3 Activities description = Use the searches in this Analytic Story to monitor your AWS S3 buckets for evidence of anomalous activity and suspicious behaviors, such as detecting open S3 buckets and buckets being accessed from a new IP. The contextual and investigative searches will give you more information, when required. disabled = 0 -panels = ["panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_all_aws_activity_from_ip_address___response_task", "panel://workbench_panel_aws_s3_bucket_details_via_bucketname___response_task", "panel://workbench_panel_investigate_aws_activities_via_region_name___response_task", "panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task"] +panels = ["panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_aws_s3_bucket_details_via_bucketname___response_task", "panel://workbench_panel_investigate_aws_activities_via_region_name___response_task", "panel://workbench_panel_get_all_aws_activity_from_ip_address___response_task", "panel://workbench_panel_get_notable_history___response_task"] [panel_group://workbench_panel_group_suspicious_aws_traffic] label = Suspicious AWS Traffic description = Leverage these searches to monitor your AWS network traffic for evidence of anomalous activity and suspicious behaviors, such as a spike in blocked outbound traffic in your virtual private cloud (VPC). disabled = 0 -panels = ["panel://workbench_panel_get_dns_server_history_for_a_host___response_task", "panel://workbench_panel_aws_network_interface_details_via_resourceid___response_task", "panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_get_all_aws_activity_from_ip_address___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_dns_traffic_ratio___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_aws_network_acl_details_from_id___response_task", "panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_get_process_responsible_for_the_dns_traffic___response_task"] +panels = ["panel://workbench_panel_get_process_information_for_port_activity___response_task", "panel://workbench_panel_get_dns_server_history_for_a_host___response_task", "panel://workbench_panel_aws_investigate_user_activities_by_arn___response_task", "panel://workbench_panel_get_process_responsible_for_the_dns_traffic___response_task", "panel://workbench_panel_get_dns_traffic_ratio___response_task", "panel://workbench_panel_get_all_aws_activity_from_ip_address___response_task", "panel://workbench_panel_aws_network_interface_details_via_resourceid___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_aws_network_acl_details_from_id___response_task"] [panel_group://workbench_panel_group_suspicious_cloud_authentication_activities] label = Suspicious Cloud Authentication Activities @@ -480,14 +508,14 @@ label = Suspicious DNS Traffic description = Attackers often attempt to hide within or otherwise abuse the domain name system (DNS). You can thwart attempts to manipulate this omnipresent protocol by monitoring for these types of abuses. disabled = 0 -panels = ["panel://workbench_panel_get_dns_server_history_for_a_host___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_dns_traffic_ratio___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_process_responsible_for_the_dns_traffic___response_task"] +panels = ["panel://workbench_panel_get_dns_server_history_for_a_host___response_task", "panel://workbench_panel_get_process_responsible_for_the_dns_traffic___response_task", "panel://workbench_panel_get_dns_traffic_ratio___response_task", "panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task"] [panel_group://workbench_panel_group_suspicious_emails] label = Suspicious Emails description = Email remains one of the primary means for attackers to gain an initial foothold within the modern enterprise. Detect and investigate suspicious emails in your environment with the help of the searches in this Analytic Story. disabled = 0 -panels = ["panel://workbench_panel_get_email_info___response_task", "panel://workbench_panel_get_emails_from_specific_sender___response_task", "panel://workbench_panel_get_notable_history___response_task"] +panels = ["panel://workbench_panel_get_emails_from_specific_sender___response_task", "panel://workbench_panel_get_notable_history___response_task", "panel://workbench_panel_get_email_info___response_task"] [panel_group://workbench_panel_group_suspicious_gcp_storage_activities] label = Suspicious GCP Storage Activities @@ -508,7 +536,7 @@ label = Suspicious Okta Activity description = Monitor your Okta environment for suspicious activities. Due to the Covid outbreak, many users are migrating over to leverage cloud services more and more. Okta is a popular tool to manage multiple users and the web-based applications they need to stay productive. The searches in this story will help monitor your Okta environment for suspicious activities and associated user behaviors. disabled = 0 -panels = ["panel://workbench_panel_investigate_okta_activity_by_ip_address___response_task", "panel://workbench_panel_investigate_user_activities_in_okta___response_task", "panel://workbench_panel_investigate_okta_activity_by_app___response_task"] +panels = ["panel://workbench_panel_investigate_okta_activity_by_app___response_task", "panel://workbench_panel_investigate_okta_activity_by_ip_address___response_task", "panel://workbench_panel_investigate_user_activities_in_okta___response_task"] [panel_group://workbench_panel_group_suspicious_regsvr32_activity] label = Suspicious Regsvr32 Activity @@ -529,7 +557,7 @@ label = Suspicious WMI Use description = Attackers are increasingly abusing Windows Management Instrumentation (WMI), a framework and associated utilities available on all modern Windows operating systems. Because WMI can be leveraged to manage both local and remote systems, it is important to identify the processes executed and the user context within which the activity occurred. disabled = 0 -panels = ["panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_sysmon_wmi_activity_for_host___response_task", "panel://workbench_panel_get_notable_history___response_task"] +panels = ["panel://workbench_panel_get_sysmon_wmi_activity_for_host___response_task", "panel://workbench_panel_get_parent_process_info___response_task", "panel://workbench_panel_get_process_info___response_task", "panel://workbench_panel_get_notable_history___response_task"] [panel_group://workbench_panel_group_suspicious_windows_registry_activities] label = Suspicious Windows Registry Activities @@ -585,7 +613,7 @@ label = Web Fraud Detection description = Monitor your environment for activity consistent with common attack techniques bad actors use when attempting to compromise web servers or other web-related assets. disabled = 0 -panels = ["panel://workbench_panel_get_web_session_information_via_session_id___response_task", "panel://workbench_panel_get_emails_from_specific_sender___response_task", "panel://workbench_panel_get_notable_history___response_task"] +panels = ["panel://workbench_panel_get_emails_from_specific_sender___response_task", "panel://workbench_panel_get_web_session_information_via_session_id___response_task", "panel://workbench_panel_get_notable_history___response_task"] [panel_group://workbench_panel_group_windows_dns_sigred_cve_2020_1350] label = Windows DNS SIGRed CVE-2020-1350 diff --git a/package/default/macros.conf b/package/default/macros.conf index f14dd819d8..c2f4496853 100644 --- a/package/default/macros.conf +++ b/package/default/macros.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security_content -# On Date: 2021-03-12T17:19:06 UTC +# On Date: 2021-03-25T19:21:00 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# @@ -307,6 +307,18 @@ description = Update this macro to limit the output results to filter out false definition = search * description = Update this macro to limit the output results to filter out false positives. +[aws_create_policy_version_to_allow_all_resources_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + +[aws_createaccesskey_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + +[aws_createloginprofile_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + [aws_cross_account_activity_from_previously_unseen_account_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. @@ -339,6 +351,14 @@ description = Update this macro to limit the output results to filter out false definition = search * description = Update this macro to limit the output results to filter out false positives. +[aws_setdefaultpolicyversion_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + +[aws_updateloginprofile_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + [abnormally_high_aws_instances_launched_by_user_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. @@ -415,6 +435,18 @@ description = Update this macro to limit the output results to filter out false definition = search * description = Update this macro to limit the output results to filter out false positives. +[certutil_download_with_urlcache_and_split_arguments_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + +[certutil_download_with_verifyctl_and_split_arguments_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + +[certutil_with_decode_argument_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + [certutil_exe_certificate_extraction_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. @@ -427,6 +459,14 @@ description = Update this macro to limit the output results to filter out false definition = search * description = Update this macro to limit the output results to filter out false positives. +[clop_common_exec_parameter_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + +[clop_ransomware_known_service_name_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + [cloud_api_calls_from_previously_unseen_user_roles_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. @@ -487,6 +527,10 @@ description = Update this macro to limit the output results to filter out false definition = search * description = Update this macro to limit the output results to filter out false positives. +[create_service_in_suspicious_file_path_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + [create_local_admin_accounts_using_net_exe_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. @@ -975,10 +1019,18 @@ description = Update this macro to limit the output results to filter out false definition = search * description = Update this macro to limit the output results to filter out false positives. +[high_file_deletion_frequency_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + [high_number_of_login_failures_from_a_single_source_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. +[high_process_termination_frequency_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + [hosts_receiving_high_volume_of_network_traffic_from_email_server_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. @@ -1207,6 +1259,10 @@ description = Update this macro to limit the output results to filter out false definition = search * description = Update this macro to limit the output results to filter out false positives. +[process_deleting_its_process_file_path_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + [process_execution_via_wmi_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. @@ -1239,6 +1295,10 @@ description = Update this macro to limit the output results to filter out false definition = search * description = Update this macro to limit the output results to filter out false positives. +[ransomware_notes_bulk_creation_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + [reg_exe_manipulating_windows_services_registry_keys_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. @@ -1283,6 +1343,10 @@ description = Update this macro to limit the output results to filter out false definition = search * description = Update this macro to limit the output results to filter out false positives. +[resize_shadowstorage_volume_filter] +definition = search * +description = Update this macro to limit the output results to filter out false positives. + [rundll_loading_dll_by_ordinal_filter] definition = search * description = Update this macro to limit the output results to filter out false positives. diff --git a/package/default/savedsearches.conf b/package/default/savedsearches.conf index 2bbc7b7539..19bd327409 100644 --- a/package/default/savedsearches.conf +++ b/package/default/savedsearches.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security_content -# On Date: 2021-03-12T17:19:06 UTC +# On Date: 2021-03-25T19:21:00 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# @@ -152,6 +152,123 @@ realtime_schedule = 0 is_visible = false search = `cloudtrail` (eventName=Run* OR eventName=Create*) | iplocation sourceIPAddress | search Region=* [search `cloudtrail` (eventName=Run* OR eventName=Create*) | iplocation sourceIPAddress | search Region=* | stats earliest(_time) as firstTime, latest(_time) as lastTime by sourceIPAddress, City, Region, Country | inputlookup append=t previously_seen_provisioning_activity_src.csv | stats min(firstTime) as firstTime max(lastTime) as lastTime by sourceIPAddress, City, Region, Country | outputlookup previously_seen_provisioning_activity_src.csv | stats min(firstTime) as firstTime max(lastTime) as lastTime by Region | eval newRegion=if(firstTime >= relative_time(now(), "-70m@m"), 1, 0) | where newRegion=1 | table Region] | spath output=user userIdentity.arn | rename sourceIPAddress as src_ip | table _time, user, src_ip, Region, eventName, errorCode | `aws_cloud_provisioning_from_previously_unseen_region_filter` +[ESCU - AWS Create Policy Version to allow all resources - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = This search looks for CloudTrail events where a user created a policy version that allows them to access any resource in their account +action.escu.mappings = {"cis20": ["CIS 13"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1078.004"], "nist": ["PR.DS", "PR.AC", "DE.CM"]} +action.escu.data_models = [] +action.escu.eli5 = This search looks for CloudTrail events where a user created a policy version that allows them to access any resource in their account +action.escu.how_to_implement = You must install splunk AWS add on and Splunk App for AWS. This search works with cloudtrail logs. +action.escu.known_false_positives = While this search has no known false positives, it is possible that an AWS admin has legitimately created a policy to allow a user to access all resources. That said, AWS strongly advises against granting full control to all AWS resources +action.escu.creation_date = 2021-02-22 +action.escu.modification_date = 2021-02-22 +action.escu.confidence = high +action.escu.full_search_name = ESCU - AWS Create Policy Version to allow all resources - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = [] +action.escu.analytic_story = ["AWS IAM Privilege Escalation"] +action.risk = 1 +action.risk.param._risk_object = src +action.risk.param._risk_object_type = system +action.risk.param._risk_score = 20 +action.risk.param.verbose = 0 +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - AWS Create Policy Version to allow all resources - Rule +action.correlationsearch.annotations = {"analytic_story": ["AWS IAM Privilege Escalation"], "cis20": ["CIS 13"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1078.004"], "nist": ["PR.DS", "PR.AC", "DE.CM"]} +schedule_window = auto +alert.digest_mode = 1 +disabled = true +enableSched = 1 +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = `cloudtrail` eventName=CreatePolicyVersion eventSource = iam.amazonaws.com errorCode = success | spath input=requestParameters.policyDocument output=key_policy_statements path=Statement{} | mvexpand key_policy_statements | spath input=key_policy_statements output=key_policy_action_1 path=Action | search key_policy_action_1 = "*" | stats count min(_time) as firstTime max(_time) as lastTime values(key_policy_statements) as policy_added by eventName eventSource aws_account_id errorCode userAgent eventID awsRegion userIdentity.principalId user_arn | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`|`aws_create_policy_version_to_allow_all_resources_filter` + +[ESCU - AWS CreateAccessKey - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = This search looks for CloudTrail events where a user A who has already permission to create access keys, makes an API call to create access keys for another user B. Attackers have been know to use this technique for Privilege Escalation in case new victim(user B) has more permissions than old victim(user B) +action.escu.mappings = {"cis20": ["CIS 13"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1136.003"], "nist": ["PR.DS", "PR.AC", "DE.CM"]} +action.escu.data_models = [] +action.escu.eli5 = This search looks for CloudTrail events where a user A who has already permission to create access keys, makes an API call to create access keys for another user B. Attackers have been know to use this technique for Privilege Escalation in case new victim(user B) has more permissions than old victim(user B) +action.escu.how_to_implement = You must install splunk AWS add on and Splunk App for AWS. This search works with cloudtrail logs. +action.escu.known_false_positives = While this search has no known false positives, it is possible that an AWS admin has legitimately created keys for another user. +action.escu.creation_date = 2021-03-02 +action.escu.modification_date = 2021-03-02 +action.escu.confidence = high +action.escu.full_search_name = ESCU - AWS CreateAccessKey - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = [] +action.escu.analytic_story = ["AWS IAM Privilege Escalation"] +action.risk = 1 +action.risk.param._risk_object = src +action.risk.param._risk_object_type = system +action.risk.param._risk_score = 20 +action.risk.param.verbose = 0 +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - AWS CreateAccessKey - Rule +action.correlationsearch.annotations = {"analytic_story": ["AWS IAM Privilege Escalation"], "cis20": ["CIS 13"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1136.003"], "nist": ["PR.DS", "PR.AC", "DE.CM"]} +schedule_window = auto +alert.digest_mode = 1 +disabled = true +enableSched = 1 +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = `cloudtrail` eventName = CreateAccessKey userAgent !=console.amazonaws.com errorCode = success| search userName!=requestParameters.userName | stats count min(_time) as firstTime max(_time) as lastTime by requestParameters.userName src eventName eventSource aws_account_id errorCode userAgent eventID awsRegion userIdentity.principalId user_arn | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`|`aws_createaccesskey_filter` + +[ESCU - AWS CreateLoginProfile - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = This search looks for CloudTrail events where a user A(victim A) creates a login profile for user B, followed by a AWS Console login event from user B from the same src_ip as user B. This correlated event can be indicative of privilege escalation since both events happened from the same src_ip +action.escu.mappings = {"cis20": ["CIS 13"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1136.003"], "nist": ["PR.DS", "PR.AC", "DE.CM"]} +action.escu.data_models = [] +action.escu.eli5 = This search looks for CloudTrail events where a user A(victim A) creates a login profile for user B, followed by a AWS Console login event from user B from the same src_ip as user B. This correlated event can be indicative of privilege escalation since both events happened from the same src_ip +action.escu.how_to_implement = You must install splunk AWS add on and Splunk App for AWS. This search works with cloudtrail logs. +action.escu.known_false_positives = While this search has no known false positives, it is possible that an AWS admin has legitimately created a login profile for another user. +action.escu.creation_date = 2021-03-02 +action.escu.modification_date = 2021-03-02 +action.escu.confidence = high +action.escu.full_search_name = ESCU - AWS CreateLoginProfile - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = [] +action.escu.analytic_story = ["AWS IAM Privilege Escalation"] +action.risk = 1 +action.risk.param._risk_object = src_ip +action.risk.param._risk_object_type = system +action.risk.param._risk_score = 20 +action.risk.param.verbose = 0 +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - AWS CreateLoginProfile - Rule +action.correlationsearch.annotations = {"analytic_story": ["AWS IAM Privilege Escalation"], "cis20": ["CIS 13"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1136.003"], "nist": ["PR.DS", "PR.AC", "DE.CM"]} +schedule_window = auto +alert.digest_mode = 1 +disabled = true +enableSched = 1 +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = `cloudtrail` eventName = CreateLoginProfile | rename requestParameters.userName as new_login_profile | table src_ip eventName new_login_profile userName | join new_login_profile src_ip [| search `cloudtrail` eventName = ConsoleLogin | rename userName as new_login_profile | stats count values(eventName) min(_time) as firstTime max(_time) as lastTime by eventSource aws_account_id errorCode userAgent eventID awsRegion userIdentity.principalId user_arn new_login_profile src_ip | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`] | `aws_createloginprofile_filter` + [ESCU - AWS Cross Account Activity From Previously Unseen Account - Rule] action.escu = 0 action.escu.enabled = 1 @@ -205,9 +322,14 @@ action.escu.modification_date = 2021-01-11 action.escu.confidence = high action.escu.full_search_name = ESCU - AWS Detect Users creating keys with encrypt policy without MFA - Rule action.escu.search_type = detection -action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = [] action.escu.analytic_story = ["Ransomware Cloud"] +action.risk = 1 +action.risk.param._risk_object = userIdentity.principalId +action.risk.param._risk_object_type = user +action.risk.param._risk_score = 20 +action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -239,9 +361,14 @@ action.escu.modification_date = 2021-01-11 action.escu.confidence = high action.escu.full_search_name = ESCU - AWS Detect Users with KMS keys performing encryption S3 - Rule action.escu.search_type = detection -action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = [] action.escu.analytic_story = ["Ransomware Cloud"] +action.risk = 1 +action.risk.param._risk_object = user +action.risk.param._risk_object_type = user +action.risk.param._risk_score = 25 +action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -307,7 +434,7 @@ action.escu.modification_date = 2021-01-11 action.escu.confidence = high action.escu.full_search_name = ESCU - AWS Network Access Control List Created with All Open Ports - Rule action.escu.search_type = detection -action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = [] action.escu.analytic_story = ["AWS Network ACL Activity"] action.risk = 1 @@ -346,7 +473,7 @@ action.escu.modification_date = 2021-01-12 action.escu.confidence = high action.escu.full_search_name = ESCU - AWS Network Access Control List Deleted - Rule action.escu.search_type = detection -action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = [] action.escu.analytic_story = ["AWS Network ACL Activity"] action.risk = 1 @@ -385,9 +512,14 @@ action.escu.modification_date = 2021-01-26 action.escu.confidence = high action.escu.full_search_name = ESCU - AWS SAML Access by Provider User and Principal - Rule action.escu.search_type = detection -action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = [] action.escu.analytic_story = ["Cloud Federated Credential Abuse"] +action.risk = 1 +action.risk.param._risk_object = recipientAccountId +action.risk.param._risk_object_type = other +action.risk.param._risk_score = 25 +action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -419,9 +551,14 @@ action.escu.modification_date = 2021-01-26 action.escu.confidence = high action.escu.full_search_name = ESCU - AWS SAML Update identity provider - Rule action.escu.search_type = detection -action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = [] action.escu.analytic_story = ["Cloud Federated Credential Abuse"] +action.risk = 1 +action.risk.param._risk_object = sourceIPAddress +action.risk.param._risk_object_type = system +action.risk.param._risk_score = 20 +action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -439,6 +576,84 @@ realtime_schedule = 0 is_visible = false search = `cloudtrail` eventName=UpdateSAMLProvider | stats count min(_time) as firstTime max(_time) as lastTime by eventType eventName requestParameters.sAMLProviderArn userIdentity.sessionContext.sessionIssuer.arn sourceIPAddress userIdentity.accessKeyId userIdentity.principalId | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` |`aws_saml_update_identity_provider_filter` +[ESCU - AWS SetDefaultPolicyVersion - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = This search looks for CloudTrail events where a user has set a default policy versions. Attackers have been know to use this technique for Privilege Escalation in case the previous versions of the policy had permissions to access more resources than the current version of the policy +action.escu.mappings = {"cis20": ["CIS 13"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1078.004"], "nist": ["PR.DS", "PR.AC", "DE.CM"]} +action.escu.data_models = [] +action.escu.eli5 = This search looks for CloudTrail events where a user has set a default policy versions. Attackers have been know to use this technique for Privilege Escalation in case the previous versions of the policy had permissions to access more resources than the current version of the policy +action.escu.how_to_implement = You must install splunk AWS add on and Splunk App for AWS. This search works with cloudtrail logs. +action.escu.known_false_positives = While this search has no known false positives, it is possible that an AWS admin has legitimately set a default policy to allow a user to access all resources. That said, AWS strongly advises against granting full control to all AWS resources +action.escu.creation_date = 2021-03-02 +action.escu.modification_date = 2021-03-02 +action.escu.confidence = high +action.escu.full_search_name = ESCU - AWS SetDefaultPolicyVersion - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = [] +action.escu.analytic_story = ["AWS IAM Privilege Escalation"] +action.risk = 1 +action.risk.param._risk_object = src +action.risk.param._risk_object_type = system +action.risk.param._risk_score = 20 +action.risk.param.verbose = 0 +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - AWS SetDefaultPolicyVersion - Rule +action.correlationsearch.annotations = {"analytic_story": ["AWS IAM Privilege Escalation"], "cis20": ["CIS 13"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1078.004"], "nist": ["PR.DS", "PR.AC", "DE.CM"]} +schedule_window = auto +alert.digest_mode = 1 +disabled = true +enableSched = 1 +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = `cloudtrail` eventName=SetDefaultPolicyVersion eventSource = iam.amazonaws.com | stats count min(_time) as firstTime max(_time) as lastTime values(requestParameters.policyArn) as policy_arn by src requestParameters.versionId eventName eventSource aws_account_id errorCode userAgent eventID awsRegion userIdentity.principalId user_arn | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `aws_setdefaultpolicyversion_filter` + +[ESCU - AWS UpdateLoginProfile - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = This search looks for CloudTrail events where a user A who has already permission to update login profile, makes an API call to update login profile for another user B . Attackers have been know to use this technique for Privilege Escalation in case new victim(user B) has more permissions than old victim(user B) +action.escu.mappings = {"cis20": ["CIS 13"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1136.003"], "nist": ["PR.DS", "PR.AC", "DE.CM"]} +action.escu.data_models = [] +action.escu.eli5 = This search looks for CloudTrail events where a user A who has already permission to update login profile, makes an API call to update login profile for another user B . Attackers have been know to use this technique for Privilege Escalation in case new victim(user B) has more permissions than old victim(user B) +action.escu.how_to_implement = You must install splunk AWS add on and Splunk App for AWS. This search works with cloudtrail logs. +action.escu.known_false_positives = While this search has no known false positives, it is possible that an AWS admin has legitimately created keys for another user. +action.escu.creation_date = 2021-03-02 +action.escu.modification_date = 2021-03-02 +action.escu.confidence = high +action.escu.full_search_name = ESCU - AWS UpdateLoginProfile - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = [] +action.escu.analytic_story = ["AWS IAM Privilege Escalation"] +action.risk = 1 +action.risk.param._risk_object = src +action.risk.param._risk_object_type = system +action.risk.param._risk_score = 20 +action.risk.param.verbose = 0 +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - AWS UpdateLoginProfile - Rule +action.correlationsearch.annotations = {"analytic_story": ["AWS IAM Privilege Escalation"], "cis20": ["CIS 13"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1136.003"], "nist": ["PR.DS", "PR.AC", "DE.CM"]} +schedule_window = auto +alert.digest_mode = 1 +disabled = true +enableSched = 1 +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = `cloudtrail` eventName = UpdateLoginProfile userAgent !=console.amazonaws.com errorCode = success| search userName!=requestParameters.userName | stats count min(_time) as firstTime max(_time) as lastTime by requestParameters.userName src eventName eventSource aws_account_id errorCode userAgent eventID awsRegion userName user_arn | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`|`aws_updateloginprofile_filter` + [ESCU - Abnormally High AWS Instances Launched by User - Rule] action.escu = 0 action.escu.enabled = 1 @@ -920,10 +1135,10 @@ search = | tstats `security_content_summariesonly` count min(_time) as firstTime [ESCU - Attempt To Add Certificate To Untrusted Store - Rule] action.escu = 0 action.escu.enabled = 1 -description = Attempt to add a certificate to the certificate store +description = Attempt To Add Certificate To Untrusted Store action.escu.mappings = {"cis20": ["CIS 3", "CIS 5", "CIS 8"], "kill_chain_phases": ["Installation", "Actions on Objectives"], "mitre_attack": ["T1553.004"], "nist": ["PR.PT", "DE.CM", "PR.IP"]} action.escu.data_models = ["Endpoint"] -action.escu.eli5 = Attempt to add a certificate to the certificate store +action.escu.eli5 = Attempt To Add Certificate To Untrusted Store action.escu.how_to_implement = You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. action.escu.known_false_positives = There may be legitimate reasons for administrators to add a certificate to the untrusted certificate store. In such cases, this will typically be done on a large number of systems. action.escu.creation_date = 2020-11-03 @@ -1121,6 +1336,108 @@ realtime_schedule = 0 is_visible = false search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime values(Filesystem.dest) as dest values(Filesystem.file_name) as file_name values(Filesystem.user) as user from datamodel=Endpoint.Filesystem by Filesystem.file_path | `drop_dm_object_name(Filesystem)` | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)`| rex field=file_name "(?\.[^\.]+)$" | search file_path=*system32* AND file_extension=.bat | `batch_file_write_to_system32_filter` +[ESCU - CertUtil Download With URLCache and Split Arguments - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = Certutil.exe may download a file from a remote destination using `-urlcache`. This behavior does require a URL to be passed on the command-line. In addition, `-f` (force) and `-split` (Split embedded ASN.1 elements, and save to files) will be used. It is not entirely common for `certutil.exe` to contact public IP space. However, it is uncommon for `certutil.exe` to write files to world writeable paths.\ During triage, capture any files on disk and review. Review the reputation of the remote IP or domain in question. +action.escu.mappings = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1105"]} +action.escu.data_models = ["Endpoint"] +action.escu.eli5 = Certutil.exe may download a file from a remote destination using `-urlcache`. This behavior does require a URL to be passed on the command-line. In addition, `-f` (force) and `-split` (Split embedded ASN.1 elements, and save to files) will be used. It is not entirely common for `certutil.exe` to contact public IP space. However, it is uncommon for `certutil.exe` to write files to world writeable paths.\ During triage, capture any files on disk and review. Review the reputation of the remote IP or domain in question. +action.escu.how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. +action.escu.known_false_positives = Limited false positives in most environments, however tune as needed based on parent-child relationship or network connection. +action.escu.creation_date = 2021-03-23 +action.escu.modification_date = 2021-03-23 +action.escu.confidence = high +action.escu.full_search_name = ESCU - CertUtil Download With URLCache and Split Arguments - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = [] +action.escu.analytic_story = ["Ingress Tool Transfer"] +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - CertUtil Download With URLCache and Split Arguments - Rule +action.correlationsearch.annotations = {"analytic_story": ["Ingress Tool Transfer"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1105"]} +schedule_window = auto +alert.digest_mode = 1 +disabled = true +enableSched = 1 +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=certutil.exe Processes.process=*urlcache* Processes.process=*split* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `certutil_download_with_urlcache_and_split_arguments_filter` + +[ESCU - CertUtil Download With VerifyCtl and Split Arguments - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = Certutil.exe may download a file from a remote destination using `-VerifyCtl`. This behavior does require a URL to be passed on the command-line. In addition, `-f` (force) and `-split` (Split embedded ASN.1 elements, and save to files) will be used. It is not entirely common for `certutil.exe` to contact public IP space. \ During triage, capture any files on disk and review. Review the reputation of the remote IP or domain in question. Using `-VerifyCtl`, the file will either be written to the current working directory or `%APPDATA%\..\LocalLow\Microsoft\CryptnetUrlCache\Content\`. +action.escu.mappings = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1105"]} +action.escu.data_models = ["Endpoint"] +action.escu.eli5 = Certutil.exe may download a file from a remote destination using `-VerifyCtl`. This behavior does require a URL to be passed on the command-line. In addition, `-f` (force) and `-split` (Split embedded ASN.1 elements, and save to files) will be used. It is not entirely common for `certutil.exe` to contact public IP space. \ During triage, capture any files on disk and review. Review the reputation of the remote IP or domain in question. Using `-VerifyCtl`, the file will either be written to the current working directory or `%APPDATA%\..\LocalLow\Microsoft\CryptnetUrlCache\Content\`. +action.escu.how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. +action.escu.known_false_positives = Limited false positives in most environments, however tune as needed based on parent-child relationship or network connection. +action.escu.creation_date = 2021-03-23 +action.escu.modification_date = 2021-03-23 +action.escu.confidence = high +action.escu.full_search_name = ESCU - CertUtil Download With VerifyCtl and Split Arguments - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = [] +action.escu.analytic_story = ["Ingress Tool Transfer"] +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - CertUtil Download With VerifyCtl and Split Arguments - Rule +action.correlationsearch.annotations = {"analytic_story": ["Ingress Tool Transfer"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1105"]} +schedule_window = auto +alert.digest_mode = 1 +disabled = true +enableSched = 1 +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=certutil.exe Processes.process=*verifyctl* Processes.process=*split* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `certutil_download_with_verifyctl_and_split_arguments_filter` + +[ESCU - CertUtil With Decode Argument - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = CertUtil.exe may be used to `encode` and `decode` a file, including PE and script code. Encoding will convert a file to base64 with `-----BEGIN CERTIFICATE-----` and `-----END CERTIFICATE-----` tags. Malicious usage will include decoding a encoded file that was downloaded. Once decoded, it will be loaded by a parallel process. Note that there are two additional command switches that may be used - `encodehex` and `decodehex`. Similarly, the file will be encoded in HEX and later decoded for further execution. During triage, identify the source of the file being decoded. Review its contents or execution behavior for further analysis. +action.escu.mappings = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1140"]} +action.escu.data_models = ["Endpoint"] +action.escu.eli5 = CertUtil.exe may be used to `encode` and `decode` a file, including PE and script code. Encoding will convert a file to base64 with `-----BEGIN CERTIFICATE-----` and `-----END CERTIFICATE-----` tags. Malicious usage will include decoding a encoded file that was downloaded. Once decoded, it will be loaded by a parallel process. Note that there are two additional command switches that may be used - `encodehex` and `decodehex`. Similarly, the file will be encoded in HEX and later decoded for further execution. During triage, identify the source of the file being decoded. Review its contents or execution behavior for further analysis. +action.escu.how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. +action.escu.known_false_positives = Typically seen used to `encode` files, but it is possible to see legitimate use of `decode`. Filter based on parent-child relationship, file paths, endpoint or user. +action.escu.creation_date = 2021-03-23 +action.escu.modification_date = 2021-03-23 +action.escu.confidence = high +action.escu.full_search_name = ESCU - CertUtil With Decode Argument - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = [] +action.escu.analytic_story = ["Deobfuscate-Decode Files or Information"] +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - CertUtil With Decode Argument - Rule +action.correlationsearch.annotations = {"analytic_story": ["Deobfuscate-Decode Files or Information"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1140"]} +schedule_window = auto +alert.digest_mode = 1 +disabled = true +enableSched = 1 +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=certutil.exe Processes.process=*decode* by Processes.dest Processes.user Processes.parent_process Processes.process_name Processes.process Processes.process_id Processes.parent_process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `certutil_with_decode_argument_filter` + [ESCU - Certutil exe certificate extraction - Rule] action.escu = 0 action.escu.enabled = 1 @@ -1225,6 +1542,74 @@ realtime_schedule = 0 is_visible = false search = | tstats `security_content_summariesonly` count, values(DNS.dest) AS dest dc(DNS.dest) as dest_count from datamodel=Network_Resolution where DNS.message_type=QUERY by DNS.src | `drop_dm_object_name("Network_Resolution")` |where dest_count > 5 | `clients_connecting_to_multiple_dns_servers_filter` +[ESCU - Clop Common Exec Parameter - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = The following analytics are designed to identifies some CLOP ransomware variant that using arguments to execute its main code or feature of its code. In this variant if the parameter is "runrun", CLOP ransomware will try to encrypt files in network shares and if it is "temp.dat", it will try to read from some stream pipe or file start encrypting files within the infected local machines. This technique can be also identified as an anti-sandbox technique to make its code non-responsive since it is waiting for some parameter to execute properly. +action.escu.mappings = {"kill_chain_phases": ["Obfuscation"], "mitre_attack": ["T1204"]} +action.escu.data_models = ["Endpoint"] +action.escu.eli5 = The following analytics are designed to identifies some CLOP ransomware variant that using arguments to execute its main code or feature of its code. In this variant if the parameter is "runrun", CLOP ransomware will try to encrypt files in network shares and if it is "temp.dat", it will try to read from some stream pipe or file start encrypting files within the infected local machines. This technique can be also identified as an anti-sandbox technique to make its code non-responsive since it is waiting for some parameter to execute properly. +action.escu.how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. +action.escu.known_false_positives = Operators can execute third party tools using these parameters. +action.escu.creation_date = 2021-03-17 +action.escu.modification_date = 2021-03-17 +action.escu.confidence = high +action.escu.full_search_name = ESCU - Clop Common Exec Parameter - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = [] +action.escu.analytic_story = ["Clop Ransomware"] +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - Clop Common Exec Parameter - Rule +action.correlationsearch.annotations = {"analytic_story": ["Clop Ransomware"], "kill_chain_phases": ["Obfuscation"], "mitre_attack": ["T1204"]} +schedule_window = auto +alert.digest_mode = 1 +disabled = true +enableSched = 1 +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = | tstats `security_content_summariesonly` values(Processes.process) as cmdline values(Processes.parent_process_name) as parent_process values(Processes.process_name) count min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process = "*runrun*" OR Processes.process = "*temp.dat*" by Processes.parent_process_name Processes.process_name Processes.process Processes.dest Processes.user Processes.process_id Processes.process_guid | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `clop_common_exec_parameter_filter` + +[ESCU - Clop Ransomware Known Service Name - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = This detection is to identify the common service name created by the CLOP ransomware as part of its persistence and high privilege code execution in the infected machine. Ussually CLOP ransomware use StartServiceCtrlDispatcherW API in creating this service entry. +action.escu.mappings = {"kill_chain_phases": ["Privilege Escalation"], "mitre_attack": ["T1543"]} +action.escu.data_models = [] +action.escu.eli5 = This detection is to identify the common service name created by the CLOP ransomware as part of its persistence and high privilege code execution in the infected machine. Ussually CLOP ransomware use StartServiceCtrlDispatcherW API in creating this service entry. +action.escu.how_to_implement = To successfully implement this search, you need to be ingesting logs with the Service name, Service File Name Service Start type, and Service Type from your endpoints. +action.escu.known_false_positives = unknown +action.escu.creation_date = 2021-03-17 +action.escu.modification_date = 2021-03-17 +action.escu.confidence = high +action.escu.full_search_name = ESCU - Clop Ransomware Known Service Name - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = [] +action.escu.analytic_story = ["Clop Ransomware"] +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - Clop Ransomware Known Service Name - Rule +action.correlationsearch.annotations = {"analytic_story": ["Clop Ransomware"], "kill_chain_phases": ["Privilege Escalation"], "mitre_attack": ["T1543"]} +schedule_window = auto +alert.digest_mode = 1 +disabled = true +enableSched = 1 +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = `wineventlog_system` EventCode=7045 Service_Name IN ("SecurityCenterIBM", "WinCheckDRVs") | stats count min(_time) as firstTime max(_time) as lastTime by EventCode Service_File_Name Service_Name Service_Start_Type Service_Type | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `clop_ransomware_known_service_name_filter` + [ESCU - Cloud API Calls From Previously Unseen User Roles - Rule] action.escu = 0 action.escu.enabled = 1 @@ -1709,13 +2094,13 @@ action.escu.full_search_name = ESCU - Common Ransomware Extensions - Rule action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = [] -action.escu.analytic_story = ["SamSam Ransomware", "Ryuk Ransomware", "Ransomware"] +action.escu.analytic_story = ["SamSam Ransomware", "Ryuk Ransomware", "Ransomware", "Clop Ransomware"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Common Ransomware Extensions - Rule -action.correlationsearch.annotations = {"analytic_story": ["SamSam Ransomware", "Ryuk Ransomware", "Ransomware"], "cis20": ["CIS 8"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1485"], "nist": ["PR.PT", "DE.CM"]} +action.correlationsearch.annotations = {"analytic_story": ["SamSam Ransomware", "Ryuk Ransomware", "Ransomware", "Clop Ransomware"], "cis20": ["CIS 8"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1485"], "nist": ["PR.PT", "DE.CM"]} schedule_window = auto alert.digest_mode = 1 disabled = true @@ -1743,13 +2128,13 @@ action.escu.full_search_name = ESCU - Common Ransomware Notes - Rule action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = [] -action.escu.analytic_story = ["SamSam Ransomware", "Ransomware", "Ryuk Ransomware"] +action.escu.analytic_story = ["SamSam Ransomware", "Ransomware", "Ryuk Ransomware", "Clop Ransomware"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Common Ransomware Notes - Rule -action.correlationsearch.annotations = {"analytic_story": ["SamSam Ransomware", "Ransomware", "Ryuk Ransomware"], "cis20": ["CIS 8"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1485"], "nist": ["PR.PT", "DE.CM"]} +action.correlationsearch.annotations = {"analytic_story": ["SamSam Ransomware", "Ransomware", "Ryuk Ransomware", "Clop Ransomware"], "cis20": ["CIS 8"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1485"], "nist": ["PR.PT", "DE.CM"]} schedule_window = auto alert.digest_mode = 1 disabled = true @@ -1795,6 +2180,40 @@ realtime_schedule = 0 is_visible = false search = `sysmon` EventID=8 TargetImage=*lsass.exe | stats count min(_time) as firstTime max(_time) as lastTime by Computer, EventCode, TargetImage, TargetProcessId | rename Computer as dest | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `create_remote_thread_into_lsass_filter` +[ESCU - Create Service In Suspicious File Path - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = This detection is to identify a creation of "user mode service" where the service file path is located in non-common service folder in windows. +action.escu.mappings = {"kill_chain_phases": ["Privilege Escalation"], "mitre_attack": ["T1569.001, T1569.002"]} +action.escu.data_models = [] +action.escu.eli5 = This detection is to identify a creation of "user mode service" where the service file path is located in non-common service folder in windows. +action.escu.how_to_implement = To successfully implement this search, you need to be ingesting logs with the Service name, Service File Name Service Start type, and Service Type from your endpoints. +action.escu.known_false_positives = unknown +action.escu.creation_date = 2021-03-12 +action.escu.modification_date = 2021-03-12 +action.escu.confidence = high +action.escu.full_search_name = ESCU - Create Service In Suspicious File Path - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = [] +action.escu.analytic_story = ["Clop Ransomware"] +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - Create Service In Suspicious File Path - Rule +action.correlationsearch.annotations = {"analytic_story": ["Clop Ransomware"], "kill_chain_phases": ["Privilege Escalation"], "mitre_attack": ["T1569.001, T1569.002"]} +schedule_window = auto +alert.digest_mode = 1 +disabled = true +enableSched = 1 +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = `wineventlog_system` EventCode=7045 Service_File_Name = "*\.exe" NOT (Service_File_Name IN ("C:\\Windows\\*", "C:\\Program File*", "C:\\Programdata\\*", "%systemroot%\\*")) Service_Type = "user mode service" | stats count min(_time) as firstTime max(_time) as lastTime by EventCode Service_File_Name Service_Name Service_Start_Type Service_Type | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `create_service_in_suspicious_file_path_filter` + [ESCU - Create local admin accounts using net exe - Rule] action.escu = 0 action.escu.enabled = 1 @@ -2195,13 +2614,13 @@ action.escu.full_search_name = ESCU - Deleting Shadow Copies - Rule action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = [] -action.escu.analytic_story = ["Windows Log Manipulation", "SamSam Ransomware", "Ransomware"] +action.escu.analytic_story = ["Windows Log Manipulation", "SamSam Ransomware", "Ransomware", "Clop Ransomware"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Deleting Shadow Copies - Rule -action.correlationsearch.annotations = {"analytic_story": ["Windows Log Manipulation", "SamSam Ransomware", "Ransomware"], "cis20": ["CIS 8", "CIS 10"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1490"], "nist": ["PR.PT", "DE.CM", "PR.IP"]} +action.correlationsearch.annotations = {"analytic_story": ["Windows Log Manipulation", "SamSam Ransomware", "Ransomware", "Clop Ransomware"], "cis20": ["CIS 8", "CIS 10"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1490"], "nist": ["PR.PT", "DE.CM", "PR.IP"]} schedule_window = auto alert.digest_mode = 1 disabled = true @@ -2816,10 +3235,10 @@ search = | tstats `security_content_summariesonly` count min(_time) as firstTime [ESCU - Detect Exchange Web Shell - Rule] action.escu = 0 action.escu.enabled = 1 -description = The following query identifies suspicious .aspx created in 3 paths identified by Microsoft as known drop locations for Exchange exploitation related to HAFNIUM group. Paths include: `\HttpProxy\owa\auth\`, `\inetpub\wwwroot\aspnet_client\`, and `\HttpProxy\OAB\`. Upon triage, the suspicious .aspx file will have a randomized name of 8 characters long. Review the file for suspect commands. Identify additional log sources, IIS included, to review source and other potential exploitation. +description = The following query identifies suspicious .aspx created in 3 paths identified by Microsoft as known drop locations for Exchange exploitation related to HAFNIUM group. Paths include: `\HttpProxy\owa\auth\`, `\inetpub\wwwroot\aspnet_client\`, and `\HttpProxy\OAB\`. Upon triage, the suspicious .aspx file will likely look obvious on the surface. inspect the contents for script code inside. Identify additional log sources, IIS included, to review source and other potential exploitation. action.escu.mappings = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1505.003"]} action.escu.data_models = [] -action.escu.eli5 = The following query identifies suspicious .aspx created in 3 paths identified by Microsoft as known drop locations for Exchange exploitation related to HAFNIUM group. Paths include: `\HttpProxy\owa\auth\`, `\inetpub\wwwroot\aspnet_client\`, and `\HttpProxy\OAB\`. Upon triage, the suspicious .aspx file will have a randomized name of 8 characters long. Review the file for suspect commands. Identify additional log sources, IIS included, to review source and other potential exploitation. +action.escu.eli5 = The following query identifies suspicious .aspx created in 3 paths identified by Microsoft as known drop locations for Exchange exploitation related to HAFNIUM group. Paths include: `\HttpProxy\owa\auth\`, `\inetpub\wwwroot\aspnet_client\`, and `\HttpProxy\OAB\`. Upon triage, the suspicious .aspx file will likely look obvious on the surface. inspect the contents for script code inside. Identify additional log sources, IIS included, to review source and other potential exploitation. action.escu.how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node and `Filesystem` node. action.escu.known_false_positives = The query is structured in a way that `action` (read, create) is not defined. Review the results of this query, filter, and tune as necessary. It may be necessary to generate this query specific to your endpoint product. action.escu.creation_date = 2021-03-09 @@ -2845,7 +3264,7 @@ relation = greater than quantity = 0 realtime_schedule = 0 is_visible = false -search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*\\HttpProxy\\owa\\auth\\*", "*\\inetpub\\wwwroot\\aspnet_client\\*", "*\\HttpProxy\\OAB\\*") Filesystem.file_name="*.aspx" by _time span=1h Filesystem.process_id Filesystem.file_name Filesystem.file_path Filesystem.file_hash Filesystem.user | `drop_dm_object_name(Filesystem)` | rename process_id as aspx_pid | join aspx_pid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=w3wp.exe by _time span=1h Processes.parent_process_id Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process | `drop_dm_object_name(Processes)` | rename parent_process_id as aspx_pid | fields _time aspx_pid process_id dest process_name process_path process] | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | table firstTime, lastTime, aspx_pid, process_id, user, dest, file_name, file_path, process_name, process, process_path, file_hash | `detect_exchange_web_shell_filter` +search = | tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=System by _time span=1h Processes.process_id Processes.process_name Processes.dest | `drop_dm_object_name(Processes)` | join process_guid, _time [| tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_path IN ("*\\HttpProxy\\owa\\auth\\*", "*\\inetpub\\wwwroot\\aspnet_client\\*", "*\\HttpProxy\\OAB\\*") Filesystem.file_name="*.aspx" by _time span=1h Filesystem.dest Filesystem.file_create_time Filesystem.file_name Filesystem.file_path | `drop_dm_object_name(Filesystem)` | fields _time dest file_create_time file_name file_path process_name process_path process] | dedup file_create_time | table dest file_create_time, file_name, file_path, process_name | `detect_exchange_web_shell_filter` [ESCU - Detect F5 TMUI RCE CVE-2020-5902 - Rule] action.escu = 0 @@ -3371,7 +3790,7 @@ action.escu.modification_date = 2021-01-12 action.escu.confidence = high action.escu.full_search_name = ESCU - Detect New Open S3 Buckets over AWS CLI - Rule action.escu.search_type = detection -action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = [] action.escu.analytic_story = ["Suspicious AWS S3 Activities"] action.risk = 1 @@ -3410,7 +3829,7 @@ action.escu.modification_date = 2021-01-12 action.escu.confidence = high action.escu.full_search_name = ESCU - Detect New Open S3 buckets - Rule action.escu.search_type = detection -action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = [] action.escu.analytic_story = ["Suspicious AWS S3 Activities"] action.risk = 1 @@ -4255,9 +4674,14 @@ action.escu.modification_date = 2021-01-26 action.escu.confidence = high action.escu.full_search_name = ESCU - Detect Spike in AWS Security Hub Alerts for EC2 Instance - Rule action.escu.search_type = detection -action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = [] action.escu.analytic_story = ["AWS Security Hub Alerts"] +action.risk = 1 +action.risk.param._risk_object = dest +action.risk.param._risk_object_type = system +action.risk.param._risk_score = 20 +action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -6100,6 +6524,40 @@ realtime_schedule = 0 is_visible = false search = | tstats `security_content_summariesonly` count min(_time) values(Processes.process) as process max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=attrib.exe (Processes.process=*+h*) by Processes.parent_process Processes.process_name Processes.user Processes.dest | `drop_dm_object_name("Processes")` | `security_content_ctime(firstTime)`|`security_content_ctime(lastTime)`| `hiding_files_and_directories_with_attrib_exe_filter` +[ESCU - High File Deletion Frequency - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = This search looks for high frequency of file deletion relative to process name and process id. These events usually happen when the ransomware tries to encrypt the files with the ransomware file extensions and sysmon treat the original files to be deleted as soon it was replace as encrypted data. +action.escu.mappings = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1485"]} +action.escu.data_models = [] +action.escu.eli5 = This search looks for high frequency of file deletion relative to process name and process id. These events usually happen when the ransomware tries to encrypt the files with the ransomware file extensions and sysmon treat the original files to be deleted as soon it was replace as encrypted data. +action.escu.how_to_implement = To successfully implement this search, you need to be ingesting logs with the deleted target file name, process name and process id from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. +action.escu.known_false_positives = user may delete bunch of pictures or files in a folder. +action.escu.creation_date = 2021-03-16 +action.escu.modification_date = 2021-03-16 +action.escu.confidence = high +action.escu.full_search_name = ESCU - High File Deletion Frequency - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = [] +action.escu.analytic_story = ["Clop Ransomware"] +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - High File Deletion Frequency - Rule +action.correlationsearch.annotations = {"analytic_story": ["Clop Ransomware"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1485"]} +schedule_window = auto +alert.digest_mode = 1 +disabled = true +enableSched = 1 +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = `sysmon` EventCode=23 TargetFilename IN ("*\.cmd", "*\.ini","*\.gif", "*\.jpg", "*\.jpeg", "*\.db", "*\.ps1", "*\.doc*", "*\.xls*", "*\.ppt*", "*\.bmp","*\.zip", "*\.rar", "*\.7z", "*\.chm", "*\.png", "*\.log", "*\.vbs", "*\.js") | stats values(TargetFilename) as deleted_files min(_time) as firstTime max(_time) as lastTime count by Computer user EventCode Image ProcessID |where count >=100 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `high_file_deletion_frequency_filter` + [ESCU - High Number of Login Failures from a single source - Rule] action.escu = 0 action.escu.enabled = 1 @@ -6134,6 +6592,40 @@ realtime_schedule = 0 is_visible = false search = `o365_management_activity` Operation=UserLoginFailed record_type=AzureActiveDirectoryStsLogon app=AzureActiveDirectory | stats count dc(user) as accounts_locked values(user) as user values(LogonError) as LogonError values(authentication_method) as authentication_method values(signature) as signature values(UserAgent) as UserAgent by src_ip record_type Operation app | search accounts_locked >= 5| `high_number_of_login_failures_from_a_single_source_filter` +[ESCU - High Process Termination Frequency - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = This analytics are designed to indentify a high frequency of process termination on a machine which is a common behavior of ransomware malware before encrypting files. This technique is designed to avoid an exception error while accessing (docs, images, database and etc..) in the infected machine for encryption. +action.escu.mappings = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1486"]} +action.escu.data_models = [] +action.escu.eli5 = This analytics are designed to indentify a high frequency of process termination on a machine which is a common behavior of ransomware malware before encrypting files. This technique is designed to avoid an exception error while accessing (docs, images, database and etc..) in the infected machine for encryption. +action.escu.how_to_implement = To successfully implement this search, you need to be ingesting logs with the Image (process full path of terminated process) from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. +action.escu.known_false_positives = admin or user tool that can terminate multiple process. +action.escu.creation_date = 2021-03-16 +action.escu.modification_date = 2021-03-16 +action.escu.confidence = high +action.escu.full_search_name = ESCU - High Process Termination Frequency - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = [] +action.escu.analytic_story = ["Clop Ransomware"] +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - High Process Termination Frequency - Rule +action.correlationsearch.annotations = {"analytic_story": ["Clop Ransomware"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1486"]} +schedule_window = auto +alert.digest_mode = 1 +disabled = true +enableSched = 1 +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = `sysmon` EventCode=5 |bin _time span=3s |stats values(Image) as proc_terminated min(_time) as firstTime max(_time) as lastTime count by Computer EventCode ProcessID | where count >= 15 | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `high_process_termination_frequency_filter` + [ESCU - Hosts receiving high volume of network traffic from email server - Rule] action.escu = 0 action.escu.enabled = 1 @@ -7478,9 +7970,14 @@ action.escu.modification_date = 2021-01-26 action.escu.confidence = high action.escu.full_search_name = ESCU - O365 Add App Role Assignment Grant User - Rule action.escu.search_type = detection -action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = [] action.escu.analytic_story = ["Office 365 Detections", "Cloud Federated Credential Abuse"] +action.risk = 1 +action.risk.param._risk_object = dest +action.risk.param._risk_object_type = system +action.risk.param._risk_score = 20 +action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -7512,9 +8009,14 @@ action.escu.modification_date = 2021-01-26 action.escu.confidence = high action.escu.full_search_name = ESCU - O365 Added Service Principal - Rule action.escu.search_type = detection -action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = [] action.escu.analytic_story = ["Office 365 Detections", "Cloud Federated Credential Abuse"] +action.risk = 1 +action.risk.param._risk_object = ActorIpAddress +action.risk.param._risk_object_type = system +action.risk.param._risk_score = 20 +action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -7546,9 +8048,14 @@ action.escu.modification_date = 2021-01-12 action.escu.confidence = high action.escu.full_search_name = ESCU - O365 Bypass MFA via Trusted IP - Rule action.escu.search_type = detection -action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = [] action.escu.analytic_story = ["Office 365 Detections"] +action.risk = 1 +action.risk.param._risk_object = user +action.risk.param._risk_object_type = user +action.risk.param._risk_score = 20 +action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -7580,9 +8087,14 @@ action.escu.modification_date = 2020-12-16 action.escu.confidence = high action.escu.full_search_name = ESCU - O365 Disable MFA - Rule action.escu.search_type = detection -action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = [] action.escu.analytic_story = ["Office 365 Detections"] +action.risk = 1 +action.risk.param._risk_object = dest +action.risk.param._risk_object_type = system +action.risk.param._risk_score = 20 +action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -7614,9 +8126,14 @@ action.escu.modification_date = 2020-12-16 action.escu.confidence = high action.escu.full_search_name = ESCU - O365 Excessive Authentication Failures Alert - Rule action.escu.search_type = detection -action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = [] action.escu.analytic_story = ["Office 365 Detections"] +action.risk = 1 +action.risk.param._risk_object = user +action.risk.param._risk_object_type = user +action.risk.param._risk_score = 20 +action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -7648,9 +8165,14 @@ action.escu.modification_date = 2021-01-26 action.escu.confidence = high action.escu.full_search_name = ESCU - O365 Excessive SSO logon errors - Rule action.escu.search_type = detection -action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = [] action.escu.analytic_story = ["Office 365 Detections", "Cloud Federated Credential Abuse"] +action.risk = 1 +action.risk.param._risk_object = user +action.risk.param._risk_object_type = user +action.risk.param._risk_score = 20 +action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -7682,9 +8204,14 @@ action.escu.modification_date = 2021-01-26 action.escu.confidence = high action.escu.full_search_name = ESCU - O365 New Federated Domain Added - Rule action.escu.search_type = detection -action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = [] action.escu.analytic_story = ["Office 365 Detections", "Cloud Federated Credential Abuse"] +action.risk = 1 +action.risk.param._risk_object = UserId +action.risk.param._risk_object_type = user +action.risk.param._risk_score = 20 +action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -7716,9 +8243,14 @@ action.escu.modification_date = 2020-12-16 action.escu.confidence = high action.escu.full_search_name = ESCU - O365 PST export alert - Rule action.escu.search_type = detection -action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = [] action.escu.analytic_story = ["Office 365 Detections"] +action.risk = 1 +action.risk.param._risk_object = Source +action.risk.param._risk_object_type = system +action.risk.param._risk_score = 20 +action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -7743,16 +8275,21 @@ description = This search detects when an admin configured a forwarding rule for action.escu.mappings = {"cis20": ["CIS 16"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1114.003"], "nist": ["DE.DP", "DE.AE"]} action.escu.data_models = [] action.escu.eli5 = This search detects when an admin configured a forwarding rule for multiple mailboxes to the same destination. -action.escu.how_to_implement = +action.escu.how_to_implement = You must install splunk Microsoft Office 365 add-on. This search works with o365:management:activity action.escu.known_false_positives = unknown action.escu.creation_date = 2020-12-16 action.escu.modification_date = 2020-12-16 action.escu.confidence = high action.escu.full_search_name = ESCU - O365 Suspicious Admin Email Forwarding - Rule action.escu.search_type = detection -action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = [] action.escu.analytic_story = ["Office 365 Detections"] +action.risk = 1 +action.risk.param._risk_object = src_user +action.risk.param._risk_object_type = system +action.risk.param._risk_score = 20 +action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -7777,16 +8314,21 @@ description = This search detects the assignment of rights to accesss content fr action.escu.mappings = {"cis20": ["CIS 16"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1114.002"], "nist": ["DE.DP", "DE.AE"]} action.escu.data_models = [] action.escu.eli5 = This search detects the assignment of rights to accesss content from another mailbox. This is usually only assigned to a service account. -action.escu.how_to_implement = +action.escu.how_to_implement = You must install splunk Microsoft Office 365 add-on. This search works with o365:management:activity action.escu.known_false_positives = Service Accounts action.escu.creation_date = 2020-12-15 action.escu.modification_date = 2020-12-15 action.escu.confidence = high action.escu.full_search_name = ESCU - O365 Suspicious Rights Delegation - Rule action.escu.search_type = detection -action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = [] action.escu.analytic_story = ["Office 365 Detections"] +action.risk = 1 +action.risk.param._risk_object = user +action.risk.param._risk_object_type = user +action.risk.param._risk_score = 20 +action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -7811,16 +8353,21 @@ description = This search detects when multiple user configured a forwarding rul action.escu.mappings = {"cis20": ["CIS 16"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1114.003"], "nist": ["DE.DP", "DE.AE"]} action.escu.data_models = [] action.escu.eli5 = This search detects when multiple user configured a forwarding rule to the same destination. -action.escu.how_to_implement = +action.escu.how_to_implement = You must install splunk Microsoft Office 365 add-on. This search works with o365:management:activity action.escu.known_false_positives = unknown action.escu.creation_date = 2020-12-16 action.escu.modification_date = 2020-12-16 action.escu.confidence = high action.escu.full_search_name = ESCU - O365 Suspicious User Email Forwarding - Rule action.escu.search_type = detection -action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.product = ["Splunk Security Analytics for AWS", "Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = [] action.escu.analytic_story = ["Office 365 Detections"] +action.risk = 1 +action.risk.param._risk_object = ForwardingSmtpAddress +action.risk.param._risk_object_type = system +action.risk.param._risk_score = 20 +action.risk.param.verbose = 0 cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m @@ -8076,6 +8623,40 @@ realtime_schedule = 0 is_visible = false search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Filesystem where Filesystem.file_name="*.lnk" AND Filesystem.file_path="C:\\Temp*" by _time span=1h Filesystem.process_id Filesystem.file_name Filesystem.file_path Filesystem.file_hash Filesystem.user | `drop_dm_object_name(Filesystem)` | rename process_id as lnk_pid | join lnk_pid, _time [| tstats `security_content_summariesonly` count FROM datamodel=Endpoint.Processes where Processes.process_name=* by _time span=1h Processes.parent_process_id Processes.process_id Processes.process_name Processes.dest Processes.process_path Processes.process | `drop_dm_object_name(Processes)` | rename parent_process_id as lnk_pid | fields _time lnk_pid process_id dest process_name process_path process] | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | table firstTime, lastTime, lnk_pid, process_id, user, dest, file_name, file_path, process_name, process, process_path, file_hash | `process_creating_lnk_file_in_suspicious_location_filter` +[ESCU - Process Deleting Its Process File Path - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = This detection is to identify a suspicious process that tries to delete the process file path related to its process. This technique is known to be defense evasion once a certain condition of malware is satisfied or not. Clop ransomware use this technique where it will try to delete its process file path using a .bat command if the keyboard layout is not the layout it tries to infect. +action.escu.mappings = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1003.002"]} +action.escu.data_models = [] +action.escu.eli5 = This detection is to identify a suspicious process that tries to delete the process file path related to its process. This technique is known to be defense evasion once a certain condition of malware is satisfied or not. Clop ransomware use this technique where it will try to delete its process file path using a .bat command if the keyboard layout is not the layout it tries to infect. +action.escu.how_to_implement = You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. +action.escu.known_false_positives = unknown +action.escu.creation_date = 2021-03-17 +action.escu.modification_date = 2021-03-17 +action.escu.confidence = high +action.escu.full_search_name = ESCU - Process Deleting Its Process File Path - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = [] +action.escu.analytic_story = ["Clop Ransomware"] +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - Process Deleting Its Process File Path - Rule +action.correlationsearch.annotations = {"analytic_story": ["Clop Ransomware"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1003.002"]} +schedule_window = auto +alert.digest_mode = 1 +disabled = true +enableSched = 1 +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = `sysmon` EventCode=1 cmdline = "*/c del*" Image = "*\\cmd.exe" |eval result = if(like(process,"%".parent_process."%"), "Found", "Not Found") | stats min(_time) as firstTime max(_time) as lastTime count by Computer user ParentImage ParentCommandLine Image cmdline EventCode ProcessID result | where result = "Found" | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `process_deleting_its_process_file_path_filter` + [ESCU - Process Execution via WMI - Rule] action.escu = 0 action.escu.enabled = 1 @@ -8348,6 +8929,40 @@ realtime_schedule = 0 is_visible = false search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Network_Traffic where All_Traffic.transport="tcp" AND (All_Traffic.dest_port="23" OR All_Traffic.dest_port="143" OR All_Traffic.dest_port="110" OR (All_Traffic.dest_port="21" AND All_Traffic.user != "anonymous")) by All_Traffic.user All_Traffic.src All_Traffic.dest All_Traffic.dest_port | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `drop_dm_object_name("All_Traffic")` | `protocols_passing_authentication_in_cleartext_filter` +[ESCU - Ransomware Notes bulk creation - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = The following analytics identifies a big number of instance of ransomware notes (filetype e.g .txt, .html, .hta) file creation to the infected machine. This behavior is a good sensor if the ransomware note filename is quite new for security industry or the ransomware note filename is not in your lookup table list for monitoring. +action.escu.mappings = {"kill_chain_phases": ["Obfuscation"], "mitre_attack": ["T1486"]} +action.escu.data_models = [] +action.escu.eli5 = The following analytics identifies a big number of instance of ransomware notes (filetype e.g .txt, .html, .hta) file creation to the infected machine. This behavior is a good sensor if the ransomware note filename is quite new for security industry or the ransomware note filename is not in your lookup table list for monitoring. +action.escu.how_to_implement = You must be ingesting data that records the filesystem activity from your hosts to populate the Endpoint file-system data model node. If you are using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which you want to collect data. +action.escu.known_false_positives = unknown +action.escu.creation_date = 2021-03-12 +action.escu.modification_date = 2021-03-12 +action.escu.confidence = high +action.escu.full_search_name = ESCU - Ransomware Notes bulk creation - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = [] +action.escu.analytic_story = ["Clop Ransomware"] +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - Ransomware Notes bulk creation - Rule +action.correlationsearch.annotations = {"analytic_story": ["Clop Ransomware"], "kill_chain_phases": ["Obfuscation"], "mitre_attack": ["T1486"]} +schedule_window = auto +alert.digest_mode = 1 +disabled = true +enableSched = 1 +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = `sysmon` EventCode=11 file_name IN ("*\.txt","*\.html","*\.hta") | stats min(_time) as firstTime max(_time) as lastTime dc(TargetFilename) as unique_readme_path_count values(TargetFilename) as list_of_readme_path by Computer Image file_name | where unique_readme_path_count >= 50 | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | `ransomware_notes_bulk_creation_filter` + [ESCU - Reg exe Manipulating Windows Services Registry Keys - Rule] action.escu = 0 action.escu.enabled = 1 @@ -8722,6 +9337,40 @@ realtime_schedule = 0 is_visible = false search = | tstats `security_content_summariesonly` count values(Processes.process) as process values(Processes.parent_process) as parent_process min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.process_name=wmic.exe AND Processes.process= */node* by Processes.user Processes.process_name Processes.parent_process_name Processes.dest | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)`| `security_content_ctime(lastTime)` | `remote_wmi_command_attempt_filter` +[ESCU - Resize ShadowStorage volume - Rule] +action.escu = 0 +action.escu.enabled = 1 +description = The following analytics identifies the resizing of shadowstorage by ransomware malware to avoid the shadow volumes being made again. this technique is an alternative by ransomware attacker than deleting the shadowstorage which is known alert in defensive team. one example of ransomware that use this technique is CLOP ransomware where it drops a .bat file that will resize the shadowstorage to minimum size as much as possible +action.escu.mappings = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1490"]} +action.escu.data_models = ["Endpoint"] +action.escu.eli5 = The following analytics identifies the resizing of shadowstorage by ransomware malware to avoid the shadow volumes being made again. this technique is an alternative by ransomware attacker than deleting the shadowstorage which is known alert in defensive team. one example of ransomware that use this technique is CLOP ransomware where it drops a .bat file that will resize the shadowstorage to minimum size as much as possible +action.escu.how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. +action.escu.known_false_positives = network admin can resize the shadowstorage for valid purposes. +action.escu.creation_date = 2021-03-12 +action.escu.modification_date = 2021-03-12 +action.escu.confidence = high +action.escu.full_search_name = ESCU - Resize ShadowStorage volume - Rule +action.escu.search_type = detection +action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] +action.escu.providing_technologies = [] +action.escu.analytic_story = ["Clop Ransomware"] +cron_schedule = 0 * * * * +dispatch.earliest_time = -70m@m +dispatch.latest_time = -10m@m +action.correlationsearch.enabled = 1 +action.correlationsearch.label = ESCU - Resize ShadowStorage volume - Rule +action.correlationsearch.annotations = {"analytic_story": ["Clop Ransomware"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1490"]} +schedule_window = auto +alert.digest_mode = 1 +disabled = true +enableSched = 1 +counttype = number of events +relation = greater than +quantity = 0 +realtime_schedule = 0 +is_visible = false +search = | tstats `security_content_summariesonly` values(Processes.process) as cmdline values(Processes.parent_process_name) as parent_process values(Processes.process_name) as process_name min(_time) as firstTime max(_time) as lastTime from datamodel=Endpoint.Processes where Processes.parent_process_name = "cmd.exe" OR Processes.parent_process_name = "powershell.exe" OR Processes.parent_process_name = "powershell_ise.exe" OR Processes.parent_process_name = "wmic.exe" Processes.process_name = "vssadmin.exe" Processes.process="*resize*" Processes.process="*shadowstorage*" Processes.process="*/maxsize*" by Processes.parent_process_name Processes.parent_process Processes.process_name Processes.process Processes.dest Processes.user Processes.process_id Processes.process_guid | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` |`security_content_ctime(lastTime)` | `resize_shadowstorage_volume_filter` + [ESCU - RunDLL Loading DLL By Ordinal - Rule] action.escu = 0 action.escu.enabled = 1 @@ -9523,13 +10172,13 @@ action.escu.full_search_name = ESCU - Suspicious Curl Network Connection - Rule action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = [] -action.escu.analytic_story = ["Silver Sparrow"] +action.escu.analytic_story = ["Silver Sparrow", "Ingress Tool Transfer"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Suspicious Curl Network Connection - Rule -action.correlationsearch.annotations = {"analytic_story": ["Silver Sparrow"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1105"]} +action.correlationsearch.annotations = {"analytic_story": ["Silver Sparrow", "Ingress Tool Transfer"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1105"]} schedule_window = auto alert.digest_mode = 1 disabled = true @@ -10221,7 +10870,7 @@ search = `sysmon` EventID=1 (process_name=searchprotocolhost.exe OR OriginalFile action.escu = 0 action.escu.enabled = 1 description = The following analytic identifies a renamed instance of microsoft.workflow.compiler.exe. Microsoft.workflow.compiler.exe is natively found in C:\Windows\Microsoft.NET\Framework64\v4.0.30319 and is rarely utilized. When investigating, identify the executed code on disk and review. A spawned child process from microsoft.workflow.compiler.exe is uncommon. In any instance, microsoft.workflow.compiler.exe spawning from an Office product or any living off the land binary is highly suspect. -action.escu.mappings = {"cis20": ["CIS 8"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1127, T1036.003"], "nist": ["PR.PT", "DE.CM"]} +action.escu.mappings = {"cis20": ["CIS 8"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1127", "T1036.003"], "nist": ["PR.PT", "DE.CM"]} action.escu.data_models = [] action.escu.eli5 = The following analytic identifies a renamed instance of microsoft.workflow.compiler.exe. Microsoft.workflow.compiler.exe is natively found in C:\Windows\Microsoft.NET\Framework64\v4.0.30319 and is rarely utilized. When investigating, identify the executed code on disk and review. A spawned child process from microsoft.workflow.compiler.exe is uncommon. In any instance, microsoft.workflow.compiler.exe spawning from an Office product or any living off the land binary is highly suspect. action.escu.how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. @@ -10239,7 +10888,7 @@ dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Suspicious microsoft workflow compiler rename - Rule -action.correlationsearch.annotations = {"analytic_story": ["Trusted Developer Utilities Proxy Execution", "Cobalt Strike"], "cis20": ["CIS 8"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1127, T1036.003"], "nist": ["PR.PT", "DE.CM"]} +action.correlationsearch.annotations = {"analytic_story": ["Trusted Developer Utilities Proxy Execution", "Cobalt Strike"], "cis20": ["CIS 8"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1127", "T1036.003"], "nist": ["PR.PT", "DE.CM"]} schedule_window = auto alert.digest_mode = 1 disabled = true @@ -10403,13 +11052,13 @@ action.escu.full_search_name = ESCU - Suspicious wevtutil Usage - Rule action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = [] -action.escu.analytic_story = ["Windows Log Manipulation", "Ransomware"] +action.escu.analytic_story = ["Windows Log Manipulation", "Ransomware", "Clop Ransomware"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Suspicious wevtutil Usage - Rule -action.correlationsearch.annotations = {"analytic_story": ["Windows Log Manipulation", "Ransomware"], "cis20": ["CIS 3", "CIS 5", "CIS 6"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1070.001"], "nist": ["DE.DP", "PR.IP", "PR.PT", "PR.AC", "PR.AT", "DE.AE"]} +action.correlationsearch.annotations = {"analytic_story": ["Windows Log Manipulation", "Ransomware", "Clop Ransomware"], "cis20": ["CIS 3", "CIS 5", "CIS 6"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1070.001"], "nist": ["DE.DP", "PR.IP", "PR.PT", "PR.AC", "PR.AT", "DE.AE"]} schedule_window = auto alert.digest_mode = 1 disabled = true @@ -11287,13 +11936,13 @@ action.escu.full_search_name = ESCU - Windows Event Log Cleared - Rule action.escu.search_type = detection action.escu.product = ["Splunk Enterprise", "Splunk Enterprise Security", "Splunk Cloud"] action.escu.providing_technologies = [] -action.escu.analytic_story = ["Windows Log Manipulation", "Ransomware"] +action.escu.analytic_story = ["Windows Log Manipulation", "Ransomware", "Clop Ransomware"] cron_schedule = 0 * * * * dispatch.earliest_time = -70m@m dispatch.latest_time = -10m@m action.correlationsearch.enabled = 1 action.correlationsearch.label = ESCU - Windows Event Log Cleared - Rule -action.correlationsearch.annotations = {"analytic_story": ["Windows Log Manipulation", "Ransomware"], "cis20": ["CIS 3", "CIS 5", "CIS 6"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1070.001"], "nist": ["DE.DP", "PR.IP", "PR.AC", "PR.AT", "DE.AE"]} +action.correlationsearch.annotations = {"analytic_story": ["Windows Log Manipulation", "Ransomware", "Clop Ransomware"], "cis20": ["CIS 3", "CIS 5", "CIS 6"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1070.001"], "nist": ["DE.DP", "PR.IP", "PR.AC", "PR.AT", "DE.AE"]} schedule_window = auto alert.digest_mode = 1 disabled = true @@ -12968,11 +13617,11 @@ search = | tstats `security_content_summariesonly` dc(Updates.dest) as count FRO ### ESCU RESPONSE TASKS ### -[response - AWS Investigate Security Hub alerts by dest - Response Task] +[ESCU - AWS Investigate Security Hub alerts by dest - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - AWS Investigate Security Hub alerts by dest - Response Task +action.escu.full_search_name = ESCU - AWS Investigate Security Hub alerts by dest - Response Task description = This search retrieves the all the alerts created by AWS Security Hub for a specific dest(instance_id). action.escu.creation_date = 2020-06-08 action.escu.modification_date = 2020-06-08 @@ -12989,11 +13638,11 @@ schedule_window = auto is_visible = false search = sourcetype="aws:securityhub:firehose" "findings{}.Resources{}.Type"=AWSEC2Instance | rex field=findings{}.Resources{}.Id .*instance/(?.*)| rename instance as dest| search dest = $dest$ |rename findings{}.* as * | rename Remediation.Recommendation.Text as Remediation | table dest Title ProductArn Description FirstObservedAt RecordState Remediation -[response - AWS Investigate User Activities By ARN - Response Task] +[ESCU - AWS Investigate User Activities By ARN - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - AWS Investigate User Activities By ARN - Response Task +action.escu.full_search_name = ESCU - AWS Investigate User Activities By ARN - Response Task description = This search lists all the logged CloudTrail activities by a specific user ARN and will create a table containing the source of the user, the region of the activity, the name and type of the event, the action taken, and all the user's identity information. action.escu.creation_date = 2019-04-30 action.escu.modification_date = 2019-04-30 @@ -13010,11 +13659,11 @@ schedule_window = auto is_visible = false search = | search sourcetype=aws:cloudtrail | search user=$user$| table _time userIdentity.type userIdentity.userName userIdentity.arn aws_account_id src awsRegion eventName eventType -[response - AWS Investigate User Activities By AccessKeyId - Response Task] +[ESCU - AWS Investigate User Activities By AccessKeyId - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - AWS Investigate User Activities By AccessKeyId - Response Task +action.escu.full_search_name = ESCU - AWS Investigate User Activities By AccessKeyId - Response Task description = This search retrieves the times, ARN, source IPs, AWS regions, event names, and the result of the event for specific credentials. action.escu.creation_date = 2018-06-08 action.escu.modification_date = 2018-06-08 @@ -13031,11 +13680,11 @@ schedule_window = auto is_visible = false search = | search sourcetype=aws:cloudtrail | rename userIdentity.accessKeyId as accessKeyId| search accessKeyId=$accessKeyId$ | spath output=user path=userIdentity.arn | rename sourceIPAddress as src_ip | table _time, user, src_ip, awsRegion, eventName, errorCode, errorMessage -[response - AWS Network ACL Details from ID - Response Task] +[ESCU - AWS Network ACL Details from ID - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - AWS Network ACL Details from ID - Response Task +action.escu.full_search_name = ESCU - AWS Network ACL Details from ID - Response Task description = This search queries AWS description logs and returns all the information about a specific network ACL via network ACL ID action.escu.creation_date = 2017-01-22 action.escu.modification_date = 2017-01-22 @@ -13052,11 +13701,11 @@ schedule_window = auto is_visible = false search = | search sourcetype=aws:description| rename id as networkAclId | search networkAclId=$networkAclId$ | table id account_id vpc_id network_acl_entries{}.* -[response - AWS Network Interface details via resourceId - Response Task] +[ESCU - AWS Network Interface details via resourceId - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - AWS Network Interface details via resourceId - Response Task +action.escu.full_search_name = ESCU - AWS Network Interface details via resourceId - Response Task description = This search queries AWS configuration logs and returns the information about a specific network interface via network interface ID. The information will include the ARN of the network interface, its relationships with other AWS resources, the public and the private IP associated with the network interface. action.escu.creation_date = 2018-05-07 action.escu.modification_date = 2018-05-07 @@ -13073,11 +13722,11 @@ schedule_window = auto is_visible = false search = | search sourcetype=aws:config resourceId=$resourceId$ | table _time ARN relationships{}.resourceType relationships{}.name relationships{}.resourceId configuration.privateIpAddresses{}.privateIpAddress configuration.privateIpAddresses{}.association.publicIp -[response - AWS S3 Bucket details via bucketName - Response Task] +[ESCU - AWS S3 Bucket details via bucketName - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - AWS S3 Bucket details via bucketName - Response Task +action.escu.full_search_name = ESCU - AWS S3 Bucket details via bucketName - Response Task description = This search queries AWS configuration logs and returns the information about a specific S3 bucket. The information returned includes the time the S3 bucket was created, the resource ID, the region it belongs to, the value of action performed, AWS account ID, and configuration values of the access-control lists associated with the bucket. action.escu.creation_date = 2018-06-26 action.escu.modification_date = 2018-06-26 @@ -13094,11 +13743,11 @@ schedule_window = auto is_visible = false search = | search sourcetype=aws:config | rename resourceId as bucketName |search bucketName=$bucketName$ | table resourceCreationTime bucketName vendor_region action aws_account_id supplementaryConfiguration.AccessControlList -[response - All backup logs for host - Response Task] +[ESCU - All backup logs for host - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - All backup logs for host - Response Task +action.escu.full_search_name = ESCU - All backup logs for host - Response Task description = Retrieve the backup logs for the last 2 weeks for a specific host in order to investigate why backups are not completing successfully. action.escu.creation_date = 2017-09-12 action.escu.modification_date = 2017-09-12 @@ -13115,11 +13764,11 @@ schedule_window = auto is_visible = false search = | search sourcetype="netbackup_logs" dest=$dest$ -[response - Amazon EKS Kubernetes activity by src ip - Response Task] +[ESCU - Amazon EKS Kubernetes activity by src ip - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Amazon EKS Kubernetes activity by src ip - Response Task +action.escu.full_search_name = ESCU - Amazon EKS Kubernetes activity by src ip - Response Task description = This search provides investigation data about requests via user agent, authentication request URI, verb and cluster name data against Kubernetes cluster from a specific IP address action.escu.creation_date = 2020-04-13 action.escu.modification_date = 2020-04-13 @@ -13136,11 +13785,11 @@ schedule_window = auto is_visible = false search = sourcetype="aws:cloudwatchlogs:eks" |rename sourceIPs{} as src_ip |search src_ip=$src_ip$ | stats count min(_time) as firstTime max(_time) as lastTime values(user.username) values(requestURI) values(verb) values(userAgent) by source annotations.authorization.k8s.io/decision src_ip -[response - GCP Kubernetes activity by src ip - Response Task] +[ESCU - GCP Kubernetes activity by src ip - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - GCP Kubernetes activity by src ip - Response Task +action.escu.full_search_name = ESCU - GCP Kubernetes activity by src ip - Response Task description = This search provides investigation data about requests via user agent, authentication request URI, resource path and cluster name data against Kubernetes cluster from a specific IP address action.escu.creation_date = 2020-04-13 action.escu.modification_date = 2020-04-13 @@ -13157,11 +13806,11 @@ schedule_window = auto is_visible = false search = sourcetype="google:gcp:pubsub:message" | rename data.protoPayload.requestMetadata.callerIp as src_ip | search src_ip =$src_ip$ | stats count min(_time) as firstTime max(_time) as lastTime values(data.protoPayload.methodName) as method_names values(data.protoPayload.resourceName) as resource_name values(data.protoPayload.requestMetadata.callerSuppliedUserAgent) as http_user_agent values(data.protoPayload.authenticationInfo.principalEmail) as user values(data.protoPayload.status.message) by src_ip data.resource.labels.cluster_name data.resource.type -[response - Get All AWS Activity From City - Response Task] +[ESCU - Get All AWS Activity From City - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Get All AWS Activity From City - Response Task +action.escu.full_search_name = ESCU - Get All AWS Activity From City - Response Task description = This search retrieves all the activity from a specific city and will create a table containing the time, city, ARN, username, the type of user, the source IP address, the AWS region the activity was in, the API called, and whether or not the API call was successful. action.escu.creation_date = 2018-03-19 action.escu.modification_date = 2018-03-19 @@ -13178,11 +13827,11 @@ schedule_window = auto is_visible = false search = | search sourcetype=aws:cloudtrail | iplocation sourceIPAddress | search City=$City$ | spath output=user path=userIdentity.arn | spath output=awsUserName path=userIdentity.userName | spath output=userType path=userIdentity.type | rename sourceIPAddress as src_ip | table _time, City, user, userName, userType, src_ip, awsRegion, eventName, errorCode -[response - Get All AWS Activity From Country - Response Task] +[ESCU - Get All AWS Activity From Country - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Get All AWS Activity From Country - Response Task +action.escu.full_search_name = ESCU - Get All AWS Activity From Country - Response Task description = This search retrieves all the activity from a specific country and will create a table containing the time, country, ARN, username, the type of user, the source IP address, the AWS region the activity was in, the API called, and whether or not the API call was successful. action.escu.creation_date = 2018-03-19 action.escu.modification_date = 2018-03-19 @@ -13199,11 +13848,11 @@ schedule_window = auto is_visible = false search = | search sourcetype=aws:cloudtrail | iplocation sourceIPAddress | search Country=$Country$ | spath output=user path=userIdentity.arn | spath output=awsUserName path=userIdentity.userName | spath output=userType path=userIdentity.type | rename sourceIPAddress as src_ip | table _time, Country, user, userName, userType, src_ip, awsRegion, eventName, errorCode -[response - Get All AWS Activity From IP Address - Response Task] +[ESCU - Get All AWS Activity From IP Address - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Get All AWS Activity From IP Address - Response Task +action.escu.full_search_name = ESCU - Get All AWS Activity From IP Address - Response Task description = This search retrieves all the activity from a specific IP address and will create a table containing the time, ARN, username, the type of user, the IP address, the AWS region the activity was in, the API called, and whether or not the API call was successful. action.escu.creation_date = 2018-03-19 action.escu.modification_date = 2018-03-19 @@ -13220,11 +13869,11 @@ schedule_window = auto is_visible = false search = | search sourcetype=aws:cloudtrail | iplocation sourceIPAddress | search src_ip=$src_ip$ | spath output=user path=userIdentity.arn | spath output=awsUserName path=userIdentity.userName | spath output=userType path=userIdentity.type | rename sourceIPAddress as src_ip | table _time, user, userName, userType, src_ip, awsRegion, eventName, errorCode -[response - Get All AWS Activity From Region - Response Task] +[ESCU - Get All AWS Activity From Region - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Get All AWS Activity From Region - Response Task +action.escu.full_search_name = ESCU - Get All AWS Activity From Region - Response Task description = This search retrieves all the activity from a specific geographic region and will create a table containing the time, geographic region, ARN, username, the type of user, the source IP address, the AWS region the activity was in, the API called, and whether or not the API call was successful. action.escu.creation_date = 2018-03-19 action.escu.modification_date = 2018-03-19 @@ -13241,11 +13890,11 @@ schedule_window = auto is_visible = false search = | search sourcetype=aws:cloudtrail | iplocation sourceIPAddress | search Region=$Region$ | spath output=user path=userIdentity.arn | spath output=awsUserName path=userIdentity.userName | spath output=userType path=userIdentity.type | rename sourceIPAddress as src_ip | table _time, Region, user, userName, userType, src_ip, awsRegion, eventName, errorCode -[response - Get Backup Logs For Endpoint - Response Task] +[ESCU - Get Backup Logs For Endpoint - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Get Backup Logs For Endpoint - Response Task +action.escu.full_search_name = ESCU - Get Backup Logs For Endpoint - Response Task description = This search will tell you the backup status from your netbackup_logs of a specific endpoint for the last week. action.escu.creation_date = 2017-09-14 action.escu.modification_date = 2017-09-14 @@ -13262,11 +13911,11 @@ schedule_window = auto is_visible = false search = | search sourcetype="netbackup_logs" COMPUTERNAME=$dest$ | rename COMPUTERNAME as dest, MESSAGE as signature | table _time, dest, signature -[response - Get Certificate logs for a domain - Response Task] +[ESCU - Get Certificate logs for a domain - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Get Certificate logs for a domain - Response Task +action.escu.full_search_name = ESCU - Get Certificate logs for a domain - Response Task description = This search queries the Certificates datamodel and give you all the information for a specific domain. Please note that the certificates issued by "Let's Encrypt" are widely used by attackers. action.escu.creation_date = 2019-04-29 action.escu.modification_date = 2019-04-29 @@ -13283,11 +13932,11 @@ schedule_window = auto is_visible = false search = | tstats `summariesonly` count min(_time) as firstTime max(_time) as lastTime FROM datamodel=Certificates.All_Certificates where All_Certificates.SSL.ssl_subject_common_name=*$domain$ by All_Certificates.dest All_Certificates.src All_Certificates.SSL.ssl_issuer_common_name All_Certificates.SSL.ssl_subject_common_name All_Certificates.SSL.ssl_hash | `drop_dm_object_name(All_Certificates)` | `drop_dm_object_name(SSL)` | rename ssl_subject_common_name as domain | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` -[response - Get DNS Server History for a host - Response Task] +[ESCU - Get DNS Server History for a host - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Get DNS Server History for a host - Response Task +action.escu.full_search_name = ESCU - Get DNS Server History for a host - Response Task description = While investigating any detections it is important to understand which and how many DNS servers a host has connected to in the past. This search uses data that is tagged as DNS and gives you a count and list of DNS servers that a particular host has connected to the previous 24 hours. action.escu.creation_date = 2017-11-09 action.escu.modification_date = 2017-11-09 @@ -13304,11 +13953,11 @@ schedule_window = auto is_visible = false search = | search tag=dns src_ip=$src_ip$ dest_port=53 | streamstats time_window=1d count values(dest_ip) as dcip by src_ip | table date_mday src_ip dcip count | sort -count -[response - Get DNS traffic ratio - Response Task] +[ESCU - Get DNS traffic ratio - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Get DNS traffic ratio - Response Task +action.escu.full_search_name = ESCU - Get DNS traffic ratio - Response Task description = This search calculates the ratio of DNS traffic originating and coming from a host to a list of DNS servers over the last 24 hours. A high value of this ratio could be very useful to quickly understand if a src_ip (host) is sending a high volume of data out via port 53, could be an indicator of data exfiltration via DNS. action.escu.creation_date = 2017-11-09 action.escu.modification_date = 2017-11-09 @@ -13325,11 +13974,11 @@ schedule_window = auto is_visible = false search = | tstats allow_old_summaries=true sum(All_Traffic.bytes_out) as "bytes_out" sum(All_Traffic.bytes_in) as "bytes_in" from datamodel=Network_Traffic where nodename=All_Traffic All_Traffic.dest_port=53 by All_Traffic.src All_Traffic.dest| `drop_dm_object_name(All_Traffic)` | rename src as src_ip | rename dest as dest_ip | search src_ip=$src_ip$ | search dest_ip = $dest_ip | eval ratio = (bytes_out/bytes_in) | table ratio -[response - Get EC2 Instance Details by instanceId - Response Task] +[ESCU - Get EC2 Instance Details by instanceId - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Get EC2 Instance Details by instanceId - Response Task +action.escu.full_search_name = ESCU - Get EC2 Instance Details by instanceId - Response Task description = This search queries AWS description logs and returns all the information about a specific instance via the instanceId field action.escu.creation_date = 2018-02-12 action.escu.modification_date = 2018-02-12 @@ -13346,11 +13995,11 @@ schedule_window = auto is_visible = false search = | search sourcetype="aws:description" source="*:ec2_instances"| dedup id sortby -_time |rename id as instanceId| search instanceId=$instanceId$ | spath output=tags path=tags | eval tags=mvzip(key,value," = "), ip_address=if((ip_address == "null"),private_ip_address,ip_address) | table id, tags.Name, aws_account_id, placement, instance_type, key_name, ip_address, launch_time, state, vpc_id, subnet_id, tags | rename aws_account_id as "Account ID", id as ID, instance_type as Type, ip_address as "IP Address", key_name as "Key Pair", launch_time as "Launch Time", placement as "Availability Zone", state as State, subnet_id as Subnet, "tags.Name" as Name, vpc_id as VPC -[response - Get EC2 Launch Details - Response Task] +[ESCU - Get EC2 Launch Details - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Get EC2 Launch Details - Response Task +action.escu.full_search_name = ESCU - Get EC2 Launch Details - Response Task description = This search returns some of the launch details for a EC2 instance. action.escu.creation_date = 2018-03-12 action.escu.modification_date = 2018-03-12 @@ -13367,11 +14016,11 @@ schedule_window = auto is_visible = false search = | search sourcetype=aws:cloudtrail dest=$dest$ |rename userIdentity.arn as arn, responseElements.instancesSet.items{}.instanceId as dest, responseElements.instancesSet.items{}.privateIpAddress as privateIpAddress, responseElements.instancesSet.items{}.imageId as amiID, responseElements.instancesSet.items{}.architecture as architecture, responseElements.instancesSet.items{}.keyName as keyName | table arn, awsRegion, dest, architecture, privateIpAddress, amiID, keyName -[response - Get Email Info - Response Task] +[ESCU - Get Email Info - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Get Email Info - Response Task +action.escu.full_search_name = ESCU - Get Email Info - Response Task description = This search returns all the information Splunk might have collected a specific email message over the last 2 hours. action.escu.creation_date = 2017-11-09 action.escu.modification_date = 2017-11-09 @@ -13388,11 +14037,11 @@ schedule_window = auto is_visible = false search = | from datamodel Email.All_Email | search message_id=$message_id$ -[response - Get Emails From Specific Sender - Response Task] +[ESCU - Get Emails From Specific Sender - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Get Emails From Specific Sender - Response Task +action.escu.full_search_name = ESCU - Get Emails From Specific Sender - Response Task description = This search returns all the emails from a specific sender over the last 24 and next hours. action.escu.creation_date = 2017-11-09 action.escu.modification_date = 2017-11-09 @@ -13409,11 +14058,11 @@ schedule_window = auto is_visible = false search = | from datamodel Email.All_Email | search src_user=$src_user$ -[response - Get First Occurrence and Last Occurrence of a MAC Address - Response Task] +[ESCU - Get First Occurrence and Last Occurrence of a MAC Address - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Get First Occurrence and Last Occurrence of a MAC Address - Response Task +action.escu.full_search_name = ESCU - Get First Occurrence and Last Occurrence of a MAC Address - Response Task description = This search allows you to gather more context around a notable which has detected a new device connecting to your network. Use this search to determine the first and last occurrences of the suspicious device attempting to connect with your network. action.escu.creation_date = 2017-09-13 action.escu.modification_date = 2017-09-13 @@ -13430,11 +14079,11 @@ schedule_window = auto is_visible = false search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Network_Sessions where nodename=All_Sessions.DHCP All_Sessions.signature=DHCPREQUEST All_Sessions.All_Sessions.src_mac= $src_mac$ by All_Sessions.src_ip All_Sessions.user | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` -[response - Get History Of Email Sources - Response Task] +[ESCU - Get History Of Email Sources - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Get History Of Email Sources - Response Task +action.escu.full_search_name = ESCU - Get History Of Email Sources - Response Task description = This search returns a list of all email sources seen in the 48 hours prior to the notable event to 24 hours after, and the number of emails from each source. action.escu.creation_date = 2019-02-21 action.escu.modification_date = 2019-02-21 @@ -13451,11 +14100,11 @@ schedule_window = auto is_visible = false search = |tstats `security_content_summariesonly` values(All_Email.dest) as dest values(All_Email.recipient) as recepient min(_time) as firstTime max(_time) as lastTime count from datamodel=Email.All_Email by All_Email.src |`drop_dm_object_name(All_Email)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | search src=$src$ -[response - Get Logon Rights Modifications For Endpoint - Response Task] +[ESCU - Get Logon Rights Modifications For Endpoint - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Get Logon Rights Modifications For Endpoint - Response Task +action.escu.full_search_name = ESCU - Get Logon Rights Modifications For Endpoint - Response Task description = This search allows you to retrieve any modifications to logon rights associated with a specific host. action.escu.creation_date = 2017-09-12 action.escu.modification_date = 2017-09-12 @@ -13472,11 +14121,11 @@ schedule_window = auto is_visible = false search = | search eventtype=wineventlog_security (signature_id=4718 OR signature_id=4717) dest=$dest$ | rename user as "Account Modified" | table _time, dest, "Account Modified", Access_Right, signature -[response - Get Logon Rights Modifications For User - Response Task] +[ESCU - Get Logon Rights Modifications For User - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Get Logon Rights Modifications For User - Response Task +action.escu.full_search_name = ESCU - Get Logon Rights Modifications For User - Response Task description = This search allows you to retrieve any modifications to logon rights for a specific user account. action.escu.creation_date = 2019-02-27 action.escu.modification_date = 2019-02-27 @@ -13493,11 +14142,11 @@ schedule_window = auto is_visible = false search = | search eventtype=wineventlog_security (signature_id=4718 OR signature_id=4717) user=$user$ | rename user as "Account Modified" | table _time, dest, "Account Modified", Access_Right, signature -[response - Get Notable History - Response Task] +[ESCU - Get Notable History - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Get Notable History - Response Task +action.escu.full_search_name = ESCU - Get Notable History - Response Task description = This search queries the notable index and returns all the Notable Events for the particular destination host, giving the analyst an overview of the incidents that may have occurred with the host under investigation. action.escu.creation_date = 2017-09-20 action.escu.modification_date = 2017-09-20 @@ -13514,11 +14163,11 @@ schedule_window = auto is_visible = false search = | search `notable` | search dest=$dest$ | table _time, dest, rule_name, owner, priority, severity, status_description -[response - Get Outbound Emails to Hidden Cobra Threat Actors - Response Task] +[ESCU - Get Outbound Emails to Hidden Cobra Threat Actors - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Get Outbound Emails to Hidden Cobra Threat Actors - Response Task +action.escu.full_search_name = ESCU - Get Outbound Emails to Hidden Cobra Threat Actors - Response Task description = This search returns the information of the users that sent emails to the accounts controlled by the Hidden Cobra Threat Actors: specifically to `misswang8107@gmail.com`, and from `redhat@gmail.com`. action.escu.creation_date = 2018-06-14 action.escu.modification_date = 2018-06-14 @@ -13535,11 +14184,11 @@ schedule_window = auto is_visible = false search = | from datamodel Email.All_Email | search recipient=misswang8107@gmail.com OR src_user=redhat@gmail.com | stats count earliest(_time) as firstTime, latest(_time) as lastTime values(dest) values(src) by src_user recipient | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` -[response - Get Parent Process Info - Response Task] +[ESCU - Get Parent Process Info - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Get Parent Process Info - Response Task +action.escu.full_search_name = ESCU - Get Parent Process Info - Response Task description = This search queries the Endpoint data model to give you details about the parent process of a process running on a host which is under investigation. Enter the values of the process name in question and the dest action.escu.creation_date = 2019-02-28 action.escu.modification_date = 2019-02-28 @@ -13556,11 +14205,11 @@ schedule_window = auto is_visible = false search = | tstats `summariesonly` count values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes by Processes.user Processes.parent_process_name Processes.process_name Processes.dest | `drop_dm_object_name("Processes")` | search parent_process_name= $parent_process_name$ |search dest = $dest$ | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` -[response - Get Process File Activity - Response Task] +[ESCU - Get Process File Activity - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Get Process File Activity - Response Task +action.escu.full_search_name = ESCU - Get Process File Activity - Response Task description = This search returns the file activity for a specific process on a specific endpoint action.escu.creation_date = 2019-11-06 action.escu.modification_date = 2019-11-06 @@ -13577,11 +14226,11 @@ schedule_window = auto is_visible = false search = | tstats `security_content_summariesonly` values(Filesystem.file_name) as file_name values(Filesystem.dest) as dest, values(Filesystem.process_name) as process_name from datamodel=Endpoint.Filesystem by Filesystem.dest Filesystem.process_name Filesystem.file_path, Filesystem.action, _time | `drop_dm_object_name(Filesystem)` | search dest=$dest$ | search process_name=$process_name$ | table _time, process_name, dest, action, file_name, file_path -[response - Get Process Info - Response Task] +[ESCU - Get Process Info - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Get Process Info - Response Task +action.escu.full_search_name = ESCU - Get Process Info - Response Task description = This search queries the Endpoint data model to give you details about the process running on a host which is under investigation. To gather the process info, enter the values for the process name in question and the destination IP address. action.escu.creation_date = 2019-04-01 action.escu.modification_date = 2019-04-01 @@ -13598,11 +14247,11 @@ schedule_window = auto is_visible = false search = | tstats `summariesonly` count values(Processes.process) as process min(_time) as firstTime max(_time) as lastTime FROM datamodel=Endpoint.Processes by Processes.user Processes.parent_process_name Processes.process_name Processes.dest | `drop_dm_object_name("Processes")` | search process_name= $process_name$ | search dest = $dest$ | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` -[response - Get Process Information For Port Activity - Response Task] +[ESCU - Get Process Information For Port Activity - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Get Process Information For Port Activity - Response Task +action.escu.full_search_name = ESCU - Get Process Information For Port Activity - Response Task description = This search will return information about the process associated with observed network traffic to a specific destination port from a specific host. action.escu.creation_date = 2019-04-01 action.escu.modification_date = 2019-04-01 @@ -13619,11 +14268,11 @@ schedule_window = auto is_visible = false search = | tstats `security_content_summariesonly` count min(_time) max(_time) as lastTime from datamodel=Endpoint.Processes by Processes.process_name Processes.user Processes.dest Processes.process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | search dest=$dest$ | join dest type=inner [| tstats `security_content_summariesonly` count from datamodel=Endpoint.Ports by Ports.process_id Ports.src Ports.dest_port | `drop_dm_object_name(Ports)` | search dest_port=$dest_port$ | rename src as dest] -[response - Get Process Responsible For The DNS Traffic - Response Task] +[ESCU - Get Process Responsible For The DNS Traffic - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Get Process Responsible For The DNS Traffic - Response Task +action.escu.full_search_name = ESCU - Get Process Responsible For The DNS Traffic - Response Task description = While investigating, an analyst will want to know what process and parent_process is responsible for generating suspicious DNS traffic. Use the following search and enter the value of `dest` in the search to get specific details on the process responsible for creating the DNS traffic. action.escu.creation_date = 2019-04-01 action.escu.modification_date = 2019-04-01 @@ -13640,11 +14289,11 @@ schedule_window = auto is_visible = false search = | tstats `security_content_summariesonly` count min(_time) max(_time) as lastTime from datamodel=Endpoint.Processes by Processes.parent_process Processes.process_name Processes.user Processes.dest Processes.process_id | `drop_dm_object_name(Processes)` | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)` | search dest = $dest$ | join dest type=inner [| tstats `security_content_summariesonly` count from datamodel=Endpoint.Ports where Ports.dest_port=53 by Ports.process_id Ports.src | `drop_dm_object_name(Ports)` | rename src as dest] -[response - Get Sysmon WMI Activity for Host - Response Task] +[ESCU - Get Sysmon WMI Activity for Host - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Get Sysmon WMI Activity for Host - Response Task +action.escu.full_search_name = ESCU - Get Sysmon WMI Activity for Host - Response Task description = This search queries Sysmon WMI events for the host of interest. action.escu.creation_date = 2018-10-23 action.escu.modification_date = 2018-10-23 @@ -13661,11 +14310,11 @@ schedule_window = auto is_visible = false search = sourcetype="XmlWinEventLog:Microsoft-Windows-Sysmon/Operational" EventCode>18 EventCode<22 | rename host as dest | search dest=$dest$| table _time, dest, user, Name, Operation, EventType, Type, Query, Consumer, Filter -[response - Get Web Session Information via session id - Response Task] +[ESCU - Get Web Session Information via session id - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Get Web Session Information via session id - Response Task +action.escu.full_search_name = ESCU - Get Web Session Information via session id - Response Task description = This search helps an analyst investigate a notable event to find out more about a specific web session. The search looks for a specific web session ID in the HTTP web traffic and outputs the URL and user agents, grouped by source IP address and HTTP status code. action.escu.creation_date = 2018-10-08 action.escu.modification_date = 2018-10-08 @@ -13682,11 +14331,11 @@ schedule_window = auto is_visible = false search = | search sourcetype=stream:http session_id = $session_id$ | stats values(url) values(http_user_agent) by src_ip status -[response - Investigate AWS User Activities by user field - Response Task] +[ESCU - Investigate AWS User Activities by user field - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Investigate AWS User Activities by user field - Response Task +action.escu.full_search_name = ESCU - Investigate AWS User Activities by user field - Response Task description = This search lists all the logged CloudTrail activities by a specific user and will create a table containing the source of the user, the region of the activity, the name and type of the event, the action taken, and the user's identity information. action.escu.creation_date = 2018-03-12 action.escu.modification_date = 2018-03-12 @@ -13703,11 +14352,11 @@ schedule_window = auto is_visible = false search = | search sourcetype=aws:cloudtrail user=$user$ | table _time userIdentity.type userIdentity.userName userIdentity.arn aws_account_id src awsRegion eventName eventType -[response - Investigate AWS activities via region name - Response Task] +[ESCU - Investigate AWS activities via region name - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Investigate AWS activities via region name - Response Task +action.escu.full_search_name = ESCU - Investigate AWS activities via region name - Response Task description = This search lists all the user activities logged by CloudTrail for a specific region in question and will create a table of the values of parameters requested, the type of the event and the response from the AWS API by each user action.escu.creation_date = 2018-02-09 action.escu.modification_date = 2018-02-09 @@ -13724,11 +14373,11 @@ schedule_window = auto is_visible = false search = | search sourcetype=aws:cloudtrail vendor_region=$vendor_region$| rename requestParameters.instancesSet.items{}.instanceId as instanceId | stats values(eventName) by user instanceId vendor_region -[response - Investigate Failed Logins for Multiple Destinations - Response Task] +[ESCU - Investigate Failed Logins for Multiple Destinations - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Investigate Failed Logins for Multiple Destinations - Response Task +action.escu.full_search_name = ESCU - Investigate Failed Logins for Multiple Destinations - Response Task description = This search returns failed logins to multiple destinations by user. action.escu.creation_date = 2019-12-10 action.escu.modification_date = 2019-12-10 @@ -13745,11 +14394,11 @@ schedule_window = auto is_visible = false search = | tstats count `security_content_summariesonly` earliest(_time) as first_login latest(_time) as last_login dc(Authentication.dest) AS distinct_count_dest values(Authentication.dest) AS Authentication.dest values(Authentication.app) AS Authentication.app from datamodel=Authentication where Authentication.action=failure by Authentication.user | where distinct_count_dest > 1 | `security_content_ctime(first_login)` | `security_content_ctime(last_login)` | `drop_dm_object_name("Authentication")` | search user=$user$ -[response - Investigate Network Traffic From src ip - Response Task] +[ESCU - Investigate Network Traffic From src ip - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Investigate Network Traffic From src ip - Response Task +action.escu.full_search_name = ESCU - Investigate Network Traffic From src ip - Response Task description = This search allows you to find all the network traffic from a specific IP address. action.escu.creation_date = 2018-06-15 action.escu.modification_date = 2018-06-15 @@ -13766,11 +14415,11 @@ schedule_window = auto is_visible = false search = | from datamodel Network_Traffic.All_Traffic | search src_ip=$src_ip$ -[response - Investigate Okta Activity by IP Address - Response Task] +[ESCU - Investigate Okta Activity by IP Address - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Investigate Okta Activity by IP Address - Response Task +action.escu.full_search_name = ESCU - Investigate Okta Activity by IP Address - Response Task description = This search returns all okta events from a specific IP address. action.escu.creation_date = 2020-04-02 action.escu.modification_date = 2020-04-02 @@ -13787,11 +14436,11 @@ schedule_window = auto is_visible = false search = eventtype=okta_log src_ip={src_ip} | rename client.geographicalContext.country as country, client.geographicalContext.state as state, client.geographicalContext.city as city | table _time, user, displayMessage, app, src_ip, state, city, result, outcome.reason -[response - Investigate Okta Activity by app - Response Task] +[ESCU - Investigate Okta Activity by app - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Investigate Okta Activity by app - Response Task +action.escu.full_search_name = ESCU - Investigate Okta Activity by app - Response Task description = This search returns all okta events associated with a specific app action.escu.creation_date = 2020-04-02 action.escu.modification_date = 2020-04-02 @@ -13808,11 +14457,11 @@ schedule_window = auto is_visible = false search = eventtype=okta_log app=$app$ | rename client.geographicalContext.country as country, client.geographicalContext.state as state, client.geographicalContext.city as city | table _time, user, displayMessage, app, src_ip, state, city, result, outcome.reason -[response - Investigate Pass the Hash Attempts - Response Task] +[ESCU - Investigate Pass the Hash Attempts - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Investigate Pass the Hash Attempts - Response Task +action.escu.full_search_name = ESCU - Investigate Pass the Hash Attempts - Response Task description = This search hunts for dumped NTLM hashes used for pass the hash. action.escu.creation_date = 2019-12-10 action.escu.modification_date = 2019-12-10 @@ -13829,11 +14478,11 @@ schedule_window = auto is_visible = false search = `wineventlog_security` EventCode=4624 Logon_Type=9 AuthenticationPackageName=Negotiate | stats count earliest(_time) as first_login latest(_time) as last_login by src_user dest | `security_content_ctime(first_login)` | `security_content_ctime(last_login)` | search dest=$dest$ -[response - Investigate Pass the Ticket Attempts - Response Task] +[ESCU - Investigate Pass the Ticket Attempts - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Investigate Pass the Ticket Attempts - Response Task +action.escu.full_search_name = ESCU - Investigate Pass the Ticket Attempts - Response Task description = This search hunts for dumped kerberos ticket from LSASS memory. action.escu.creation_date = 2019-12-10 action.escu.modification_date = 2019-12-10 @@ -13850,11 +14499,11 @@ schedule_window = auto is_visible = false search = `wineventlog_security` EventCode=4768 OR EventCode=4769 | rex field=user "(?[^\@]+)" | stats count BY new_user, dest, EventCode | stats max(count) AS max_count sum(count) AS sum_count BY new_user, dest| search dest=$dest$ | where sum_count/max_count!=2 | rename new_user AS user -[response - Investigate Previous Unseen User - Response Task] +[ESCU - Investigate Previous Unseen User - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Investigate Previous Unseen User - Response Task +action.escu.full_search_name = ESCU - Investigate Previous Unseen User - Response Task description = This search returns previous unseen user, which didn't log in for 30 days. action.escu.creation_date = 2019-12-10 action.escu.modification_date = 2019-12-10 @@ -13871,11 +14520,11 @@ schedule_window = auto is_visible = false search = | tstats count `security_content_summariesonly` earliest(_time) as first_login latest(_time) as last_login values(Authentication.dest) AS Authentication.dest values(Authentication.app) AS Authentication.app values(Authentication.action) AS Authentication.action from datamodel=Authentication where Authentication.action=success by _time, Authentication.user | bucket _time span=30d | stats count min(first_login) as first_login max(last_login) as last_login values(Authentication.dest) AS Authentication.dest by Authentication.user | where count=1 | where first_login >= relative_time(now(), "-30d") | `security_content_ctime(first_login)` | `security_content_ctime(last_login)` | `drop_dm_object_name("Authentication")` | search dest=$dest$ -[response - Investigate Successful Remote Desktop Authentications - Response Task] +[ESCU - Investigate Successful Remote Desktop Authentications - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Investigate Successful Remote Desktop Authentications - Response Task +action.escu.full_search_name = ESCU - Investigate Successful Remote Desktop Authentications - Response Task description = This search returns the source, destination, and user for all successful remote-desktop authentications. A successful authentication after a brute-force attack on a destination machine is suspicious behavior. action.escu.creation_date = 2018-12-14 action.escu.modification_date = 2018-12-14 @@ -13892,11 +14541,11 @@ schedule_window = auto is_visible = false search = | tstats `security_content_summariesonly` count min(_time) as firstTime max(_time) as lastTime from datamodel=Authentication where Authentication.signature_id=4624 Authentication.app=win:remote by Authentication.src Authentication.dest Authentication.app Authentication.user Authentication.signature Authentication.src_nt_domain | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `drop_dm_object_name("Authentication")` | search dest=$dest$ | table firstTime lastTime src src_nt_domain dest user app count | sort count -[response - Investigate Suspicious Strings in HTTP Header - Response Task] +[ESCU - Investigate Suspicious Strings in HTTP Header - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Investigate Suspicious Strings in HTTP Header - Response Task +action.escu.full_search_name = ESCU - Investigate Suspicious Strings in HTTP Header - Response Task description = This search helps an analyst investigate a notable event related to a potential Apache Struts exploitation. To investigate, we will want to isolate and analyze the "payload" or the commands that were passed to the vulnerable hosts by creating a few regular expressions to carve out the commands focusing on common keywords from the payload, such as cmd.exe, /bin/bash and whois. The search returns these suspicious strings found in the HTTP logs of the system of interest. action.escu.creation_date = 2017-10-20 action.escu.modification_date = 2017-10-20 @@ -13913,11 +14562,11 @@ schedule_window = auto is_visible = false search = | search sourcetype=stream:http | search src_ip=$src_ip$ | search dest_ip=$dest_ip$ | eval cs_content_type_length = len(cs_content_type) | search cs_content_type_length > 100 | rex field="cs_content_type" (?cmd.exe) | eval suspicious_strings_found=if(match(cs_content_type, "application"), "True", "False") | rename suspicious_strings_found AS "Suspicious Content-Type Found" | fields "Suspicious Content-Type Found", dest_ip, src_ip, suspicious_strings, cs_content_type, cs_content_type_length, url -[response - Investigate User Activities In Okta - Response Task] +[ESCU - Investigate User Activities In Okta - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Investigate User Activities In Okta - Response Task +action.escu.full_search_name = ESCU - Investigate User Activities In Okta - Response Task description = This search returns all okta events by a specific user action.escu.creation_date = 2020-04-02 action.escu.modification_date = 2020-04-02 @@ -13934,11 +14583,11 @@ schedule_window = auto is_visible = false search = eventtype=okta_log user=$user$ | rename client.geographicalContext.country as country, client.geographicalContext.state as state, client.geographicalContext.city as city | table _time, user, displayMessage, app, src_ip, state, city, result, outcome.reason -[response - Investigate Web POSTs From src - Response Task] +[ESCU - Investigate Web POSTs From src - Response Task] action.escu = 0 action.escu.enabled = 1 action.escu.search_type = investigative -action.escu.full_search_name = response - Investigate Web POSTs From src - Response Task +action.escu.full_search_name = ESCU - Investigate Web POSTs From src - Response Task description = This investigative search retrieves POST requests from a specified source IP or hostname. Identifying the POST requests, as well as their associated destination URLs and user agent(s), may help you scope and characterize the suspicious traffic. action.escu.creation_date = 2018-12-06 action.escu.modification_date = 2018-12-06 diff --git a/package/default/transforms.conf b/package/default/transforms.conf index fa14eb5c6e..0f54933b37 100644 --- a/package/default/transforms.conf +++ b/package/default/transforms.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security_content -# On Date: 2021-03-12T17:19:06 UTC +# On Date: 2021-03-25T19:21:00 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# diff --git a/package/default/use_case_library.conf b/package/default/use_case_library.conf index d40b3ba8df..e29ce6a0fb 100644 --- a/package/default/use_case_library.conf +++ b/package/default/use_case_library.conf @@ -1,6 +1,6 @@ ############# # Automatically generated by generator.py in splunk/security_content -# On Date: 2021-03-12T17:19:06 UTC +# On Date: 2021-03-25T19:21:00 UTC # Author: Splunk Security Research # Contact: research@splunk.com ############# @@ -14,7 +14,7 @@ version = 1 references = ["https://aws.amazon.com/blogs/security/aws-cloudtrail-now-tracks-cross-account-activity-to-its-origin/"] maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}] spec_version = 3 -searches = ["ESCU - aws detect sts get session token abuse - Rule", "ESCU - aws detect attach to role policy - Rule", "ESCU - aws detect permanent key creation - Rule", "ESCU - aws detect sts assume role abuse - Rule", "ESCU - aws detect role creation - Rule", "ESCU - AWS Investigate User Activities By AccessKeyId - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - aws detect role creation - Rule", "ESCU - aws detect sts assume role abuse - Rule", "ESCU - aws detect sts get session token abuse - Rule", "ESCU - aws detect permanent key creation - Rule", "ESCU - aws detect attach to role policy - Rule", "ESCU - AWS Investigate User Activities By AccessKeyId - Response Task", "ESCU - Get Notable History - Response Task"] description = Track when a user assumes an IAM role in another AWS account to obtain cross-account access to services and resources in that account. Accessing new roles could be an indication of malicious activity. narrative = Amazon Web Services (AWS) admins manage access to AWS resources and services across the enterprise using AWS's Identity and Access Management (IAM) functionality. IAM provides the ability to create and manage AWS users, groups, and roles-each with their own unique set of privileges and defined access to specific resources (such as EC2 instances, the AWS Management Console, API, or the command-line interface). Unlike conventional (human) users, IAM roles are assumable by anyone in the organization. They provide users with dynamically created temporary security credentials that expire within a set time period.\ Herein lies the rub. In between the time between when the temporary credentials are issued and when they expire is a period of opportunity, where a user could leverage the temporary credentials to wreak havoc-spin up or remove instances, create new users, elevate privileges, and other malicious activities-throughout the environment.\ @@ -27,13 +27,24 @@ version = 1 references = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf"] maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}] spec_version = 3 -searches = ["ESCU - Abnormally High AWS Instances Launched by User - Rule", "ESCU - EC2 Instance Started With Previously Unseen Instance Type - Rule", "ESCU - Abnormally High AWS Instances Launched by User - MLTK - Rule", "ESCU - EC2 Instance Started In Previously Unseen Region - Rule", "ESCU - EC2 Instance Started With Previously Unseen User - Rule", "ESCU - EC2 Instance Started With Previously Unseen AMI - Rule", "ESCU - Get Notable History - Response Task", "ESCU - Investigate AWS activities via region name - Response Task", "ESCU - Get EC2 Launch Details - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get EC2 Instance Details by instanceId - Response Task"] +searches = ["ESCU - Abnormally High AWS Instances Launched by User - Rule", "ESCU - EC2 Instance Started With Previously Unseen User - Rule", "ESCU - EC2 Instance Started In Previously Unseen Region - Rule", "ESCU - EC2 Instance Started With Previously Unseen AMI - Rule", "ESCU - EC2 Instance Started With Previously Unseen Instance Type - Rule", "ESCU - Abnormally High AWS Instances Launched by User - MLTK - Rule", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get EC2 Instance Details by instanceId - Response Task", "ESCU - Investigate AWS activities via region name - Response Task", "ESCU - Get EC2 Launch Details - Response Task", "ESCU - Get Notable History - Response Task"] description = Monitor your AWS EC2 instances for activities related to cryptojacking/cryptomining. New instances that originate from previously unseen regions, users who launch abnormally high numbers of instances, or EC2 instances started by previously unseen users are just a few examples of potentially malicious behavior. narrative = Cryptomining is an intentionally difficult, resource-intensive business. Its complexity was designed into the process to ensure that the number of blocks mined each day would remain steady. So, it's par for the course that ambitious, but unscrupulous, miners make amassing the computing power of large enterprises--a practice known as cryptojacking--a top priority. \ Cryptojacking has attracted an increasing amount of media attention since its explosion in popularity in the fall of 2017. The attacks have moved from in-browser exploits and mobile phones to enterprise cloud services, such as Amazon Web Services (AWS). It's difficult to determine exactly how widespread the practice has become, since bad actors continually evolve their ability to escape detection, including employing unlisted endpoints, moderating their CPU usage, and hiding the mining pool's IP address behind a free CDN. \ When malicious miners appropriate a cloud instance, often spinning up hundreds of new instances, the costs can become astronomical for the account holder. So, it is critically important to monitor your systems for suspicious activities that could indicate that your network has been infiltrated. \ This Analytic Story is focused on detecting suspicious new instances in your EC2 environment to help prevent such a disaster. It contains detection searches that will detect when a previously unused instance type or AMI is used. It also contains support searches to build lookup files to ensure proper execution of the detection searches. +[analytic_story://AWS IAM Privilege Escalation] +category = Cloud Security +last_updated = 2021-03-08 +version = 1 +references = ["https://rhinosecuritylabs.com/aws/aws-privilege-escalation-methods-mitigation/", "https://www.cyberark.com/resources/threat-research-blog/the-cloud-shadow-admin-threat-10-permissions-to-protect", "https://labs.bishopfox.com/tech-blog/privilege-escalation-in-aws"] +maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] +spec_version = 3 +searches = ["ESCU - AWS Create Policy Version to allow all resources - Rule", "ESCU - AWS CreateAccessKey - Rule", "ESCU - AWS UpdateLoginProfile - Rule", "ESCU - AWS SetDefaultPolicyVersion - Rule", "ESCU - AWS CreateLoginProfile - Rule"] +description = This analytic story contains detections that query your AWS Cloudtrail for activities related to privilege escalation. +narrative = Amazon Web Services provides a neat feature called Identity and Access Management (IAM) that enables organizations to manage various AWS services and resources in a secure way. All IAM users have roles, groups and policies associated with them which governs and sets permissions to allow a user to access specific restrictions. \ However, if these IAM policies are misconfigured and have specific combinations of weak permissions; it can allow attackers to escalate their privileges and further compromise the organization. Rhino Security Labs have published comprehensive blogs detailing various AWS Escalation methods. By using this as an inspiration, Splunk’s research team wants to highlight how these attack vectors look in AWS Cloudtrail logs and provide you with detection queries to uncover these potentially malicious events via this Analytic Story. \ + [analytic_story://AWS Network ACL Activity] category = Cloud Security last_updated = 2018-05-21 @@ -41,7 +52,7 @@ version = 2 references = ["https://docs.aws.amazon.com/AmazonVPC/latest/UserGuide/VPC_Appendix_NACLs.html", "https://aws.amazon.com/blogs/security/how-to-help-prepare-for-ddos-attacks-by-reducing-your-attack-surface/"] maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - Detect Spike in blocked Outbound Traffic from your AWS - Rule", "ESCU - Detect Spike in Network ACL Activity - Rule", "ESCU - AWS Network Access Control List Created with All Open Ports - Rule", "ESCU - AWS Network Access Control List Deleted - Rule", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - AWS Network Interface details via resourceId - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - AWS Network ACL Details from ID - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task"] +searches = ["ESCU - Detect Spike in blocked Outbound Traffic from your AWS - Rule", "ESCU - AWS Network Access Control List Deleted - Rule", "ESCU - AWS Network Access Control List Created with All Open Ports - Rule", "ESCU - Detect Spike in Network ACL Activity - Rule", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - AWS Network Interface details via resourceId - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - AWS Network ACL Details from ID - Response Task"] description = Monitor your AWS network infrastructure for bad configurations and malicious activity. Investigative searches help you probe deeper, when the facts warrant it. narrative = AWS CloudTrail is an AWS service that helps you enable governance, compliance, and operational/risk auditing of your AWS account. Actions taken by a user, role, or an AWS service are recorded as events in CloudTrail. It is crucial for a company to monitor events and actions taken in the AWS Management Console, AWS Command Line Interface, and AWS SDKs and APIs to ensure that your servers are not vulnerable to attacks. This analytic story contains detection searches that leverage CloudTrail logs from AWS to check for bad configurations and malicious activity in your AWS network access controls. @@ -52,7 +63,7 @@ version = 1 references = ["https://aws.amazon.com/security-hub/features/"] maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - Detect Spike in AWS Security Hub Alerts for EC2 Instance - Rule", "ESCU - Detect Spike in AWS Security Hub Alerts for User - Rule", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get EC2 Launch Details - Response Task", "ESCU - Get EC2 Instance Details by instanceId - Response Task"] +searches = ["ESCU - Detect Spike in AWS Security Hub Alerts for User - Rule", "ESCU - Detect Spike in AWS Security Hub Alerts for EC2 Instance - Rule", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get EC2 Instance Details by instanceId - Response Task", "ESCU - Get EC2 Launch Details - Response Task"] description = This story is focused around detecting Security Hub alerts generated from AWS narrative = AWS Security Hub collects and consolidates findings from AWS security services enabled in your environment, such as intrusion detection findings from Amazon GuardDuty, vulnerability scans from Amazon Inspector, S3 bucket policy findings from Amazon Macie, publicly accessible and cross-account resources from IAM Access Analyzer, and resources lacking WAF coverage from AWS Firewall Manager. @@ -63,7 +74,7 @@ version = 1 references = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf"] maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}] spec_version = 3 -searches = ["ESCU - AWS Cloud Provisioning From Previously Unseen City - Rule", "ESCU - AWS Cloud Provisioning From Previously Unseen IP Address - Rule", "ESCU - AWS Cloud Provisioning From Previously Unseen Country - Rule", "ESCU - AWS Cloud Provisioning From Previously Unseen Region - Rule", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - AWS Investigate Security Hub alerts by dest - Response Task", "ESCU - Get All AWS Activity From Region - Response Task", "ESCU - Get All AWS Activity From Country - Response Task", "ESCU - Get All AWS Activity From City - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task"] +searches = ["ESCU - AWS Cloud Provisioning From Previously Unseen IP Address - Rule", "ESCU - AWS Cloud Provisioning From Previously Unseen Region - Rule", "ESCU - AWS Cloud Provisioning From Previously Unseen Country - Rule", "ESCU - AWS Cloud Provisioning From Previously Unseen City - Rule", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get All AWS Activity From City - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - AWS Investigate Security Hub alerts by dest - Response Task", "ESCU - Get All AWS Activity From Region - Response Task", "ESCU - Get All AWS Activity From Country - Response Task"] description = Monitor your AWS provisioning activities for behaviors originating from unfamiliar or unusual locations. These behaviors may indicate that malicious activities are occurring somewhere within your network. narrative = Because most enterprise AWS activities originate from familiar geographic locations, monitoring for activity from unknown or unusual regions is an important security measure. This indicator can be especially useful in environments where it is impossible to add specific IPs to an allow list because they vary. \ This Analytic Story was designed to provide you with flexibility in the precision you employ in specifying legitimate geographic regions. It can be as specific as an IP address or a city, or as broad as a region (think state) or an entire country. By determining how precise you want your geographical locations to be and monitoring for new locations that haven't previously accessed your environment, you can detect adversaries as they begin to probe your environment. Since there are legitimate reasons for activities from unfamiliar locations, this is not a standalone indicator. Nevertheless, location can be a relevant piece of information that you may wish to investigate further. @@ -75,7 +86,7 @@ version = 1 references = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf", "https://redlock.io/blog/cryptojacking-tesla"] maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - Detect API activity from users without MFA - Rule", "ESCU - Detect AWS API Activities From Unapproved Accounts - Rule", "ESCU - Detect new API calls from user roles - Rule", "ESCU - Detect Spike in AWS API Activity - Rule", "ESCU - Detect Spike in Security Group Activity - Rule", "ESCU - Investigate AWS User Activities by user field - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Detect API activity from users without MFA - Rule", "ESCU - Detect Spike in AWS API Activity - Rule", "ESCU - Detect AWS API Activities From Unapproved Accounts - Rule", "ESCU - Detect new API calls from user roles - Rule", "ESCU - Detect Spike in Security Group Activity - Rule", "ESCU - Investigate AWS User Activities by user field - Response Task", "ESCU - Get Notable History - Response Task"] description = Detect and investigate dormant user accounts for your AWS environment that have become active again. Because inactive and ad-hoc accounts are common attack targets, it's critical to enable governance within your environment. narrative = It seems obvious that it is critical to monitor and control the users who have access to your cloud infrastructure. Nevertheless, it's all too common for enterprises to lose track of ad-hoc accounts, leaving their servers vulnerable to attack. In fact, this was the very oversight that led to Tesla's cryptojacking attack in February, 2018.\ In addition to compromising the security of your data, when bad actors leverage your compute resources, it can incur monumental costs, since you will be billed for any new EC2 instances and increased bandwidth usage. \ @@ -89,7 +100,7 @@ version = 1 references = ["https://github.com/SpiderLabs/owasp-modsecurity-crs/blob/v3.2/dev/rules/REQUEST-944-APPLICATION-ATTACK-JAVA.conf"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}] spec_version = 3 -searches = ["ESCU - Suspicious Java Classes - Rule", "ESCU - Unusually Long Content-Type Length - Rule", "ESCU - Web Servers Executing Suspicious Processes - Rule", "ESCU - Investigate Web POSTs From src - Response Task", "ESCU - Investigate Suspicious Strings in HTTP Header - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Suspicious Java Classes - Rule", "ESCU - Web Servers Executing Suspicious Processes - Rule", "ESCU - Unusually Long Content-Type Length - Rule", "ESCU - Investigate Web POSTs From src - Response Task", "ESCU - Investigate Suspicious Strings in HTTP Header - Response Task", "ESCU - Get Notable History - Response Task"] description = Detect and investigate activities--such as unusually long `Content-Type` length, suspicious java classes and web servers executing suspicious processes--consistent with attempts to exploit Apache Struts vulnerabilities. narrative = In March of 2017, a remote code-execution vulnerability in the Jakarta Multipart parser in Apache Struts, a widely used open-source framework for creating Java web applications, was disclosed and assigned to CVE-2017-5638. About two months later, hackers exploited the flaw to carry out the world's 5th largest data breach. The target, credit giant Equifax, told investigators that it had become aware of the vulnerability two months before the attack. \ The exploit involved manipulating the `Content-Type HTTP` header to execute commands embedded in the header.\ @@ -124,7 +135,7 @@ version = 1 references = ["https://blog.qualys.com/vulnerabilities-research/2021/01/26/cve-2021-3156-heap-based-buffer-overflow-in-sudo-baron-samedit"] maintainers = [{"company": "Splunk", "email": "-", "name": "Shannon Davis"}] spec_version = 3 -searches = ["ESCU - Detect Baron Samedit CVE-2021-3156 - Rule", "ESCU - Detect Baron Samedit CVE-2021-3156 Segfault - Rule", "ESCU - Detect Baron Samedit CVE-2021-3156 via OSQuery - Rule"] +searches = ["ESCU - Detect Baron Samedit CVE-2021-3156 via OSQuery - Rule", "ESCU - Detect Baron Samedit CVE-2021-3156 Segfault - Rule", "ESCU - Detect Baron Samedit CVE-2021-3156 - Rule"] description = Uncover activity consistent with CVE-2021-3156. Discovered by the Qualys Research Team, this vulnerability has been found to affect sudo across multiple Linux distributions (Ubuntu 20.04 and prior, Debian 10 and prior, Fedora 33 and prior). As this vulnerability was committed to code in July 2011, there will be many distributions affected. Successful exploitation of this vulnerability allows any unprivileged user to gain root privileges on the vulnerable host. narrative = A non-privledged user is able to execute the sudoedit command to trigger a buffer overflow. After the successful buffer overflow, they are then able to gain root privileges on the affected host. The conditions needed to be run are a trailing "\" along with shell and edit flags. Monitoring the /var/log directory on Linux hosts using the Splunk Universal Forwarder will allow you to pick up this behavior when using the provided detection. @@ -135,12 +146,23 @@ version = 1 references = ["https://www.zerofox.com/blog/what-is-digital-risk-monitoring/", "https://securingtomorrow.mcafee.com/consumer/family-safety/what-is-typosquatting/", "https://blog.malwarebytes.com/cybercrime/2016/06/explained-typosquatting/"] maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}] spec_version = 3 -searches = ["ESCU - Monitor DNS For Brand Abuse - Rule", "ESCU - Monitor Email For Brand Abuse - Rule", "ESCU - Monitor Web Traffic For Brand Abuse - Rule", "ESCU - Get Email Info - Response Task", "ESCU - Get Emails From Specific Sender - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Monitor DNS For Brand Abuse - Rule", "ESCU - Monitor Web Traffic For Brand Abuse - Rule", "ESCU - Monitor Email For Brand Abuse - Rule", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Get Emails From Specific Sender - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Email Info - Response Task"] description = Detect and investigate activity that may indicate that an adversary is using faux domains to mislead users into interacting with malicious infrastructure. Monitor DNS, email, and web traffic for permutations of your brand name. narrative = While you can educate your users and customers about the risks and threats posed by typosquatting, phishing, and corporate espionage, human error is a persistent fact of life. Of course, your adversaries are all too aware of this reality and will happily leverage it for nefarious purposes whenever possible3phishing with lookalike addresses, embedding faux command-and-control domains in malware, and hosting malicious content on domains that closely mimic your corporate servers. This is where brand monitoring comes in.\ You can use our adaptation of `DNSTwist`, together with the support searches in this Analytic Story, to generate permutations of specified brands and external domains. Splunk can monitor email, DNS requests, and web traffic for these permutations and provide you with early warnings and situational awareness--powerful elements of an effective defense.\ Notable events will include IP addresses, URLs, and user data. Drilling down can provide you with even more actionable intelligence, including likely geographic information, contextual searches to help you scope the problem, and investigative searches. +[analytic_story://Clop Ransomware] +category = Malware +last_updated = 2021-03-17 +version = 1 +references = ["https://www.hhs.gov/sites/default/files/analyst-note-cl0p-tlp-white.pdf", "https://securityaffairs.co/wordpress/115250/data-breach/qualys-clop-ransomware.html", "https://www.darkreading.com/attacks-breaches/qualys-is-the-latest-victim-of-accellion-data-breach/d/d-id/1340323"] +maintainers = [{"company": "Teoderick Contreras, Splunk", "email": "-", "name": "Rod Soto"}] +spec_version = 3 +searches = ["ESCU - High Process Termination Frequency - Rule", "ESCU - Clop Ransomware Known Service Name - Rule", "ESCU - Common Ransomware Extensions - Rule", "ESCU - High File Deletion Frequency - Rule", "ESCU - Process Deleting Its Process File Path - Rule", "ESCU - Resize ShadowStorage volume - Rule", "ESCU - Suspicious wevtutil Usage - Rule", "ESCU - Ransomware Notes bulk creation - Rule", "ESCU - Create Service In Suspicious File Path - Rule", "ESCU - Deleting Shadow Copies - Rule", "ESCU - Clop Common Exec Parameter - Rule", "ESCU - Windows Event Log Cleared - Rule", "ESCU - Common Ransomware Notes - Rule"] +description = Leverage searches that allow you to detect and investigate unusual activities that might relate to the Clop ransomware, including looking for file writes associated with Clope, encrypting network shares, deleting and resizing shadow volume storage, registry key modification, deleting of security logs, and more. +narrative = Clop ransomware campaigns targeting healthcare and other vertical sectors, involve the use of ransomware payloads along with exfiltration of data per HHS bulletin. Malicious actors demand payment for ransome of data and threaten deletion and exposure of exfiltrated data. + [analytic_story://Cloud Cryptomining] category = Cloud Security last_updated = 2019-10-02 @@ -148,7 +170,7 @@ version = 1 references = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf"] maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}] spec_version = 3 -searches = ["ESCU - Cloud Compute Instance Created With Previously Unseen Image - Rule", "ESCU - Cloud Compute Instance Created In Previously Unused Region - Rule", "ESCU - Cloud Compute Instance Created With Previously Unseen Instance Type - Rule", "ESCU - Abnormally High Number Of Cloud Instances Launched - Rule", "ESCU - Cloud Compute Instance Created By Previously Unseen User - Rule", "ESCU - Get Notable History - Response Task", "ESCU - AWS Investigate Security Hub alerts by dest - Response Task", "ESCU - Investigate AWS activities via region name - Response Task", "ESCU - Get EC2 Launch Details - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get EC2 Instance Details by instanceId - Response Task"] +searches = ["ESCU - Cloud Compute Instance Created With Previously Unseen Image - Rule", "ESCU - Cloud Compute Instance Created By Previously Unseen User - Rule", "ESCU - Cloud Compute Instance Created In Previously Unused Region - Rule", "ESCU - Abnormally High Number Of Cloud Instances Launched - Rule", "ESCU - Cloud Compute Instance Created With Previously Unseen Instance Type - Rule", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get EC2 Instance Details by instanceId - Response Task", "ESCU - Investigate AWS activities via region name - Response Task", "ESCU - AWS Investigate Security Hub alerts by dest - Response Task", "ESCU - Get EC2 Launch Details - Response Task", "ESCU - Get Notable History - Response Task"] description = Monitor your cloud compute instances for activities related to cryptojacking/cryptomining. New instances that originate from previously unseen regions, users who launch abnormally high numbers of instances, or compute instances started by previously unseen users are just a few examples of potentially malicious behavior. narrative = Cryptomining is an intentionally difficult, resource-intensive business. Its complexity was designed into the process to ensure that the number of blocks mined each day would remain steady. So, it's par for the course that ambitious, but unscrupulous, miners make amassing the computing power of large enterprises--a practice known as cryptojacking--a top priority. \ Cryptojacking has attracted an increasing amount of media attention since its explosion in popularity in the fall of 2017. The attacks have moved from in-browser exploits and mobile phones to enterprise cloud services, such as Amazon Web Services (AWS), Google Cloud Platform (GCP), and Azure. It's difficult to determine exactly how widespread the practice has become, since bad actors continually evolve their ability to escape detection, including employing unlisted endpoints, moderating their CPU usage, and hiding the mining pool's IP address behind a free CDN. \ @@ -162,7 +184,7 @@ version = 1 references = ["https://www.cyberark.com/resources/threat-research-blog/golden-saml-newly-discovered-attack-technique-forges-authentication-to-cloud-apps", "https://www.fireeye.com/content/dam/fireeye-www/blog/pdfs/wp-m-unc2452-2021-000343-01.pdf", "https://us-cert.cisa.gov/ncas/alerts/aa21-008a"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rod Soto"}] spec_version = 3 -searches = ["ESCU - Detect Mimikatz Using Loaded Images - Rule", "ESCU - O365 Excessive SSO logon errors - Rule", "ESCU - Detect Mimikatz Via PowerShell And EventCode 4703 - Rule", "ESCU - O365 Added Service Principal - Rule", "ESCU - AWS SAML Access by Provider User and Principal - Rule", "ESCU - O365 New Federated Domain Added - Rule", "ESCU - Certutil exe certificate extraction - Rule", "ESCU - O365 Add App Role Assignment Grant User - Rule", "ESCU - Registry Keys Used For Privilege Escalation - Rule", "ESCU - Detect Rare Executables - Rule", "ESCU - AWS SAML Update identity provider - Rule"] +searches = ["ESCU - AWS SAML Access by Provider User and Principal - Rule", "ESCU - Registry Keys Used For Privilege Escalation - Rule", "ESCU - O365 New Federated Domain Added - Rule", "ESCU - O365 Excessive SSO logon errors - Rule", "ESCU - Detect Mimikatz Using Loaded Images - Rule", "ESCU - O365 Add App Role Assignment Grant User - Rule", "ESCU - Certutil exe certificate extraction - Rule", "ESCU - Detect Mimikatz Via PowerShell And EventCode 4703 - Rule", "ESCU - AWS SAML Update identity provider - Rule", "ESCU - O365 Added Service Principal - Rule", "ESCU - Detect Rare Executables - Rule"] description = This analytical story addresses events that indicate abuse of cloud federated credentials. These credentials are usually extracted from endpoint desktop or servers specially those servers that provide federation services such as Windows Active Directory Federation Services. Identity Federation relies on objects such as Oauth2 tokens, cookies or SAML assertions in order to provide seamless access between cloud and perimeter environments. If these objects are either hijacked or forged then attackers will be able to pivot into victim's cloud environements. narrative = This story is composed of detection searches based on endpoint that addresses the use of Mimikatz, Escalation of Privileges and Abnormal processes that may indicate the extraction of Federated directory objects such as passwords, Oauth2 tokens, certificates and keys. Cloud environment (AWS, Azure) related events are also addressed in specific cloud environment detection searches. @@ -173,7 +195,7 @@ version = 1 references = ["https://www.cobaltstrike.com/", "https://www.infocyte.com/blog/2020/09/02/cobalt-strike-the-new-favorite-among-thieves/", "https://bluescreenofjeff.com/2017-01-24-how-to-write-malleable-c2-profiles-for-cobalt-strike/", "https://blog.talosintelligence.com/2020/09/coverage-strikes-back-cobalt-strike-paper.html", "https://www.fireeye.com/blog/threat-research/2020/12/unauthorized-access-of-fireeye-red-team-tools.html", "https://github.com/MichaelKoczwara/Awesome-CobaltStrike-Defence", "https://github.com/zer0yu/Awesome-CobaltStrike"] maintainers = [{"company": "Splunk", "email": "-", "name": "Michael Haag"}] spec_version = 3 -searches = ["ESCU - Detect Regsvr32 Application Control Bypass - Rule", "ESCU - Suspicious SearchProtocolHost no Command Line Arguments - Rule", "ESCU - Suspicious MSBuild Rename - Rule", "ESCU - Suspicious DLLHost no Command Line Arguments - Rule", "ESCU - Suspicious Rundll32 no Command Line Arguments - Rule", "ESCU - Suspicious msbuild path - Rule", "ESCU - Suspicious microsoft workflow compiler rename - Rule", "ESCU - Suspicious Rundll32 StartW - Rule", "ESCU - Cobalt Strike Named Pipes - Rule", "ESCU - Suspicious GPUpdate no Command Line Arguments - Rule"] +searches = ["ESCU - Suspicious DLLHost no Command Line Arguments - Rule", "ESCU - Suspicious MSBuild Rename - Rule", "ESCU - Detect Regsvr32 Application Control Bypass - Rule", "ESCU - Suspicious SearchProtocolHost no Command Line Arguments - Rule", "ESCU - Suspicious msbuild path - Rule", "ESCU - Suspicious Rundll32 no Command Line Arguments - Rule", "ESCU - Suspicious Rundll32 StartW - Rule", "ESCU - Suspicious microsoft workflow compiler rename - Rule", "ESCU - Suspicious GPUpdate no Command Line Arguments - Rule", "ESCU - Cobalt Strike Named Pipes - Rule"] description = Cobalt Strike is threat emulation software. Red teams and penetration testers use Cobalt Strike to demonstrate the risk of a breach and evaluate mature security programs. Most recently, Cobalt Strike has become the choice tool by threat groups due to its ease of use and extensibility. narrative = This Analytic Story supports you to detect Tactics, Techniques and Procedures (TTPs) from Cobalt Strike. Cobalt Strike has many ways to be enhanced by using aggressor scripts, malleable C2 profiles, default attack packages, and much more. For endpoint behavior, Cobalt Strike is most commonly identified via named pipes, spawn to processes, and DLL function names. Many additional variables are provided for in memory operation of the beacon implant. On the network, depending on the malleable C2 profile used, it is near infinite in the amount of ways to conceal the C2 traffic with Cobalt Strike. Not every query may be specific to Cobalt Strike the tool, but the methodologies and techniques used by it.\ Splunk Threat Research reviewed all publicly available instances of Malleabe C2 Profiles and generated a list of the most commonly used spawnto and pipenames.\ @@ -193,7 +215,7 @@ version = 1 references = ["https://www.intego.com/mac-security-blog/osxcoldroot-and-the-rat-invasion/", "https://objective-see.com/blog/blog_0x2A.html", "https://www.bleepingcomputer.com/news/security/coldroot-rat-still-undetectable-despite-being-uploaded-on-github-two-years-ago/"] maintainers = [{"company": "Splunk", "email": "-", "name": "Jose Hernandez"}] spec_version = 3 -searches = ["ESCU - Processes Tapping Keyboard Events - Rule", "ESCU - Osquery pack - ColdRoot detection - Rule", "ESCU - Investigate Network Traffic From src ip - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Osquery pack - ColdRoot detection - Rule", "ESCU - Processes Tapping Keyboard Events - Rule", "ESCU - Investigate Network Traffic From src ip - Response Task", "ESCU - Get Notable History - Response Task"] description = Leverage searches that allow you to detect and investigate unusual activities that relate to the ColdRoot Remote Access Trojan that affects MacOS. An example of some of these activities are changing sensative binaries in the MacOS sub-system, detecting process names and executables associated with the RAT, detecting when a keyboard tab is installed on a MacOS machine and more. narrative = Conventional wisdom holds that Apple's MacOS operating system is significantly less vulnerable to attack than Windows machines. While that point is debatable, it is true that attacks against MacOS systems are much less common. However, this fact does not mean that Macs are impervious to breaches. To the contrary, research has shown that that Mac malware is increasing at an alarming rate. According to AV-test, in 2018, there were 86,865 new MacOS malware variants, up from 27,338 the year before—a 31% increase. In contrast, the independent research firm found that new Windows malware had increased from 65.17M to 76.86M during that same period, less than half the rate of growth. The bottom line is that while the numbers look a lot smaller than Windows, it's definitely time to take Mac security more seriously.\ This Analytic Story addresses the ColdRoot remote access trojan (RAT), which was uploaded to Github in 2016, but was still escaping detection by the first quarter of 2018, when a new, more feature-rich variant was discovered masquerading as an Apple audio driver. Among other capabilities, the Pascal-based ColdRoot can heist passwords from users' keychains and remotely control infected machines without detection. In the initial report of his findings, Patrick Wardle, Chief Research Officer for Digita Security, explained that the new ColdRoot RAT could start and kill processes on the breached system, spawn new remote-desktop sessions, take screen captures and assemble them into a live stream of the victim's desktop, and more.\ @@ -206,7 +228,7 @@ version = 1 references = ["https://attack.mitre.org/wiki/Collection", "https://attack.mitre.org/wiki/Technique/T1074"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}] spec_version = 3 -searches = ["ESCU - Email servers sending high volume traffic to hosts - Rule", "ESCU - Email files written outside of the Outlook directory - Rule", "ESCU - Hosts receiving high volume of network traffic from email server - Rule", "ESCU - Suspicious writes to System Volume Information - Rule", "ESCU - Suspicious writes to windows Recycle Bin - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Email servers sending high volume traffic to hosts - Rule", "ESCU - Hosts receiving high volume of network traffic from email server - Rule", "ESCU - Suspicious writes to System Volume Information - Rule", "ESCU - Suspicious writes to windows Recycle Bin - Rule", "ESCU - Email files written outside of the Outlook directory - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Monitor for and investigate activities--such as suspicious writes to the Windows Recycling Bin or email servers sending high amounts of traffic to specific hosts, for example--that may indicate that an adversary is harvesting and exfiltrating sensitive data. narrative = A common adversary goal is to identify and exfiltrate data of value from a target organization. This data may include email conversations and addresses, confidential company information, links to network design/infrastructure, important dates, and so on.\ Attacks are composed of three activities: identification, collection, and staging data for exfiltration. Identification typically involves scanning systems and observing user activity. Collection can involve the transfer of large amounts of data from various repositories. Staging/preparation includes moving data to a central location and compressing (and optionally encoding and/or encrypting) it. All of these activities provide opportunities for defenders to identify their presence. \ @@ -219,7 +241,7 @@ version = 1 references = ["https://attack.mitre.org/wiki/Command_and_Control", "https://searchsecurity.techtarget.com/feature/Command-and-control-servers-The-puppet-masters-that-govern-malware"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}] spec_version = 3 -searches = ["ESCU - DNS Query Length With High Standard Deviation - Rule", "ESCU - Detect Long DNS TXT Record Response - Rule", "ESCU - Excessive DNS Failures - Rule", "ESCU - Protocol or Port Mismatch - Rule", "ESCU - DNS Query Requests Resolved by Unauthorized DNS Servers - Rule", "ESCU - Detect Large Outbound ICMP Packets - Rule", "ESCU - Detection of DNS Tunnels - Rule", "ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - Clients Connecting to Multiple DNS Servers - Rule", "ESCU - DNS Query Length Outliers - MLTK - Rule", "ESCU - Prohibited Network Traffic Allowed - Rule", "ESCU - TOR Traffic - Rule", "ESCU - Detect Spike in blocked Outbound Traffic from your AWS - Rule", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - AWS Network Interface details via resourceId - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - AWS Network ACL Details from ID - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task"] +searches = ["ESCU - Clients Connecting to Multiple DNS Servers - Rule", "ESCU - DNS Query Length With High Standard Deviation - Rule", "ESCU - Detect Spike in blocked Outbound Traffic from your AWS - Rule", "ESCU - Excessive DNS Failures - Rule", "ESCU - DNS Query Length Outliers - MLTK - Rule", "ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - Protocol or Port Mismatch - Rule", "ESCU - Detect Long DNS TXT Record Response - Rule", "ESCU - TOR Traffic - Rule", "ESCU - Detect Large Outbound ICMP Packets - Rule", "ESCU - Prohibited Network Traffic Allowed - Rule", "ESCU - DNS Query Requests Resolved by Unauthorized DNS Servers - Rule", "ESCU - Detection of DNS Tunnels - Rule", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - AWS Network Interface details via resourceId - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - AWS Network ACL Details from ID - Response Task"] description = Detect and investigate tactics, techniques, and procedures leveraged by attackers to establish and operate command and control channels. Implants installed by attackers on compromised endpoints use these channels to receive instructions and send data back to the malicious operators. narrative = Threat actors typically architect and implement an infrastructure to use in various ways during the course of their attack campaigns. In some cases, they leverage this infrastructure for scanning and performing reconnaissance activities. In others, they may use this infrastructure to launch actual attacks. One of the most important functions of this infrastructure is to establish servers that will communicate with implants on compromised endpoints. These servers establish a command and control channel that is used to proxy data between the compromised endpoint and the attacker. These channels relay commands from the attacker to the compromised endpoint and the output of those commands back to the attacker.\ Because this communication is so critical for an adversary, they often use techniques designed to hide the true nature of the communications. There are many different techniques used to establish and communicate over these channels. This Analytic Story provides searches that look for a variety of the techniques used for these channels, as well as indications that these channels are active, by examining logs associated with border control devices and network-access control lists. @@ -254,7 +276,7 @@ version = 3 references = ["https://attack.mitre.org/wiki/Technique/T1003", "https://cyberwardog.blogspot.com/2017/03/chronicles-of-threat-hunter-hunting-for.html"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}] spec_version = 3 -searches = ["ESCU - Dump LSASS via procdump Rename - Rule", "ESCU - Detect Mimikatz Using Loaded Images - Rule", "ESCU - Creation of Shadow Copy with wmic and powershell - Rule", "ESCU - Dump LSASS via procdump - Rule", "ESCU - Unsigned Image Loaded by LSASS - Rule", "ESCU - Attempt To Set Default PowerShell Execution Policy To Unrestricted or Bypass - Rule", "ESCU - Creation of Shadow Copy - Rule", "ESCU - Credential Dumping via Copy Command from Shadow Copy - Rule", "ESCU - Ntdsutil Export NTDS - Rule", "ESCU - Detect Credential Dumping through LSASS access - Rule", "ESCU - Creation of lsass Dump with Taskmgr - Rule", "ESCU - Create Remote Thread into LSASS - Rule", "ESCU - Attempted Credential Dump From Registry via Reg exe - Rule", "ESCU - Access LSASS Memory for Dump Creation - Rule", "ESCU - Dump LSASS via comsvcs DLL - Rule", "ESCU - Credential Dumping via Symlink to Shadow Copy - Rule", "ESCU - Investigate Failed Logins for Multiple Destinations - Response Task", "ESCU - Investigate Previous Unseen User - Response Task", "ESCU - Investigate Pass the Hash Attempts - Response Task", "ESCU - Investigate Pass the Ticket Attempts - Response Task"] +searches = ["ESCU - Unsigned Image Loaded by LSASS - Rule", "ESCU - Dump LSASS via procdump Rename - Rule", "ESCU - Create Remote Thread into LSASS - Rule", "ESCU - Credential Dumping via Symlink to Shadow Copy - Rule", "ESCU - Dump LSASS via comsvcs DLL - Rule", "ESCU - Creation of Shadow Copy with wmic and powershell - Rule", "ESCU - Creation of lsass Dump with Taskmgr - Rule", "ESCU - Creation of Shadow Copy - Rule", "ESCU - Detect Credential Dumping through LSASS access - Rule", "ESCU - Detect Mimikatz Using Loaded Images - Rule", "ESCU - Credential Dumping via Copy Command from Shadow Copy - Rule", "ESCU - Ntdsutil Export NTDS - Rule", "ESCU - Attempted Credential Dump From Registry via Reg exe - Rule", "ESCU - Dump LSASS via procdump - Rule", "ESCU - Attempt To Set Default PowerShell Execution Policy To Unrestricted or Bypass - Rule", "ESCU - Access LSASS Memory for Dump Creation - Rule", "ESCU - Investigate Pass the Ticket Attempts - Response Task", "ESCU - Investigate Previous Unseen User - Response Task", "ESCU - Investigate Failed Logins for Multiple Destinations - Response Task", "ESCU - Investigate Pass the Hash Attempts - Response Task"] description = Uncover activity consistent with credential dumping, a technique wherein attackers compromise systems and attempt to obtain and exfiltrate passwords. The threat actors use these pilfered credentials to further escalate privileges and spread throughout a target environment. The included searches in this Analytic Story are designed to identify attempts to credential dumping. narrative = Credential dumping—gathering credentials from a target system, often hashed or encrypted—is a common attack technique. Even though the credentials may not be in plain text, an attacker can still exfiltrate the data and set to cracking it offline, on their own systems. The threat actors target a variety of sources to extract them, including the Security Accounts Manager (SAM), Local Security Authority (LSA), NTDS from Domain Controllers, or the Group Policy Preference (GPP) files.\ Once attackers obtain valid credentials, they use them to move throughout a target network with ease, discovering new systems and identifying assets of interest. Credentials obtained in this manner typically include those of privileged users, which may provide access to more sensitive information and system operations.\ @@ -267,7 +289,7 @@ version = 2 references = ["https://www.us-cert.gov/ncas/alerts/TA18-074A"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}] spec_version = 3 -searches = ["ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - Processes launching netsh - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Suspicious Reg exe Process - Rule", "ESCU - Sc exe Manipulating Windows Services - Rule", "ESCU - Detect New Local Admin account - Rule", "ESCU - Detect Outbound SMB Traffic - Rule", "ESCU - Single Letter Process On Endpoint - Rule", "ESCU - Scheduled Task Deleted Or Created via CMD - Rule", "ESCU - Create local admin accounts using net exe - Rule", "ESCU - Malicious PowerShell Process - Execution Policy Bypass - Rule", "ESCU - SMB Traffic Spike - Rule", "ESCU - First time seen command line argument - Rule", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Process File Activity - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Parent Process Info - Response Task"] +searches = ["ESCU - Sc exe Manipulating Windows Services - Rule", "ESCU - SMB Traffic Spike - Rule", "ESCU - Detect New Local Admin account - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - Detect Outbound SMB Traffic - Rule", "ESCU - Create local admin accounts using net exe - Rule", "ESCU - Scheduled Task Deleted Or Created via CMD - Rule", "ESCU - Single Letter Process On Endpoint - Rule", "ESCU - Suspicious Reg exe Process - Rule", "ESCU - First time seen command line argument - Rule", "ESCU - Malicious PowerShell Process - Execution Policy Bypass - Rule", "ESCU - Processes launching netsh - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Get Process File Activity - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Monitor for suspicious activities associated with DHS Technical Alert US-CERT TA18-074A. Some of the activities that adversaries used in these compromises included spearfishing attacks, malware, watering-hole domains, many and more. narrative = The frequency of nation-state cyber attacks has increased significantly over the last decade. Employing numerous tactics and techniques, these attacks continue to escalate in complexity. \ There is a wide range of motivations for these state-sponsored hacks, including stealing valuable corporate, military, or diplomatic dataѿall of which could confer advantages in various arenas. They may also target critical infrastructure. \ @@ -293,7 +315,7 @@ version = 1 references = ["https://www.fireeye.com/blog/threat-research/2017/09/apt33-insights-into-iranian-cyber-espionage.html", "https://umbrella.cisco.com/blog/2013/04/15/on-the-trail-of-malicious-dynamic-dns-domains/", "http://www.noip.com/blog/2014/07/11/dynamic-dns-can-use-2/", "https://www.splunk.com/blog/2015/08/04/detecting-dynamic-dns-domains-in-splunk.html"] maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - DNS record changed - Rule", "ESCU - Clients Connecting to Multiple DNS Servers - Rule", "ESCU - DNS Query Requests Resolved by Unauthorized DNS Servers - Rule", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - DNS Hijack Enrichment - Response Task"] +searches = ["ESCU - Clients Connecting to Multiple DNS Servers - Rule", "ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - DNS record changed - Rule", "ESCU - DNS Query Requests Resolved by Unauthorized DNS Servers - Rule", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - DNS Hijack Enrichment - Response Task"] description = Secure your environment against DNS hijacks with searches that help you detect and investigate unauthorized changes to DNS records. narrative = Dubbed the Achilles heel of the Internet (see https://www.f5.com/labs/articles/threat-intelligence/dns-is-still-the-achilles-heel-of-the-internet-25613), DNS plays a critical role in routing web traffic but is notoriously vulnerable to attack. One reason is its distributed nature. It relies on unstructured connections between millions of clients and servers over inherently insecure protocols.\ The gravity and extent of the importance of securing DNS from attacks is undeniable. The fallout of compromised DNS can be disastrous. Not only can hackers bring down an entire business, they can intercept confidential information, emails, and login credentials, as well. \ @@ -323,10 +345,21 @@ version = 1 references = ["https://www.cisecurity.org/controls/data-protection/", "https://www.sans.org/reading-room/whitepapers/dns/splunk-detect-dns-tunneling-37022", "https://umbrella.cisco.com/blog/2013/04/15/on-the-trail-of-malicious-dynamic-dns-domains/"] maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - Detection of DNS Tunnels - Rule", "ESCU - Detect USB device insertion - Rule", "ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task"] +searches = ["ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - Detect USB device insertion - Rule", "ESCU - Detection of DNS Tunnels - Rule", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Fortify your data-protection arsenal--while continuing to ensure data confidentiality and integrity--with searches that monitor for and help you investigate possible signs of data exfiltration. narrative = Attackers can leverage a variety of resources to compromise or exfiltrate enterprise data. Common exfiltration techniques include remote-access channels via low-risk, high-payoff active-collections operations and close-access operations using insiders and removable media. While this Analytic Story is not a comprehensive listing of all the methods by which attackers can exfiltrate data, it provides a useful starting point. +[analytic_story://Deobfuscate-Decode Files or Information] +category = Adversary Tactics +last_updated = 2021-03-24 +version = 1 +references = ["https://attack.mitre.org/techniques/T1140/"] +maintainers = [{"company": "Splunk", "email": "-", "name": "Michael Haag"}] +spec_version = 3 +searches = ["ESCU - CertUtil With Decode Argument - Rule"] +description = Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis. +narrative = An example of obfuscated files is `Certutil.exe` usage to encode a portable executable to a certificate file, which is base64 encoded, to hide the originating file. There are many utilities cross-platform to encode using XOR, using compressed .cab files to hide contents and scripting languages that may perform similar native Windows tasks. Triaging an event related will require the capability to review related process events and file modifications. Using a tool such as CyberChef will assist with identifying the encoding that was used, and potentially assist with decoding the contents. + [analytic_story://Detect Zerologon Attack] category = Adversary Tactics last_updated = 2020-09-18 @@ -334,7 +367,7 @@ version = 1 references = ["https://attack.mitre.org/wiki/Technique/T1003", "https://github.com/SecuraBV/CVE-2020-1472", "https://www.secura.com/blog/zero-logon", "https://nvd.nist.gov/vuln/detail/CVE-2020-1472"] maintainers = [{"company": "Jose Hernandez, Stan Miskowicz, David Dorsey, Shannon Davis Splunk", "email": "-", "name": "Rod Soto"}] spec_version = 3 -searches = ["ESCU - Detect Mimikatz Using Loaded Images - Rule", "ESCU - Detect Computer Changed with Anonymous Account - Rule", "ESCU - Detect Credential Dumping through LSASS access - Rule", "ESCU - Detect Zerologon via Zeek - Rule", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Detect Credential Dumping through LSASS access - Rule", "ESCU - Detect Zerologon via Zeek - Rule", "ESCU - Detect Computer Changed with Anonymous Account - Rule", "ESCU - Detect Mimikatz Using Loaded Images - Rule", "ESCU - Get Notable History - Response Task"] description = Uncover activity related to the execution of Zerologon CVE-2020-11472, a technique wherein attackers target a Microsoft Windows Domain Controller to reset its computer account password. The result from this attack is attackers can now provide themselves high privileges and take over Domain Controller. The included searches in this Analytic Story are designed to identify attempts to reset Domain Controller Computer Account via exploit code remotely or via the use of tool Mimikatz as payload carrier. narrative = This attack is a privilege escalation technique, where attacker targets a Netlogon secure channel connection to a domain controller, using Netlogon Remote Protocol (MS-NRPC). This vulnerability exposes vulnerable Windows Domain Controllers to be targeted via unaunthenticated RPC calls which eventually reset Domain Contoller computer account ($) providing the attacker the opportunity to exfil domain controller credential secrets and assign themselve high privileges that can lead to domain controller and potentially complete network takeover. The detection searches in this Analytic Story use Windows Event viewer events and Sysmon events to detect attack execution, these searches monitor access to the Local Security Authority Subsystem Service (LSASS) process which is an indicator of the use of Mimikatz tool which has bee updated to carry this attack payload. @@ -345,7 +378,7 @@ version = 2 references = ["https://attack.mitre.org/wiki/Technique/T1089", "https://blog.malwarebytes.com/cybercrime/2015/11/vonteera-adware-uses-certificates-to-disable-anti-malware/", "https://www.operationblockbuster.com/wp-content/uploads/2016/02/Operation-Blockbuster-Tools-Report.pdf"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}] spec_version = 3 -searches = ["ESCU - Attempt To Add Certificate To Untrusted Store - Rule", "ESCU - Attempt To Stop Security Service - Rule", "ESCU - Processes launching netsh - Rule", "ESCU - Unload Sysmon Filter Driver - Rule", "ESCU - Suspicious Reg exe Process - Rule", "ESCU - Sc exe Manipulating Windows Services - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Attempt To Add Certificate To Untrusted Store - Rule", "ESCU - Sc exe Manipulating Windows Services - Rule", "ESCU - Attempt To Stop Security Service - Rule", "ESCU - Unload Sysmon Filter Driver - Rule", "ESCU - Suspicious Reg exe Process - Rule", "ESCU - Processes launching netsh - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Looks for activities and techniques associated with the disabling of security tools on a Windows system, such as suspicious `reg.exe` processes, processes launching netsh, and many others. narrative = Attackers employ a variety of tactics in order to avoid detection and operate without barriers. This often involves modifying the configuration of security tools to get around them or explicitly disabling them to prevent them from running. This Analytic Story includes searches that look for activity consistent with attackers attempting to disable various security mechanisms. Such activity may involve monitoring for suspicious registry activity, as this is where much of the configuration for Windows and various other programs reside, or explicitly attempting to shut down security-related services. Other times, attackers attempt various tricks to prevent specific programs from running, such as adding the certificates with which the security tools are signed to a block list (which would prevent them from running). @@ -356,7 +389,7 @@ version = 2 references = ["https://www.fireeye.com/blog/threat-research/2017/09/apt33-insights-into-iranian-cyber-espionage.html", "https://umbrella.cisco.com/blog/2013/04/15/on-the-trail-of-malicious-dynamic-dns-domains/", "http://www.noip.com/blog/2014/07/11/dynamic-dns-can-use-2/", "https://www.splunk.com/blog/2015/08/04/detecting-dynamic-dns-domains-in-splunk.html"] maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - Detect web traffic to dynamic domain providers - Rule", "ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - Detect web traffic to dynamic domain providers - Rule", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Notable History - Response Task"] description = Detect and investigate hosts in your environment that may be communicating with dynamic domain providers. Attackers may leverage these services to help them avoid firewall blocks and deny lists. narrative = Dynamic DNS services (DDNS) are legitimate low-cost or free services that allow users to rapidly update domain resolutions to IP infrastructure. While their usage can be benign, malicious actors can abuse DDNS to host harmful payloads or interactive-command-and-control infrastructure. These attackers will manually update or automate domain resolution changes by routing dynamic domains to IP addresses that circumvent firewall blocks and deny lists and frustrate a network defender's analytic and investigative processes. These searches will look for DNS queries made from within your infrastructure to suspicious dynamic domains and then investigate more deeply, when appropriate. While this list of top-level dynamic domains is not exhaustive, it can be dynamically updated as new suspicious dynamic domains are identified. @@ -367,7 +400,7 @@ version = 1 references = ["https://www.us-cert.gov/ncas/alerts/TA18-201A", "https://www.first.org/resources/papers/conf2017/Advanced-Incident-Detection-and-Threat-Hunting-using-Sysmon-and-Splunk.pdf", "https://www.vkremez.com/2017/05/emotet-banking-trojan-malware-analysis.html"] maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Email Attachments With Lots Of Spaces - Rule", "ESCU - Suspicious Email Attachment Extensions - Rule", "ESCU - Prohibited Software On Endpoint - Rule", "ESCU - Detection of tools built by NirSoft - Rule", "ESCU - Detect Rare Executables - Rule", "ESCU - Detect Use of cmd exe to Launch Script Interpreters - Rule", "ESCU - SMB Traffic Spike - Rule", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get History Of Email Sources - Response Task"] +searches = ["ESCU - SMB Traffic Spike - Rule", "ESCU - Suspicious Email Attachment Extensions - Rule", "ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - Detection of tools built by NirSoft - Rule", "ESCU - Detect Use of cmd exe to Launch Script Interpreters - Rule", "ESCU - Detect Rare Executables - Rule", "ESCU - Prohibited Software On Endpoint - Rule", "ESCU - Email Attachments With Lots Of Spaces - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Detect rarely used executables, specific registry paths that may confer malware survivability and persistence, instances where cmd.exe is used to launch script interpreters, and other indicators that the Emotet financial malware has compromised your environment. narrative = The trojan downloader known as Emotet first surfaced in 2014, when it was discovered targeting the banking industry to steal credentials. However, according to a joint technical alert (TA) issued by three government agencies (https://www.us-cert.gov/ncas/alerts/TA18-201A), Emotet has evolved far beyond those beginnings to become what a ThreatPost article called a threat-delivery service(see https://threatpost.com/emotet-malware-evolves-beyond-banking-to-threat-delivery-service/134342/). For example, in early 2018, Emotet was found to be using its loader function to spread the Quakbot and Ransomware variants. \ According to the TA, the the malware continues to be among the most costly and destructive malware affecting the private and public sectors. Researchers have linked it to the threat group Mealybug, which has also been on the security communitys radar since 2014.\ @@ -391,7 +424,7 @@ version = 1 references = ["https://cloud.google.com/iam/docs/understanding-service-accounts"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rod Soto"}] spec_version = 3 -searches = ["ESCU - GCP Detect accounts with high risk roles by project - Rule", "ESCU - GCP Detect high risk permissions by resource and account - Rule", "ESCU - gcp detect oauth token abuse - Rule", "ESCU - GCP Detect gcploit framework - Rule", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - gcp detect oauth token abuse - Rule", "ESCU - GCP Detect accounts with high risk roles by project - Rule", "ESCU - GCP Detect gcploit framework - Rule", "ESCU - GCP Detect high risk permissions by resource and account - Rule", "ESCU - Get Notable History - Response Task"] description = Track when a user assumes an IAM role in another GCP account to obtain cross-account access to services and resources in that account. Accessing new roles could be an indication of malicious activity. narrative = Google Cloud Platform (GCP) admins manage access to GCP resources and services across the enterprise using GCP Identity and Access Management (IAM) functionality. IAM provides the ability to create and manage GCP users, groups, and roles-each with their own unique set of privileges and defined access to specific resources (such as Compute instances, the GCP Management Console, API, or the command-line interface). Unlike conventional (human) users, IAM roles are potentially assumable by anyone in the organization. They provide users with dynamically created temporary security credentials that expire within a set time period.\ In between the time between when the temporary credentials are issued and when they expire is a period of opportunity, where a user could leverage the temporary credentials to wreak havoc-spin up or remove instances, create new users, elevate privileges, and other malicious activities-throughout the environment.\ @@ -404,7 +437,7 @@ version = 1 references = ["https://www.splunk.com/en_us/blog/security/detecting-hafnium-exchange-server-zero-day-activity-in-splunk.html", "https://www.volexity.com/blog/2021/03/02/active-exploitation-of-microsoft-exchange-zero-day-vulnerabilities/", "https://www.microsoft.com/security/blog/2021/03/02/hafnium-targeting-exchange-servers/", "https://blog.rapid7.com/2021/03/03/rapid7s-insightidr-enables-detection-and-response-to-microsoft-exchange-0-day/"] maintainers = [{"company": "Splunk", "email": "-", "name": "Michael Haag"}] spec_version = 3 -searches = ["ESCU - Dump LSASS via procdump Rename - Rule", "ESCU - Detect Exchange Web Shell - Rule", "ESCU - Dump LSASS via procdump - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - Attempt To Set Default PowerShell Execution Policy To Unrestricted or Bypass - Rule", "ESCU - Ntdsutil Export NTDS - Rule", "ESCU - Unified Messaging Service Spawning a Process - Rule", "ESCU - Detect New Local Admin account - Rule", "ESCU - Email servers sending high volume traffic to hosts - Rule", "ESCU - Nishang PowershellTCPOneLine - Rule", "ESCU - Any Powershell DownloadString - Rule", "ESCU - Malicious PowerShell Process - Connect To Internet With Hidden Window - Rule", "ESCU - Malicious PowerShell Process - Execution Policy Bypass - Rule", "ESCU - Dump LSASS via comsvcs DLL - Rule", "ESCU - W3WP Spawning Shell - Rule"] +searches = ["ESCU - Email servers sending high volume traffic to hosts - Rule", "ESCU - Dump LSASS via procdump Rename - Rule", "ESCU - Detect Exchange Web Shell - Rule", "ESCU - Dump LSASS via comsvcs DLL - Rule", "ESCU - W3WP Spawning Shell - Rule", "ESCU - Detect New Local Admin account - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - Nishang PowershellTCPOneLine - Rule", "ESCU - Any Powershell DownloadString - Rule", "ESCU - Unified Messaging Service Spawning a Process - Rule", "ESCU - Ntdsutil Export NTDS - Rule", "ESCU - Dump LSASS via procdump - Rule", "ESCU - Malicious PowerShell Process - Connect To Internet With Hidden Window - Rule", "ESCU - Attempt To Set Default PowerShell Execution Policy To Unrestricted or Bypass - Rule", "ESCU - Malicious PowerShell Process - Execution Policy Bypass - Rule"] description = HAFNIUM group was identified by Microsoft as exploiting 4 Microsoft Exchange CVEs in the wild - CVE-2021-26855, CVE-2021-26857, CVE-2021-26858 and CVE-2021-27065. narrative = On Tuesday, March 2, 2021, Microsoft released a set of security patches for its mail server, Microsoft Exchange. These patches respond to a group of vulnerabilities known to impact Exchange 2013, 2016, and 2019. It is important to note that an Exchange 2010 security update has also been issued, though the CVEs do not reference that version as being vulnerable.\ While the CVEs do not shed much light on the specifics of the vulnerabilities or exploits, the first vulnerability (CVE-2021-26855) has a remote network attack vector that allows the attacker, a group Microsoft named HAFNIUM, to authenticate as the Exchange server. Three additional vulnerabilities (CVE-2021-26857, CVE-2021-26858, and CVE-2021-27065) were also identified as part of this activity. When chained together along with CVE-2021-26855 for initial access, the attacker would have complete control over the Exchange server. This includes the ability to run code as SYSTEM and write to any path on the server.\ @@ -417,7 +450,7 @@ version = 2 references = ["https://www.us-cert.gov/HIDDEN-COBRA-North-Korean-Malicious-Cyber-Activity", "https://www.operationblockbuster.com/wp-content/uploads/2016/02/Operation-Blockbuster-Destructive-Malware-Report.pdf"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}] spec_version = 3 -searches = ["ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - DNS Query Length With High Standard Deviation - Rule", "ESCU - Create or delete windows shares using net exe - Rule", "ESCU - Remote Desktop Network Traffic - Rule", "ESCU - Suspicious File Write - Rule", "ESCU - Detect Outbound SMB Traffic - Rule", "ESCU - DNS Query Length Outliers - MLTK - Rule", "ESCU - Remote Desktop Process Running On System - Rule", "ESCU - SMB Traffic Spike - Rule", "ESCU - First time seen command line argument - Rule", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Outbound Emails to Hidden Cobra Threat Actors - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Investigate Successful Remote Desktop Authentications - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task"] +searches = ["ESCU - SMB Traffic Spike - Rule", "ESCU - DNS Query Length Outliers - MLTK - Rule", "ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - Suspicious File Write - Rule", "ESCU - Remote Desktop Process Running On System - Rule", "ESCU - Create or delete windows shares using net exe - Rule", "ESCU - Detect Outbound SMB Traffic - Rule", "ESCU - Remote Desktop Network Traffic - Rule", "ESCU - First time seen command line argument - Rule", "ESCU - DNS Query Length With High Standard Deviation - Rule", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Investigate Successful Remote Desktop Authentications - Response Task", "ESCU - Get Outbound Emails to Hidden Cobra Threat Actors - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Monitor for and investigate activities, including the creation or deletion of hidden shares and file writes, that may be evidence of infiltration by North Korean government-sponsored cybercriminals. Details of this activity were reported in DHS Report TA-18-149A. narrative = North Korea's government-sponsored "cyber army" has been slowly building momentum and gaining sophistication over the last 15 years or so. As a result, the group's activity, which the US government refers to as "Hidden Cobra," has surreptitiously crept onto the collective radar as a preeminent global threat.\ These state-sponsored actors are thought to be responsible for everything from a hack on a South Korean nuclear plant to an attack on Sony in anticipation of its release of the movie "The Interview" at the end of 2014. They're also notorious for cyberespionage. In recent years, the group seems to be focused on financial crimes, such as cryptojacking.\ @@ -431,10 +464,21 @@ version = 1 references = ["https://blog.malwarebytes.com/cybercrime/2016/09/hosts-file-hijacks/"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}] spec_version = 3 -searches = ["ESCU - Windows hosts file modification - Rule", "ESCU - Clients Connecting to Multiple DNS Servers - Rule", "ESCU - DNS Query Requests Resolved by Unauthorized DNS Servers - Rule", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Clients Connecting to Multiple DNS Servers - Rule", "ESCU - Windows hosts file modification - Rule", "ESCU - DNS Query Requests Resolved by Unauthorized DNS Servers - Rule", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Notable History - Response Task"] description = Detect evidence of tactics used to redirect traffic from a host to a destination other than the one intended--potentially one that is part of an adversary's attack infrastructure. An example is redirecting communications regarding patches and updates or misleading users into visiting a malicious website. narrative = Attackers will often attempt to manipulate client communications for nefarious purposes. In some cases, an attacker may endeavor to modify a local host file to redirect communications with resources (such as antivirus or system-update services) to prevent clients from receiving patches or updates. In other cases, an attacker might use this tactic to have the client connect to a site that looks like the intended site, but instead installs malware or collects information from the victim. Additionally, an attacker may redirect a victim in order to execute a MITM attack and observe communications. +[analytic_story://Ingress Tool Transfer] +category = Adversary Tactics +last_updated = 2021-03-24 +version = 1 +references = ["https://attack.mitre.org/techniques/T1105/"] +maintainers = [{"company": "Splunk", "email": "-", "name": "Michael Haag"}] +spec_version = 3 +searches = ["ESCU - Suspicious Curl Network Connection - Rule", "ESCU - CertUtil Download With URLCache and Split Arguments - Rule", "ESCU - CertUtil Download With VerifyCtl and Split Arguments - Rule"] +description = Adversaries may transfer tools or other files from an external system into a compromised environment. Files may be copied from an external adversary controlled system through the command and control channel to bring tools into the victim network or through alternate protocols with another tool such as FTP. +narrative = Ingress tool transfer is a Technique under tactic Command and Control. Behaviors will include the use of living off the land binaries to download implants or binaries over alternate communication ports. It is imperative to baseline applications on endpoints to understand what generates network activity, to where, and what is its native behavior. These utilities, when abused, will write files to disk in world writeable paths.\ During triage, review the reputation of the remote public destination IP or domain. Capture any files written to disk and perform analysis. Review other parrallel processes for additional behaviors. + [analytic_story://JBoss Vulnerability] category = Vulnerability last_updated = 2017-09-14 @@ -467,7 +511,7 @@ version = 1 references = ["https://github.com/splunk/cloud-datamodel-security-research"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rod Soto"}] spec_version = 3 -searches = ["ESCU - Kubernetes Azure scan fingerprint - Rule", "ESCU - GCP Kubernetes cluster pod scan detection - Rule", "ESCU - Kubernetes Azure pod scan fingerprint - Rule", "ESCU - GCP Kubernetes cluster scan detection - Rule", "ESCU - Amazon EKS Kubernetes Pod scan detection - Rule", "ESCU - Amazon EKS Kubernetes cluster scan detection - Rule", "ESCU - GCP Kubernetes activity by src ip - Response Task", "ESCU - Amazon EKS Kubernetes activity by src ip - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Amazon EKS Kubernetes Pod scan detection - Rule", "ESCU - Kubernetes Azure scan fingerprint - Rule", "ESCU - Kubernetes Azure pod scan fingerprint - Rule", "ESCU - GCP Kubernetes cluster pod scan detection - Rule", "ESCU - Amazon EKS Kubernetes cluster scan detection - Rule", "ESCU - GCP Kubernetes cluster scan detection - Rule", "ESCU - GCP Kubernetes activity by src ip - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Amazon EKS Kubernetes activity by src ip - Response Task"] description = This story addresses detection against Kubernetes cluster fingerprint scan and attack by providing information on items such as source ip, user agent, cluster names. narrative = Kubernetes is the most used container orchestration platform, this orchestration platform contains sensitve information and management priviledges of production workloads, microservices and applications. These searches allow operator to detect suspicious unauthenticated requests from the internet to kubernetes cluster. @@ -478,7 +522,7 @@ version = 1 references = ["https://www.splunk.com/en_us/blog/security/approaching-kubernetes-security-detecting-kubernetes-scan-with-splunk.html"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rod Soto"}] spec_version = 3 -searches = ["ESCU - Kubernetes GCP detect sensitive object access - Rule", "ESCU - Kubernetes GCP detect service accounts forbidden failure access - Rule", "ESCU - Kubernetes Azure detect sensitive object access - Rule", "ESCU - Kubernetes AWS detect suspicious kubectl calls - Rule", "ESCU - Kubernetes AWS detect service accounts forbidden failure access - Rule", "ESCU - Kubernetes Azure detect suspicious kubectl calls - Rule", "ESCU - Kubernetes Azure detect service accounts forbidden failure access - Rule", "ESCU - Kubernetes GCP detect suspicious kubectl calls - Rule", "ESCU - AWS EKS Kubernetes cluster sensitive object access - Rule", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Kubernetes GCP detect sensitive object access - Rule", "ESCU - AWS EKS Kubernetes cluster sensitive object access - Rule", "ESCU - Kubernetes AWS detect service accounts forbidden failure access - Rule", "ESCU - Kubernetes GCP detect suspicious kubectl calls - Rule", "ESCU - Kubernetes Azure detect service accounts forbidden failure access - Rule", "ESCU - Kubernetes AWS detect suspicious kubectl calls - Rule", "ESCU - Kubernetes Azure detect sensitive object access - Rule", "ESCU - Kubernetes Azure detect suspicious kubectl calls - Rule", "ESCU - Kubernetes GCP detect service accounts forbidden failure access - Rule", "ESCU - Get Notable History - Response Task"] description = This story addresses detection and response of accounts acccesing Kubernetes cluster sensitive objects such as configmaps or secrets providing information on items such as user user, group. object, namespace and authorization reason. narrative = Kubernetes is the most used container orchestration platform, this orchestration platform contains sensitive objects within its architecture, specifically configmaps and secrets, if accessed by an attacker can lead to further compromise. These searches allow operator to detect suspicious requests against Kubernetes sensitive objects. @@ -489,7 +533,7 @@ version = 1 references = ["https://www.splunk.com/en_us/blog/security/approaching-kubernetes-security-detecting-kubernetes-scan-with-splunk.html"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rod Soto"}] spec_version = 3 -searches = ["ESCU - Kubernetes GCP detect sensitive role access - Rule", "ESCU - Kubernetes Azure detect RBAC authorization by account - Rule", "ESCU - Kubernetes AWS detect sensitive role access - Rule", "ESCU - Kubernetes AWS detect RBAC authorization by account - Rule", "ESCU - Kubernetes Azure detect sensitive role access - Rule", "ESCU - Kubernetes GCP detect RBAC authorizations by account - Rule", "ESCU - Kubernetes Azure detect most active service accounts by pod namespace - Rule", "ESCU - Kubernetes AWS detect most active service accounts by pod - Rule", "ESCU - Kubernetes GCP detect most active service accounts by pod - Rule", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Kubernetes Azure detect sensitive role access - Rule", "ESCU - Kubernetes Azure detect most active service accounts by pod namespace - Rule", "ESCU - Kubernetes GCP detect most active service accounts by pod - Rule", "ESCU - Kubernetes Azure detect RBAC authorization by account - Rule", "ESCU - Kubernetes AWS detect most active service accounts by pod - Rule", "ESCU - Kubernetes AWS detect RBAC authorization by account - Rule", "ESCU - Kubernetes GCP detect RBAC authorizations by account - Rule", "ESCU - Kubernetes GCP detect sensitive role access - Rule", "ESCU - Kubernetes AWS detect sensitive role access - Rule", "ESCU - Get Notable History - Response Task"] description = This story addresses detection and response around Sensitive Role usage within a Kubernetes clusters against cluster resources and namespaces. narrative = Kubernetes is the most used container orchestration platform, this orchestration platform contains sensitive roles within its architecture, specifically configmaps and secrets, if accessed by an attacker can lead to further compromise. These searches allow operator to detect suspicious requests against Kubernetes role activities @@ -500,7 +544,7 @@ version = 2 references = ["https://www.fireeye.com/blog/executive-perspective/2015/08/malware_lateral_move.html"] maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}] spec_version = 3 -searches = ["ESCU - Kerberoasting spn request with RC4 encryption - Rule", "ESCU - Detect Activity Related to Pass the Hash Attacks - Rule", "ESCU - Remote Desktop Network Traffic - Rule", "ESCU - Remote Desktop Process Running On System - Rule", "ESCU - Schtasks scheduling job on remote system - Rule", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Investigate Successful Remote Desktop Authentications - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get History Of Email Sources - Response Task"] +searches = ["ESCU - Remote Desktop Process Running On System - Rule", "ESCU - Kerberoasting spn request with RC4 encryption - Rule", "ESCU - Remote Desktop Network Traffic - Rule", "ESCU - Schtasks scheduling job on remote system - Rule", "ESCU - Detect Activity Related to Pass the Hash Attacks - Rule", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Investigate Successful Remote Desktop Authentications - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Detect and investigate tactics, techniques, and procedures around how attackers move laterally within the enterprise. Because lateral movement can expose the adversary to detection, it should be an important focus for security analysts. narrative = Once attackers gain a foothold within an enterprise, they will seek to expand their accesses and leverage techniques that facilitate lateral movement. Attackers will often spend quite a bit of time and effort moving laterally. Because lateral movement renders an attacker the most vulnerable to detection, it's an excellent focus for detection and investigation.\ Indications of lateral movement can include the abuse of system utilities (such as `psexec.exe`), unauthorized use of remote desktop services, `file/admin$` shares, WMI, PowerShell, pass-the-hash, or the abuse of scheduled tasks. Organizations must be extra vigilant in detecting lateral movement techniques and look for suspicious activity in and around high-value strategic network assets, such as Active Directory, which are often considered the primary target or "crown jewels" to a persistent threat actor.\ @@ -515,7 +559,7 @@ version = 4 references = ["https://blogs.mcafee.com/mcafee-labs/malware-employs-powershell-to-infect-systems/", "https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/"] maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}] spec_version = 3 -searches = ["ESCU - Attempt To Set Default PowerShell Execution Policy To Unrestricted or Bypass - Rule", "ESCU - Malicious PowerShell Process - Encoded Command - Rule", "ESCU - Malicious PowerShell Process - Multiple Suspicious Command-Line Arguments - Rule", "ESCU - Any Powershell DownloadFile - Rule", "ESCU - Malicious PowerShell Process With Obfuscation Techniques - Rule", "ESCU - Any Powershell DownloadString - Rule", "ESCU - Malicious PowerShell Process - Connect To Internet With Hidden Window - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Malicious PowerShell Process - Multiple Suspicious Command-Line Arguments - Rule", "ESCU - Malicious PowerShell Process - Encoded Command - Rule", "ESCU - Any Powershell DownloadString - Rule", "ESCU - Malicious PowerShell Process With Obfuscation Techniques - Rule", "ESCU - Any Powershell DownloadFile - Rule", "ESCU - Malicious PowerShell Process - Connect To Internet With Hidden Window - Rule", "ESCU - Attempt To Set Default PowerShell Execution Policy To Unrestricted or Bypass - Rule", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Attackers are finding stealthy ways "live off the land," leveraging utilities and tools that come standard on the endpoint--such as PowerShell--to achieve their goals without downloading binary files. These searches can help you detect and investigate PowerShell command-line options that may be indicative of malicious intent. narrative = The searches in this Analytic Story monitor for parameters often used for malicious purposes. It is helpful to understand how often the notable events generated by this story occur, as well as the commonalities between some of these events. These factors may provide clues about whether this is a common occurrence of minimal concern or a rare event that may require more extensive investigation. Likewise, it is important to determine whether the issue is restricted to a single user/system or is broader in scope.\ The following factors may assist you in determining whether the event is malicious: \ @@ -535,7 +579,7 @@ version = 1 references = ["https://www.carbonblack.com/2016/03/04/tracking-locky-ransomware-using-carbon-black/"] maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}] spec_version = 3 -searches = ["ESCU - Extended Period Without Successful Netbackup Backups - Rule", "ESCU - Unsuccessful Netbackup backups - Rule", "ESCU - All backup logs for host - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Unsuccessful Netbackup backups - Rule", "ESCU - Extended Period Without Successful Netbackup Backups - Rule", "ESCU - All backup logs for host - Response Task", "ESCU - Get Notable History - Response Task"] description = Address common concerns when monitoring your backup processes. These searches can help you reduce risks from ransomware, device theft, or denial of physical access to a host by backing up data on endpoints. narrative = Having backups is a standard best practice that helps ensure continuity of business operations. Having mature backup processes can also help you reduce the risks of many security-related incidents and streamline your response processes. The detection searches in this Analytic Story will help you identify systems that have backup failures, as well as systems that have not been backed up for an extended period of time. The story will also return the notable event history and all of the backup logs for an endpoint. @@ -571,7 +615,7 @@ version = 2 references = ["https://www.microsoft.com/security/blog/2021/03/04/goldmax-goldfinder-sibot-analyzing-nobelium-malware/", "https://www.fireeye.com/blog/threat-research/2020/12/evasive-attacker-leverages-solarwinds-supply-chain-compromises-with-sunburst-backdoor.html", "https://msrc-blog.microsoft.com/2020/12/13/customer-guidance-on-recent-nation-state-cyber-attacks/"] maintainers = [{"company": "Michael Haag, Splunk", "email": "-", "name": "Patrick Bareiss"}] spec_version = 3 -searches = ["ESCU - Supernova Webshell - Rule", "ESCU - Malicious PowerShell Process - Encoded Command - Rule", "ESCU - Detect Prohibited Applications Spawning cmd exe - Rule", "ESCU - Sc exe Manipulating Windows Services - Rule", "ESCU - Sunburst Correlation DLL and Network Event - Rule", "ESCU - Detect Outbound SMB Traffic - Rule", "ESCU - Detect Rundll32 Inline HTA Execution - Rule", "ESCU - Scheduled Task Deleted Or Created via CMD - Rule", "ESCU - Windows AdFind Exe - Rule", "ESCU - TOR Traffic - Rule", "ESCU - First Time Seen Running Windows Service - Rule", "ESCU - Schtasks scheduling job on remote system - Rule"] +searches = ["ESCU - Malicious PowerShell Process - Encoded Command - Rule", "ESCU - Sc exe Manipulating Windows Services - Rule", "ESCU - Supernova Webshell - Rule", "ESCU - Sunburst Correlation DLL and Network Event - Rule", "ESCU - Windows AdFind Exe - Rule", "ESCU - Detect Prohibited Applications Spawning cmd exe - Rule", "ESCU - Detect Rundll32 Inline HTA Execution - Rule", "ESCU - First Time Seen Running Windows Service - Rule", "ESCU - Detect Outbound SMB Traffic - Rule", "ESCU - TOR Traffic - Rule", "ESCU - Scheduled Task Deleted Or Created via CMD - Rule", "ESCU - Schtasks scheduling job on remote system - Rule"] description = Sunburst is a trojanized updates to SolarWinds Orion IT monitoring and management software. It was discovered by FireEye in December 2020. The actors behind this campaign gained access to numerous public and private organizations around the world. narrative = This Analytic Story supports you to detect Tactics, Techniques and Procedures (TTPs) of the NOBELIUM Group. The threat actor behind sunburst compromised the SolarWinds.Orion.Core.BusinessLayer.dll, is a SolarWinds digitally-signed component of the Orion software framework that contains a backdoor that communicates via HTTP to third party servers. The detections in this Analytic Story are focusing on the dll loading events, file create events and network events to detect This malware. @@ -582,7 +626,7 @@ version = 1 references = ["https://docs.microsoft.com/en-us/previous-versions/tn-archive/bb490939(v=technet.10)", "https://htmlpreview.github.io/?https://github.com/MatthewDemaske/blogbackup/blob/master/netshell.html", "http://blog.jpcert.or.jp/2016/01/windows-commands-abused-by-attackers.html"] maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - Processes launching netsh - Rule", "ESCU - Processes created by netsh - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Processes created by netsh - Rule", "ESCU - Processes launching netsh - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Detect activities and various techniques associated with the abuse of `netsh.exe`, which can disable local firewall settings or set up a remote connection to a host from an infected system. narrative = It is a common practice for attackers of all types to leverage native Windows tools and functionality to execute commands for malicious reasons. One such tool on Windows OS is `netsh.exe`,a command-line scripting utility that allows you to--either locally or remotely--display or modify the network configuration of a computer that is currently running. `Netsh.exe` can be used to discover and disable local firewall settings. It can also be used to set up a remote connection to a host from an infected system.\ To get started, run the detection search to identify parent processes of `netsh.exe`. @@ -594,7 +638,7 @@ version = 1 references = ["https://i.blackhat.com/USA-20/Thursday/us-20-Bienstock-My-Cloud-Is-APTs-Cloud-Investigating-And-Defending-Office-365.pdf"] maintainers = [{"company": "Splunk", "email": "-", "name": "Patrick Bareiss"}] spec_version = 3 -searches = ["ESCU - O365 Suspicious Rights Delegation - Rule", "ESCU - O365 Disable MFA - Rule", "ESCU - O365 Excessive SSO logon errors - Rule", "ESCU - O365 Suspicious User Email Forwarding - Rule", "ESCU - O365 PST export alert - Rule", "ESCU - O365 Added Service Principal - Rule", "ESCU - O365 New Federated Domain Added - Rule", "ESCU - O365 Add App Role Assignment Grant User - Rule", "ESCU - High Number of Login Failures from a single source - Rule", "ESCU - O365 Bypass MFA via Trusted IP - Rule", "ESCU - O365 Suspicious Admin Email Forwarding - Rule", "ESCU - O365 Excessive Authentication Failures Alert - Rule"] +searches = ["ESCU - O365 PST export alert - Rule", "ESCU - O365 Bypass MFA via Trusted IP - Rule", "ESCU - O365 New Federated Domain Added - Rule", "ESCU - O365 Excessive SSO logon errors - Rule", "ESCU - O365 Suspicious Admin Email Forwarding - Rule", "ESCU - O365 Disable MFA - Rule", "ESCU - O365 Add App Role Assignment Grant User - Rule", "ESCU - O365 Suspicious User Email Forwarding - Rule", "ESCU - O365 Suspicious Rights Delegation - Rule", "ESCU - O365 Added Service Principal - Rule", "ESCU - High Number of Login Failures from a single source - Rule", "ESCU - O365 Excessive Authentication Failures Alert - Rule"] description = This story is focused around detecting Office 365 Attacks. narrative = More and more companies are using Microsofts Office 365 cloud offering. Therefore, we see more and more attacks against Office 365. This story provides various detections for Office 365 attacks. @@ -605,7 +649,7 @@ version = 2 references = ["https://www.symantec.com/blogs/threat-intelligence/orangeworm-targets-healthcare-us-europe-asia", "https://www.infosecurity-magazine.com/news/healthcare-targeted-by-hacker/"] maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}] spec_version = 3 -searches = ["ESCU - Sc exe Manipulating Windows Services - Rule", "ESCU - First Time Seen Running Windows Service - Rule", "ESCU - First time seen command line argument - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - First Time Seen Running Windows Service - Rule", "ESCU - First time seen command line argument - Rule", "ESCU - Sc exe Manipulating Windows Services - Rule", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Detect activities and various techniques associated with the Orangeworm Attack Group, a group that frequently targets the healthcare industry. narrative = In May of 2018, the attack group Orangeworm was implicated for installing a custom backdoor called Trojan.Kwampirs within large international healthcare corporations in the United States, Europe, and Asia. This malware provides the attackers with remote access to the target system, decrypting and extracting a copy of its main DLL payload from its resource section. Before writing the payload to disk, it inserts a randomly generated string into the middle of the decrypted payload in an attempt to evade hash-based detections.\ Awareness of the Orangeworm group first surfaced in January, 2015. It has conducted targeted attacks against related industries, as well, such as pharmaceuticals and healthcare IT solution providers.\ @@ -619,7 +663,7 @@ version = 1 references = ["https://www.fireeye.com/blog/threat-research/2019/04/spear-phishing-campaign-targets-ukraine-government.html"] maintainers = [{"company": "Splunk", "email": "-", "name": "Splunk Research Team"}] spec_version = 3 -searches = ["ESCU - Process Creating LNK file in Suspicious Location - Rule", "ESCU - Detect Oulook exe writing a zip file - Rule", "ESCU - Get Parent Process Info - Response Task"] +searches = ["ESCU - Detect Oulook exe writing a zip file - Rule", "ESCU - Process Creating LNK file in Suspicious Location - Rule", "ESCU - Get Parent Process Info - Response Task"] description = Detect signs of malicious payloads that may indicate that your environment has been breached via a phishing attack. narrative = Despite its simplicity, phishing remains the most pervasive and dangerous cyberthreat. In fact, research shows that as many as [91% of all successful attacks](https://digitalguardian.com/blog/91-percent-cyber-attacks-start-phishing-email-heres-how-protect-against-phishing) are initiated via a phishing email. \ As most people know, these emails use fraudulent domains, [email scraping](https://www.cyberscoop.com/emotet-trojan-phishing-scraping-templates-cofense-geodo/), familiar contact names inserted as senders, and other tactics to lure targets into clicking a malicious link, opening an attachment with a [nefarious payload](https://www.cyberscoop.com/emotet-trojan-phishing-scraping-templates-cofense-geodo/), or entering sensitive personal information that perpetrators may intercept. This attack technique requires a relatively low level of skill and allows adversaries to easily cast a wide net. Worse, because its success relies on the gullibility of humans, it's impossible to completely "automate" it out of your environment. However, you can use ES and ESCU to detect and investigate potentially malicious payloads injected into your environment subsequent to a phishing attack. \ @@ -637,7 +681,7 @@ version = 1 references = ["https://www.infosecurity-magazine.com/news/scope-of-mudcarp-attacks-highlight-1/", "http://blog.amossys.fr/badflick-is-not-so-bad.html"] maintainers = [{"company": "iDefense", "email": "-", "name": "iDefense Cyber Espionage Team"}] spec_version = 3 -searches = ["ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Unusually Long Command Line - Rule", "ESCU - Malicious PowerShell Process - Connect To Internet With Hidden Window - Rule", "ESCU - Unusually Long Command Line - MLTK - Rule", "ESCU - First time seen command line argument - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Malicious PowerShell Process - Connect To Internet With Hidden Window - Rule", "ESCU - Unusually Long Command Line - Rule", "ESCU - First time seen command line argument - Rule", "ESCU - Unusually Long Command Line - MLTK - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Monitor your environment for suspicious behaviors that resemble the techniques employed by the MUDCARP threat group. narrative = This story was created as a joint effort between iDefense and Splunk.\ iDefense analysts have recently discovered a Windows executable file that, upon execution, spoofs a decryption tool and then drops a file that appears to be the custom-built javascript backdoor, "Orz," which is associated with the threat actors known as MUDCARP (as well as "temp.Periscope" and "Leviathan"). The file is executed using Wscript.\ @@ -675,7 +719,7 @@ version = 1 references = ["http://www.novetta.com/2015/02/advanced-methods-to-detect-advanced-cyber-attacks-protocol-abuse/"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}] spec_version = 3 -searches = ["ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - Protocol or Port Mismatch - Rule", "ESCU - TOR Traffic - Rule", "ESCU - Prohibited Network Traffic Allowed - Rule", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Parent Process Info - Response Task"] +searches = ["ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - Protocol or Port Mismatch - Rule", "ESCU - Prohibited Network Traffic Allowed - Rule", "ESCU - TOR Traffic - Rule", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Detect instances of prohibited network traffic allowed in the environment, as well as protocols running on non-standard ports. Both of these types of behaviors typically violate policy and can be leveraged by attackers. narrative = A traditional security best practice is to control the ports, protocols, and services allowed within your environment. By limiting the services and protocols to those explicitly approved by policy, administrators can minimize the attack surface. The combined effect allows both network defenders and security controls to focus and not be mired in superfluous traffic or data types. Looking for deviations to policy can identify attacker activity that abuses services and protocols to run on alternate or non-standard ports in the attempt to avoid detection or frustrate forensic analysts. @@ -686,7 +730,7 @@ version = 1 references = ["https://www.carbonblack.com/2017/06/28/carbon-black-threat-research-technical-analysis-petya-notpetya-ransomware/", "https://www.splunk.com/blog/2017/06/27/closing-the-detection-to-mitigation-gap-or-to-petya-or-notpetya-whocares-.html"] maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}] spec_version = 3 -searches = ["ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - USN Journal Deletion - Rule", "ESCU - Schtasks used for forcing a reboot - Rule", "ESCU - Suspicious Scheduled Task from Public Directory - Rule", "ESCU - Common Ransomware Notes - Rule", "ESCU - TOR Traffic - Rule", "ESCU - WBAdmin Delete System Backups - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Unusually Long Command Line - MLTK - Rule", "ESCU - SMB Traffic Spike - Rule", "ESCU - Windows Event Log Cleared - Rule", "ESCU - Spike in File Writes - Rule", "ESCU - BCDEdit Failure Recovery Modification - Rule", "ESCU - Scheduled tasks used in BadRabbit ransomware - Rule", "ESCU - Deleting Shadow Copies - Rule", "ESCU - Suspicious wevtutil Usage - Rule", "ESCU - System Processes Run From Unexpected Locations - Rule", "ESCU - Common Ransomware Extensions - Rule", "ESCU - Remote Process Instantiation via WMI - Rule", "ESCU - Unusually Long Command Line - Rule", "ESCU - Prohibited Network Traffic Allowed - Rule", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Backup Logs For Endpoint - Response Task", "ESCU - Get Sysmon WMI Activity for Host - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get History Of Email Sources - Response Task"] +searches = ["ESCU - SMB Traffic Spike - Rule", "ESCU - Common Ransomware Notes - Rule", "ESCU - Unusually Long Command Line - MLTK - Rule", "ESCU - Scheduled tasks used in BadRabbit ransomware - Rule", "ESCU - Common Ransomware Extensions - Rule", "ESCU - SMB Traffic Spike - MLTK - Rule", "ESCU - Suspicious wevtutil Usage - Rule", "ESCU - Windows Event Log Cleared - Rule", "ESCU - Prohibited Network Traffic Allowed - Rule", "ESCU - USN Journal Deletion - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Schtasks used for forcing a reboot - Rule", "ESCU - Suspicious Scheduled Task from Public Directory - Rule", "ESCU - BCDEdit Failure Recovery Modification - Rule", "ESCU - TOR Traffic - Rule", "ESCU - Deleting Shadow Copies - Rule", "ESCU - Remote Process Instantiation via WMI - Rule", "ESCU - WBAdmin Delete System Backups - Rule", "ESCU - Unusually Long Command Line - Rule", "ESCU - Spike in File Writes - Rule", "ESCU - System Processes Run From Unexpected Locations - Rule", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Sysmon WMI Activity for Host - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Backup Logs For Endpoint - Response Task"] description = Leverage searches that allow you to detect and investigate unusual activities that might relate to ransomware--spikes in SMB traffic, suspicious wevtutil usage, the presence of common ransomware extensions, and system processes run from unexpected locations, and many others. narrative = Ransomware is an ever-present risk to the enterprise, wherein an infected host encrypts business-critical data, holding it hostage until the victim pays the attacker a ransom. There are many types and varieties of ransomware that can affect an enterprise. Attackers can deploy ransomware to enterprises through spearphishing campaigns and driveby downloads, as well as through traditional remote service-based exploitation. In the case of the WannaCry campaign, there was self-propagating wormable functionality that was used to maximize infection. Fortunately, organizations can apply several techniques--such as those in this Analytic Story--to detect and or mitigate the effects of ransomware. @@ -708,7 +752,7 @@ version = 1 references = ["https://www.fireeye.com/blog/executive-perspective/2015/09/the_new_route_toper.html", "https://www.cisco.com/c/en/us/about/security-center/event-response/synful-knock.html"] maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - Detect Port Security Violation - Rule", "ESCU - Detect IPv6 Network Infrastructure Threats - Rule", "ESCU - Detect New Login Attempts to Routers - Rule", "ESCU - Detect Rogue DHCP Server - Rule", "ESCU - Detect ARP Poisoning - Rule", "ESCU - Detect Traffic Mirroring - Rule", "ESCU - Detect Software Download To Network Device - Rule", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Detect IPv6 Network Infrastructure Threats - Rule", "ESCU - Detect Traffic Mirroring - Rule", "ESCU - Detect Software Download To Network Device - Rule", "ESCU - Detect Rogue DHCP Server - Rule", "ESCU - Detect Port Security Violation - Rule", "ESCU - Detect ARP Poisoning - Rule", "ESCU - Detect New Login Attempts to Routers - Rule", "ESCU - Get Notable History - Response Task"] description = Validate the security configuration of network infrastructure and verify that only authorized users and systems are accessing critical assets. Core routing and switching infrastructure are common strategic targets for attackers. narrative = Networking devices, such as routers and switches, are often overlooked as resources that attackers will leverage to subvert an enterprise. Advanced threats actors have shown a proclivity to target these critical assets as a means to siphon and redirect network traffic, flash backdoored operating systems, and implement cryptographic weakened algorithms to more easily decrypt network traffic.\ This Analytic Story helps you gain a better understanding of how your network devices are interacting with your hosts. By compromising your network devices, attackers can obtain direct access to the company's internal infrastructure— effectively increasing the attack surface and accessing private services/data. @@ -720,7 +764,7 @@ version = 1 references = ["https://www.splunk.com/en_us/blog/security/detecting-ryuk-using-splunk-attack-range.html", "https://www.crowdstrike.com/blog/big-game-hunting-with-ryuk-another-lucrative-targeted-ransomware/", "https://us-cert.cisa.gov/ncas/alerts/aa20-302a"] maintainers = [{"company": "Splunk", "email": "-", "name": "Jose Hernandez"}] spec_version = 3 -searches = ["ESCU - Spike in File Writes - Rule", "ESCU - BCDEdit Failure Recovery Modification - Rule", "ESCU - Remote Desktop Network Bruteforce - Rule", "ESCU - Suspicious Scheduled Task from Public Directory - Rule", "ESCU - Windows connhost exe started forcefully - Rule", "ESCU - Remote Desktop Network Traffic - Rule", "ESCU - Windows DisableAntiSpyware Registry - Rule", "ESCU - Ryuk Test Files Detected - Rule", "ESCU - Ryuk Wake on LAN Command - Rule", "ESCU - Common Ransomware Notes - Rule", "ESCU - NLTest Domain Trust Discovery - Rule", "ESCU - Windows Security Account Manager Stopped - Rule", "ESCU - Common Ransomware Extensions - Rule", "ESCU - WBAdmin Delete System Backups - Rule", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Ryuk Test Files Detected - Rule", "ESCU - Common Ransomware Extensions - Rule", "ESCU - Ryuk Wake on LAN Command - Rule", "ESCU - Windows connhost exe started forcefully - Rule", "ESCU - WBAdmin Delete System Backups - Rule", "ESCU - NLTest Domain Trust Discovery - Rule", "ESCU - Windows DisableAntiSpyware Registry - Rule", "ESCU - Suspicious Scheduled Task from Public Directory - Rule", "ESCU - BCDEdit Failure Recovery Modification - Rule", "ESCU - Remote Desktop Network Bruteforce - Rule", "ESCU - Remote Desktop Network Traffic - Rule", "ESCU - Common Ransomware Notes - Rule", "ESCU - Spike in File Writes - Rule", "ESCU - Windows Security Account Manager Stopped - Rule", "ESCU - Get Notable History - Response Task"] description = Leverage searches that allow you to detect and investigate unusual activities that might relate to the Ryuk ransomware, including looking for file writes associated with Ryuk, Stopping Security Access Manager, DisableAntiSpyware registry key modification, suspicious psexec use, and more. narrative = Cybersecurity Infrastructure Security Agency (CISA) released Alert (AA20-302A) on October 28th called “Ransomware Activity Targeting the Healthcare and Public Health Sector.” This alert details TTPs associated with ongoing and possible imminent attacks against the Healthcare sector, and is a joint advisory in coordination with other U.S. Government agencies. The objective of these malicious campaigns is to infiltrate targets in named sectors and to drop ransomware payloads, which will likely cause disruption of service and increase risk of actual harm to the health and safety of patients at hospitals, even with the aggravant of an ongoing COVID-19 pandemic. This document specifically refers to several crimeware exploitation frameworks, emphasizing the use of Ryuk ransomware as payload. The Ryuk ransomware payload is not new. It has been well documented and identified in multiple variants. Payloads need a carrier, and for Ryuk it has often been exploitation frameworks such as Cobalt Strike, or popular crimeware frameworks such as Emotet or Trickbot. @@ -743,7 +787,7 @@ version = 1 references = ["https://www.crowdstrike.com/blog/an-in-depth-analysis-of-samsam-ransomware-and-boss-spider/", "https://nakedsecurity.sophos.com/2018/07/31/samsam-the-almost-6-million-ransomware/", "https://thehackernews.com/2018/07/samsam-ransomware-attacks.html"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}] spec_version = 3 -searches = ["ESCU - Spike in File Writes - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - Remote Desktop Network Bruteforce - Rule", "ESCU - Detect malicious requests to exploit JBoss servers - Rule", "ESCU - Deleting Shadow Copies - Rule", "ESCU - Remote Desktop Network Traffic - Rule", "ESCU - Prohibited Software On Endpoint - Rule", "ESCU - Samsam Test File Write - Rule", "ESCU - Batch File Write to System32 - Rule", "ESCU - Detect attackers scanning for vulnerable JBoss servers - Rule", "ESCU - Common Ransomware Notes - Rule", "ESCU - Common Ransomware Extensions - Rule", "ESCU - File with Samsam Extension - Rule", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Backup Logs For Endpoint - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Investigate Successful Remote Desktop Authentications - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get History Of Email Sources - Response Task"] +searches = ["ESCU - Detect malicious requests to exploit JBoss servers - Rule", "ESCU - Detect attackers scanning for vulnerable JBoss servers - Rule", "ESCU - Common Ransomware Extensions - Rule", "ESCU - Detect PsExec With accepteula Flag - Rule", "ESCU - File with Samsam Extension - Rule", "ESCU - Samsam Test File Write - Rule", "ESCU - Batch File Write to System32 - Rule", "ESCU - Prohibited Software On Endpoint - Rule", "ESCU - Remote Desktop Network Bruteforce - Rule", "ESCU - Deleting Shadow Copies - Rule", "ESCU - Remote Desktop Network Traffic - Rule", "ESCU - Common Ransomware Notes - Rule", "ESCU - Spike in File Writes - Rule", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get History Of Email Sources - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Investigate Successful Remote Desktop Authentications - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Backup Logs For Endpoint - Response Task"] description = Leverage searches that allow you to detect and investigate unusual activities that might relate to the SamSam ransomware, including looking for file writes associated with SamSam, RDP brute force attacks, the presence of files with SamSam ransomware extensions, suspicious psexec use, and more. narrative = The first version of the SamSam ransomware (a.k.a. Samas or SamsamCrypt) was launched in 2015 by a group of Iranian threat actors. The malicious software has affected and continues to affect thousands of victims and has raised almost $6M in ransom.\ Although categorized under the heading of ransomware, SamSam campaigns have some importance distinguishing characteristics. Most notable is the fact that conventional ransomware is a numbers game. Perpetrators use a "spray-and-pray" approach with phishing campaigns or other mechanisms, charging a small ransom (typically under $1,000). The goal is to find a large number of victims willing to pay these mini-ransoms, adding up to a lucrative payday. They use relatively simple methods for infecting systems.\ @@ -759,7 +803,7 @@ version = 1 references = ["https://redcanary.com/blog/clipping-silver-sparrows-wings/", "https://www.sentinelone.com/blog/5-things-you-need-to-know-about-silver-sparrow/"] maintainers = [{"company": "Splunk", "email": "-", "name": "Michael Haag"}] spec_version = 3 -searches = ["ESCU - Suspicious Curl Network Connection - Rule", "ESCU - Suspicious PlistBuddy Usage - Rule", "ESCU - Suspicious PlistBuddy Usage via OSquery - Rule", "ESCU - Suspicious SQLite3 LSQuarantine Behavior - Rule"] +searches = ["ESCU - Suspicious PlistBuddy Usage - Rule", "ESCU - Suspicious Curl Network Connection - Rule", "ESCU - Suspicious SQLite3 LSQuarantine Behavior - Rule", "ESCU - Suspicious PlistBuddy Usage via OSquery - Rule"] description = Silver Sparrow, identified by Red Canary Intelligence, is a new forward looking MacOS (Intel and M1) malicious software downloader utilizing JavaScript for execution and a launchAgent to establish persistence. narrative = Silver Sparrow works is a dropper and uses typical persistence mechanisms on a Mac. It is cross platform, covering both Intel and Apple M1 architecture. To this date, no implant has been downloaded for malicious purposes. During installation of the update.pkg or updater.pkg file, the malicious software utilizes JavaScript to generate files and scripts on disk for persistence.These files later download a implant from an S3 bucket every hour. This analytic assists with identifying different types of macOS malware families establishing LaunchAgent persistence. Per SentinelOne source, it is predicted that Silver Sparrow is likely selling itself as a mechanism to 3rd party “affiliates” or pay-per-install (PPI) partners, typically seen as commodity adware/malware. Additional indicators and behaviors may be found within the references. @@ -815,7 +859,7 @@ version = 1 references = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf"] maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - Abnormally High AWS Instances Launched by User - Rule", "ESCU - Abnormally High AWS Instances Terminated by User - Rule", "ESCU - Abnormally High AWS Instances Launched by User - MLTK - Rule", "ESCU - EC2 Instance Started In Previously Unseen Region - Rule", "ESCU - EC2 Instance Started With Previously Unseen User - Rule", "ESCU - Abnormally High AWS Instances Terminated by User - MLTK - Rule", "ESCU - Get Notable History - Response Task", "ESCU - AWS Investigate Security Hub alerts by dest - Response Task", "ESCU - Investigate AWS activities via region name - Response Task", "ESCU - Get EC2 Launch Details - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get EC2 Instance Details by instanceId - Response Task"] +searches = ["ESCU - Abnormally High AWS Instances Terminated by User - MLTK - Rule", "ESCU - Abnormally High AWS Instances Launched by User - Rule", "ESCU - EC2 Instance Started With Previously Unseen User - Rule", "ESCU - EC2 Instance Started In Previously Unseen Region - Rule", "ESCU - Abnormally High AWS Instances Terminated by User - Rule", "ESCU - Abnormally High AWS Instances Launched by User - MLTK - Rule", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get EC2 Instance Details by instanceId - Response Task", "ESCU - Investigate AWS activities via region name - Response Task", "ESCU - AWS Investigate Security Hub alerts by dest - Response Task", "ESCU - Get EC2 Launch Details - Response Task", "ESCU - Get Notable History - Response Task"] description = Use the searches in this Analytic Story to monitor your AWS EC2 instances for evidence of anomalous activity and suspicious behaviors, such as EC2 instances that originate from unusual locations or those launched by previously unseen users (among others). Included investigative searches will help you probe more deeply, when the information warrants it. narrative = AWS CloudTrail is an AWS service that helps you enable governance, compliance, and risk auditing within your AWS account. Actions taken by a user, role, or an AWS service are recorded as events in CloudTrail. It is crucial for a company to monitor events and actions taken in the AWS Console, AWS command-line interface, and AWS SDKs and APIs to ensure that your EC2 instances are not vulnerable to attacks. This Analytic Story identifies suspicious activities in your AWS EC2 instances and helps you respond and investigate those activities. @@ -826,7 +870,7 @@ version = 1 references = ["https://docs.aws.amazon.com/IAM/latest/UserGuide/cloudtrail-integration.html"] maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - Detect AWS Console Login by User from New Country - Rule", "ESCU - Detect new user AWS Console Login - Rule", "ESCU - Detect AWS Console Login by User from New City - Rule", "ESCU - Detect AWS Console Login by User from New Region - Rule", "ESCU - AWS Investigate User Activities By ARN - Response Task"] +searches = ["ESCU - Detect new user AWS Console Login - Rule", "ESCU - Detect AWS Console Login by User from New Country - Rule", "ESCU - Detect AWS Console Login by User from New City - Rule", "ESCU - Detect AWS Console Login by User from New Region - Rule", "ESCU - AWS Investigate User Activities By ARN - Response Task"] description = Monitor your AWS authentication events using your CloudTrail logs. Searches within this Analytic Story will help you stay aware of and investigate suspicious logins. narrative = It is important to monitor and control who has access to your AWS infrastructure. Detecting suspicious logins to your AWS infrastructure will provide good starting points for investigations. Abusive behaviors caused by compromised credentials can lead to direct monetary costs, as you will be billed for any EC2 instances created by the attacker. @@ -837,7 +881,7 @@ version = 2 references = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf", "https://www.tripwire.com/state-of-security/security-data-protection/cloud/public-aws-s3-buckets-writable/"] maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - Detect New Open S3 Buckets over AWS CLI - Rule", "ESCU - Detect S3 access from a new IP - Rule", "ESCU - Detect New Open S3 buckets - Rule", "ESCU - Detect Spike in S3 Bucket deletion - Rule", "ESCU - Get Notable History - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - AWS S3 Bucket details via bucketName - Response Task", "ESCU - Investigate AWS activities via region name - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task"] +searches = ["ESCU - Detect S3 access from a new IP - Rule", "ESCU - Detect New Open S3 Buckets over AWS CLI - Rule", "ESCU - Detect Spike in S3 Bucket deletion - Rule", "ESCU - Detect New Open S3 buckets - Rule", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - AWS S3 Bucket details via bucketName - Response Task", "ESCU - Investigate AWS activities via region name - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - Get Notable History - Response Task"] description = Use the searches in this Analytic Story to monitor your AWS S3 buckets for evidence of anomalous activity and suspicious behaviors, such as detecting open S3 buckets and buckets being accessed from a new IP. The contextual and investigative searches will give you more information, when required. narrative = As cloud computing has exploded, so has the number of creative attacks on virtual environments. And as the number-two cloud-service provider, Amazon Web Services (AWS) has certainly had its share.\ Amazon's "shared responsibility" model dictates that the company has responsibility for the environment outside of the VM and the customer is responsible for the security inside of the S3 container. As such, it's important to stay vigilant for activities that may belie suspicious behavior inside of your environment.\ @@ -850,7 +894,7 @@ version = 1 references = ["https://rhinosecuritylabs.com/aws/hiding-cloudcobalt-strike-beacon-c2-using-amazon-apis/"] maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - Detect Spike in blocked Outbound Traffic from your AWS - Rule", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - AWS Network Interface details via resourceId - Response Task", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - AWS Network ACL Details from ID - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task"] +searches = ["ESCU - Detect Spike in blocked Outbound Traffic from your AWS - Rule", "ESCU - Get Process Information For Port Activity - Response Task", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task", "ESCU - AWS Network Interface details via resourceId - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - AWS Network ACL Details from ID - Response Task"] description = Leverage these searches to monitor your AWS network traffic for evidence of anomalous activity and suspicious behaviors, such as a spike in blocked outbound traffic in your virtual private cloud (VPC). narrative = A virtual private cloud (VPC) is an on-demand managed cloud-computing service that isolates computing resources for each client. Inside the VPC container, the environment resembles a physical network. \ Amazon's VPC service enables you to launch EC2 instances and leverage other Amazon resources. The traffic that flows in and out of this VPC can be controlled via network access-control rules and security groups. Amazon also has a feature called VPC Flow Logs that enables you to log IP traffic going to and from the network interfaces in your VPC. This data is stored using Amazon CloudWatch Logs.\ @@ -864,7 +908,7 @@ version = 1 references = ["https://aws.amazon.com/blogs/security/aws-cloudtrail-now-tracks-cross-account-activity-to-its-origin/", "https://docs.aws.amazon.com/IAM/latest/UserGuide/cloudtrail-integration.html"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}] spec_version = 3 -searches = ["ESCU - Detect AWS Console Login by User from New City - Rule", "ESCU - AWS Cross Account Activity From Previously Unseen Account - Rule", "ESCU - Detect AWS Console Login by New User - Rule", "ESCU - Detect AWS Console Login by User from New Country - Rule", "ESCU - Detect AWS Console Login by User from New Region - Rule", "ESCU - Investigate AWS User Activities by user field - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Detect AWS Console Login by User from New City - Rule", "ESCU - Detect AWS Console Login by New User - Rule", "ESCU - AWS Cross Account Activity From Previously Unseen Account - Rule", "ESCU - Detect AWS Console Login by User from New Country - Rule", "ESCU - Detect AWS Console Login by User from New Region - Rule", "ESCU - Investigate AWS User Activities by user field - Response Task", "ESCU - Get Notable History - Response Task"] description = Monitor your cloud authentication events. Searches within this Analytic Story leverage the recent cloud updates to the Authentication data model to help you stay aware of and investigate suspicious login activity. narrative = It is important to monitor and control who has access to your cloud infrastructure. Detecting suspicious logins will provide good starting points for investigations. Abusive behaviors caused by compromised credentials can lead to direct monetary costs, as you will be billed for any compute activity whether legitimate or otherwise.\ This Analytic Story has data model versions of cloud searches leveraging Authentication data, including those looking for suspicious login activity, and cross-account activity for AWS. @@ -876,7 +920,7 @@ version = 1 references = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf"] maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}] spec_version = 3 -searches = ["ESCU - Abnormally High Number Of Cloud Instances Launched - Rule", "ESCU - Abnormally High Number Of Cloud Instances Destroyed - Rule", "ESCU - Cloud Instance Modified By Previously Unseen User - Rule", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task"] +searches = ["ESCU - Abnormally High Number Of Cloud Instances Destroyed - Rule", "ESCU - Abnormally High Number Of Cloud Instances Launched - Rule", "ESCU - Cloud Instance Modified By Previously Unseen User - Rule", "ESCU - AWS Investigate User Activities By ARN - Response Task", "ESCU - Get All AWS Activity From IP Address - Response Task"] description = Monitor your cloud infrastructure provisioning activities for behaviors originating from unfamiliar or unusual locations. These behaviors may indicate that malicious activities are occurring somewhere within your cloud environment. narrative = Monitoring your cloud infrastructure logs allows you enable governance, compliance, and risk auditing. It is crucial for a company to monitor events and actions taken in the their cloud environments to ensure that your instances are not vulnerable to attacks. This Analytic Story identifies suspicious activities in your cloud compute instances and helps you respond and investigate those activities. @@ -887,7 +931,7 @@ version = 1 references = ["https://d0.awsstatic.com/whitepapers/aws-security-best-practices.pdf"] maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}] spec_version = 3 -searches = ["ESCU - Cloud Provisioning Activity From Previously Unseen City - Rule", "ESCU - Cloud Provisioning Activity From Previously Unseen Region - Rule", "ESCU - Cloud Provisioning Activity From Previously Unseen Country - Rule", "ESCU - Cloud Provisioning Activity From Previously Unseen IP Address - Rule", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Cloud Provisioning Activity From Previously Unseen Region - Rule", "ESCU - Cloud Provisioning Activity From Previously Unseen IP Address - Rule", "ESCU - Cloud Provisioning Activity From Previously Unseen City - Rule", "ESCU - Cloud Provisioning Activity From Previously Unseen Country - Rule", "ESCU - Get Notable History - Response Task"] description = Monitor your cloud infrastructure provisioning activities for behaviors originating from unfamiliar or unusual locations. These behaviors may indicate that malicious activities are occurring somewhere within your cloud environment. narrative = Because most enterprise cloud infrastructure activities originate from familiar geographic locations, monitoring for activity from unknown or unusual regions is an important security measure. This indicator can be especially useful in environments where it is impossible to add specific IPs to an allow list because they vary.\ This Analytic Story was designed to provide you with flexibility in the precision you employ in specifying legitimate geographic regions. It can be as specific as an IP address or a city, or as broad as a region (think state) or an entire country. By determining how precise you want your geographical locations to be and monitoring for new locations that haven't previously accessed your environment, you can detect adversaries as they begin to probe your environment. Since there are legitimate reasons for activities from unfamiliar locations, this is not a standalone indicator. Nevertheless, location can be a relevant piece of information that you may wish to investigate further. @@ -911,7 +955,7 @@ version = 2 references = ["https://attack.mitre.org/wiki/Technique/T1059", "https://www.microsoft.com/en-us/wdsi/threats/macro-malware", "https://www.fireeye.com/content/dam/fireeye-www/services/pdfs/mandiant-apt1-report.pdf"] maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - Unusually Long Command Line - Rule", "ESCU - Detect Prohibited Applications Spawning cmd exe - Rule", "ESCU - Unusually Long Command Line - MLTK - Rule", "ESCU - System Processes Run From Unexpected Locations - Rule", "ESCU - Detect Use of cmd exe to Launch Script Interpreters - Rule", "ESCU - First time seen command line argument - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Detect Prohibited Applications Spawning cmd exe - Rule", "ESCU - Detect Use of cmd exe to Launch Script Interpreters - Rule", "ESCU - Unusually Long Command Line - Rule", "ESCU - First time seen command line argument - Rule", "ESCU - Unusually Long Command Line - MLTK - Rule", "ESCU - System Processes Run From Unexpected Locations - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Leveraging the Windows command-line interface (CLI) is one of the most common attack techniques--one that is also detailed in the MITRE ATT&CK framework. Use this Analytic Story to help you identify unusual or suspicious use of the CLI on Windows systems. narrative = The ability to execute arbitrary commands via the Windows CLI is a primary goal for the adversary. With access to the shell, an attacker can easily run scripts and interact with the target system. Often, attackers may only have limited access to the shell or may obtain access in unusual ways. In addition, malware may execute and interact with the CLI in ways that would be considered unusual and inconsistent with typical user activity. This provides defenders with opportunities to identify suspicious use and investigate, as appropriate. This Analytic Story contains various searches to help identify this suspicious activity, as well as others to aid you in deeper investigation. @@ -922,7 +966,7 @@ version = 1 references = ["http://blogs.splunk.com/2015/10/01/random-words-on-entropy-and-dns/", "http://www.darkreading.com/analytics/security-monitoring/got-malware-three-signs-revealed-in-dns-traffic/d/d-id/1139680", "https://live.paloaltonetworks.com/t5/Threat-Vulnerability-Articles/What-are-suspicious-DNS-queries/ta-p/71454"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}] spec_version = 3 -searches = ["ESCU - DNS Query Length With High Standard Deviation - Rule", "ESCU - Detect Long DNS TXT Record Response - Rule", "ESCU - Excessive DNS Failures - Rule", "ESCU - DNS Query Requests Resolved by Unauthorized DNS Servers - Rule", "ESCU - Detection of DNS Tunnels - Rule", "ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - Clients Connecting to Multiple DNS Servers - Rule", "ESCU - DNS Query Length Outliers - MLTK - Rule", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task"] +searches = ["ESCU - Clients Connecting to Multiple DNS Servers - Rule", "ESCU - DNS Query Length With High Standard Deviation - Rule", "ESCU - Excessive DNS Failures - Rule", "ESCU - DNS Query Length Outliers - MLTK - Rule", "ESCU - Detect hosts connecting to dynamic domain providers - Rule", "ESCU - Detect Long DNS TXT Record Response - Rule", "ESCU - DNS Query Requests Resolved by Unauthorized DNS Servers - Rule", "ESCU - Detection of DNS Tunnels - Rule", "ESCU - Get DNS Server History for a host - Response Task", "ESCU - Get Process Responsible For The DNS Traffic - Response Task", "ESCU - Get DNS traffic ratio - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Attackers often attempt to hide within or otherwise abuse the domain name system (DNS). You can thwart attempts to manipulate this omnipresent protocol by monitoring for these types of abuses. narrative = Although DNS is one of the fundamental underlying protocols that make the Internet work, it is often ignored (perhaps because of its complexity and effectiveness). However, attackers have discovered ways to abuse the protocol to meet their objectives. One potential abuse involves manipulating DNS to hijack traffic and redirect it to an IP address under the attacker's control. This could inadvertently send users intending to visit google.com, for example, to an unrelated malicious website. Another technique involves using the DNS protocol for command-and-control activities with the attacker's malicious code or to covertly exfiltrate data. The searches within this Analytic Story look for these types of abuses. @@ -933,7 +977,7 @@ version = 1 references = ["https://www.splunk.com/blog/2015/06/26/phishing-hits-a-new-level-of-quality/"] maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - Suspicious Email Attachment Extensions - Rule", "ESCU - Monitor Email For Brand Abuse - Rule", "ESCU - Suspicious Email - UBA Anomaly - Rule", "ESCU - Email Attachments With Lots Of Spaces - Rule", "ESCU - Get Email Info - Response Task", "ESCU - Get Emails From Specific Sender - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Email Attachments With Lots Of Spaces - Rule", "ESCU - Monitor Email For Brand Abuse - Rule", "ESCU - Suspicious Email - UBA Anomaly - Rule", "ESCU - Suspicious Email Attachment Extensions - Rule", "ESCU - Get Emails From Specific Sender - Response Task", "ESCU - Get Notable History - Response Task", "ESCU - Get Email Info - Response Task"] description = Email remains one of the primary means for attackers to gain an initial foothold within the modern enterprise. Detect and investigate suspicious emails in your environment with the help of the searches in this Analytic Story. narrative = It is a common practice for attackers of all types to leverage targeted spearphishing campaigns and mass mailers to deliver weaponized email messages and attachments. Fortunately, there are a number of ways to monitor email data in Splunk to detect suspicious content.\ Once a phishing message has been detected, the next steps are to answer the following questions: \ @@ -959,7 +1003,7 @@ version = 2 references = ["https://redcanary.com/blog/introducing-atomictestharnesses/", "https://redcanary.com/blog/windows-registry-attacks-threat-detection/", "https://attack.mitre.org/techniques/T1218/005/", "https://medium.com/@mbromileyDFIR/malware-monday-aebb456356c5"] maintainers = [{"company": "Michael Haag, Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - Suspicious mshta spawn - Rule", "ESCU - Suspicious mshta child process - Rule", "ESCU - Detect mshta renamed - Rule", "ESCU - Detect MSHTA Url in Command Line - Rule", "ESCU - Detect Prohibited Applications Spawning cmd exe - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Detect Rundll32 Inline HTA Execution - Rule", "ESCU - Detect mshta inline hta execution - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Detect mshta renamed - Rule", "ESCU - Detect Prohibited Applications Spawning cmd exe - Rule", "ESCU - Suspicious mshta spawn - Rule", "ESCU - Detect MSHTA Url in Command Line - Rule", "ESCU - Detect Rundll32 Inline HTA Execution - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Suspicious mshta child process - Rule", "ESCU - Detect mshta inline hta execution - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Monitor and detect techniques used by attackers who leverage the mshta.exe process to execute malicious code. narrative = One common adversary tactic is to bypass application control solutions via the mshta.exe process, which loads Microsoft HTML applications (mshtml.dll) with the .hta suffix. In these cases, attackers use the trusted Windows utility to proxy execution of malicious files, whether an .hta application, javascript, or VBScript.\ The searches in this story help you detect and investigate suspicious activity that may indicate that an attacker is leveraging mshta.exe to execute malicious code.\ @@ -982,7 +1026,7 @@ version = 1 references = ["https://attack.mitre.org/wiki/Technique/T1078", "https://owasp.org/www-community/attacks/Credential_stuffing", "https://searchsecurity.techtarget.com/answer/What-is-a-password-spraying-attack-and-how-does-it-work"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}] spec_version = 3 -searches = ["ESCU - Multiple Okta Users With Invalid Credentials From The Same IP - Rule", "ESCU - Okta Account Lockout Events - Rule", "ESCU - Okta Failed SSO Attempts - Rule", "ESCU - Okta User Logins From Multiple Cities - Rule", "ESCU - Investigate Okta Activity by IP Address - Response Task", "ESCU - Investigate User Activities In Okta - Response Task", "ESCU - Investigate Okta Activity by app - Response Task"] +searches = ["ESCU - Okta Account Lockout Events - Rule", "ESCU - Okta User Logins From Multiple Cities - Rule", "ESCU - Okta Failed SSO Attempts - Rule", "ESCU - Multiple Okta Users With Invalid Credentials From The Same IP - Rule", "ESCU - Investigate Okta Activity by app - Response Task", "ESCU - Investigate Okta Activity by IP Address - Response Task", "ESCU - Investigate User Activities In Okta - Response Task"] description = Monitor your Okta environment for suspicious activities. Due to the Covid outbreak, many users are migrating over to leverage cloud services more and more. Okta is a popular tool to manage multiple users and the web-based applications they need to stay productive. The searches in this story will help monitor your Okta environment for suspicious activities and associated user behaviors. narrative = Okta is the leading single sign on (SSO) provider, allowing users to authenticate once to Okta, and from there access a variety of web-based applications. These applications are assigned to users and allow administrators to centrally manage which users are allowed to access which applications. It also provides centralized logging to help understand how the applications are used and by whom. \ While SSO is a major convenience for users, it also provides attackers with an opportunity. If the attacker can gain access to Okta, they can access a variety of applications. As such monitoring the environment is important. \ @@ -995,7 +1039,7 @@ version = 1 references = ["https://attack.mitre.org/techniques/T1218/010/", "https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.010/T1218.010.md", "https://lolbas-project.github.io/lolbas/Binaries/Regsvr32/"] maintainers = [{"company": "Splunk", "email": "-", "name": "Michael Haag"}] spec_version = 3 -searches = ["ESCU - Suspicious Regsvr32 Register Suspicious Path - Rule", "ESCU - Detect Regsvr32 Application Control Bypass - Rule"] +searches = ["ESCU - Detect Regsvr32 Application Control Bypass - Rule", "ESCU - Suspicious Regsvr32 Register Suspicious Path - Rule"] description = Monitor and detect techniques used by attackers who leverage the regsvr32.exe process to execute malicious code. narrative = One common adversary tactic is to bypass application control solutions via the regsvr32.exe process. This particular bypass was popularized with "SquiblyDoo" using the "scrobj.dll" dll to load .sct scriptlets. This technique is still widely used by adversaries to bypass detection and prevention controls. The file extension of the DLL is irrelevant (it may load a .txt file extension for example). The searches in this story help you detect and investigate suspicious activity that may indicate that an adversary is leveraging regsvr32.exe to execute malicious code. Validate execution Determine if regsvr32.exe executed. Validate the OriginalFileName of regsvr32.exe and further PE metadata. If executed outside of c:\windows\system32 or c:\windows\syswow64, it should be highly suspect. Determine if script code was executed with regsvr32. Situational Awareness - The objective of this step is meant to identify suspicious behavioral indicators related to executed of Script code by regsvr32.exe. Parent process. Is the parent process a known LOLBin? Is the parent process an Office Application? Module loads. Is regsvr32 loading any suspicious .DLLs? Unsigned or signed from non-standard paths. Network connections. Any network connections? Review the reputation of the remote IP or domain. Retrieval of Script Code - confirm the executed script code is benign or malicious. @@ -1006,7 +1050,7 @@ version = 1 references = ["https://attack.mitre.org/techniques/T1218/011/", "https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218.011/T1218.011.md", "https://lolbas-project.github.io/lolbas/Binaries/Rundll32"] maintainers = [{"company": "Splunk", "email": "-", "name": "Michael Haag"}] spec_version = 3 -searches = ["ESCU - Suspicious Rundll32 Rename - Rule", "ESCU - Suspicious Rundll32 no Command Line Arguments - Rule", "ESCU - Suspicious Rundll32 dllregisterserver - Rule", "ESCU - Suspicious Rundll32 StartW - Rule", "ESCU - Detect Rundll32 Application Control Bypass - syssetup - Rule", "ESCU - Detect Rundll32 Application Control Bypass - advpack - Rule", "ESCU - Dump LSASS via comsvcs DLL - Rule", "ESCU - Detect Rundll32 Application Control Bypass - setupapi - Rule"] +searches = ["ESCU - Detect Rundll32 Application Control Bypass - syssetup - Rule", "ESCU - Dump LSASS via comsvcs DLL - Rule", "ESCU - Suspicious Rundll32 Rename - Rule", "ESCU - Detect Rundll32 Application Control Bypass - advpack - Rule", "ESCU - Detect Rundll32 Application Control Bypass - setupapi - Rule", "ESCU - Suspicious Rundll32 dllregisterserver - Rule", "ESCU - Suspicious Rundll32 no Command Line Arguments - Rule", "ESCU - Suspicious Rundll32 StartW - Rule"] description = Monitor and detect techniques used by attackers who leverage rundll32.exe to execute arbitrary malicious code. narrative = One common adversary tactic is to bypass application control solutions via the rundll32.exe process. Natively, rundll32.exe will load DLLs and is a great example of a Living off the Land Binary. Rundll32.exe may load malicious DLLs by ordinals, function names or directly. The queries in this story focus on loading default DLLs, syssetup.dll, ieadvpack.dll, advpack.dll and setupapi.dll from disk that may be abused by adversaries. Additionally, two analytics developed to assist with identifying DLLRegisterServer, Start and StartW functions being called. The searches in this story help you detect and investigate suspicious activity that may indicate that an adversary is leveraging rundll32.exe to execute malicious code. @@ -1017,7 +1061,7 @@ version = 2 references = ["https://www.blackhat.com/docs/us-15/materials/us-15-Graeber-Abusing-Windows-Management-Instrumentation-WMI-To-Build-A-Persistent%20Asynchronous-And-Fileless-Backdoor-wp.pdf", "https://www.fireeye.com/blog/threat-research/2017/03/wmimplant_a_wmi_ba.html"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}] spec_version = 3 -searches = ["ESCU - WMI Temporary Event Subscription - Rule", "ESCU - Script Execution via WMI - Rule", "ESCU - Remote Process Instantiation via WMI - Rule", "ESCU - WMI Permanent Event Subscription - Sysmon - Rule", "ESCU - Process Execution via WMI - Rule", "ESCU - WMI Permanent Event Subscription - Rule", "ESCU - Remote WMI Command Attempt - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Sysmon WMI Activity for Host - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Remote WMI Command Attempt - Rule", "ESCU - Remote Process Instantiation via WMI - Rule", "ESCU - Script Execution via WMI - Rule", "ESCU - WMI Permanent Event Subscription - Rule", "ESCU - WMI Temporary Event Subscription - Rule", "ESCU - WMI Permanent Event Subscription - Sysmon - Rule", "ESCU - Process Execution via WMI - Rule", "ESCU - Get Sysmon WMI Activity for Host - Response Task", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Attackers are increasingly abusing Windows Management Instrumentation (WMI), a framework and associated utilities available on all modern Windows operating systems. Because WMI can be leveraged to manage both local and remote systems, it is important to identify the processes executed and the user context within which the activity occurred. narrative = WMI is a Microsoft infrastructure for management data and operations on Windows operating systems. It includes of a set of utilities that can be leveraged to manage both local and remote Windows systems. Attackers are increasingly turning to WMI abuse in their efforts to conduct nefarious tasks, such as reconnaissance, detection of antivirus and virtual machines, code execution, lateral movement, persistence, and data exfiltration. \ The detection searches included in this Analytic Story are used to look for suspicious use of WMI commands that attackers may leverage to interact with remote systems. The searches specifically look for the use of WMI to run processes on remote systems.\ @@ -1030,7 +1074,7 @@ version = 1 references = ["https://redcanary.com/blog/windows-registry-attacks-threat-detection/", "https://attack.mitre.org/wiki/Technique/T1112"] maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - Registry Keys for Creating SHIM Databases - Rule", "ESCU - Remote Registry Key modifications - Rule", "ESCU - Disabling Remote User Account Control - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Monitor Registry Keys for Print Monitors - Rule", "ESCU - Registry Keys Used For Privilege Escalation - Rule", "ESCU - Reg exe used to hide files directories via registry keys - Rule", "ESCU - Suspicious Changes to File Associations - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Registry Keys for Creating SHIM Databases - Rule", "ESCU - Registry Keys Used For Privilege Escalation - Rule", "ESCU - Remote Registry Key modifications - Rule", "ESCU - Suspicious Changes to File Associations - Rule", "ESCU - Disabling Remote User Account Control - Rule", "ESCU - Monitor Registry Keys for Print Monitors - Rule", "ESCU - Reg exe used to hide files directories via registry keys - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Monitor and detect registry changes initiated from remote locations, which can be a sign that an attacker has infiltrated your system. narrative = Attackers are developing increasingly sophisticated techniques for hijacking target servers, while evading detection. One such technique that has become progressively more common is registry modification.\ The registry is a key component of the Windows operating system. It has a hierarchical database called "registry" that contains settings, options, and values for executables. Once the threat actor gains access to a machine, they can use reg.exe to modify their account to obtain administrator-level privileges, maintain persistence, and move laterally within the environment.\ @@ -1043,7 +1087,7 @@ version = 1 references = ["https://blog.rapid7.com/2020/04/02/dispelling-zoom-bugbears-what-you-need-to-know-about-the-latest-zoom-vulnerabilities/", "https://threatpost.com/two-zoom-zero-day-flaws-uncovered/154337/"] maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}] spec_version = 3 -searches = ["ESCU - First Time Seen Child Process of Zoom - Rule", "ESCU - Detect Prohibited Applications Spawning cmd exe - Rule", "ESCU - Get Process File Activity - Response Task"] +searches = ["ESCU - Detect Prohibited Applications Spawning cmd exe - Rule", "ESCU - First Time Seen Child Process of Zoom - Rule", "ESCU - Get Process File Activity - Response Task"] description = Attackers are using Zoom as an vector to increase privileges on a sytems. This story detects new child processes of zoom and provides investigative actions for this detection. narrative = Zoom is a leader in modern enterprise video communications and its usage has increased dramatically with a large amount of the population under stay-at-home orders due to the COVID-19 pandemic. With increased usage has come increased scrutiny and several security flaws have been found with this application on both Windows and macOS systems.\ Current detections focus on finding new child processes of this application on a per host basis. Investigative searches are included to gather information needed during an investigation. @@ -1055,7 +1099,7 @@ version = 1 references = ["https://attack.mitre.org/techniques/T1127/", "https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1218/T1218.md", "https://lolbas-project.github.io/lolbas/Binaries/Microsoft.Workflow.Compiler/"] maintainers = [{"company": "Splunk", "email": "-", "name": "Michael Haag"}] spec_version = 3 -searches = ["ESCU - Suspicious microsoft workflow compiler rename - Rule", "ESCU - Suspicious microsoft workflow compiler usage - Rule"] +searches = ["ESCU - Suspicious microsoft workflow compiler usage - Rule", "ESCU - Suspicious microsoft workflow compiler rename - Rule"] description = Monitor and detect behaviors used by attackers who leverage trusted developer utilities to execute malicious code. narrative = Adversaries may take advantage of trusted developer utilities to proxy execution of malicious payloads. There are many utilities used for software development related tasks that can be used to execute code in various forms to assist in development, debugging, and reverse engineering. These utilities may often be signed with legitimate certificates that allow them to execute on a system and proxy execution of malicious code through a trusted process that effectively bypasses application control solutions.\ The searches in this story help you detect and investigate suspicious activity that may indicate that an adversary is leveraging microsoft.workflow.compiler.exe to execute malicious code. @@ -1067,7 +1111,7 @@ version = 1 references = ["https://attack.mitre.org/techniques/T1127/001/", "https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1127.001/T1127.001.md", "https://github.com/infosecn1nja/MaliciousMacroMSBuild", "https://github.com/xorrior/RandomPS-Scripts/blob/master/Invoke-ExecuteMSBuild.ps1", "https://lolbas-project.github.io/lolbas/Binaries/Msbuild/", "https://github.com/MHaggis/CBR-Queries/blob/master/msbuild.md"] maintainers = [{"company": "Splunk", "email": "-", "name": "Michael Haag"}] spec_version = 3 -searches = ["ESCU - Suspicious MSBuild Rename - Rule", "ESCU - Suspicious MSBuild Spawn - Rule", "ESCU - Suspicious msbuild path - Rule"] +searches = ["ESCU - Suspicious msbuild path - Rule", "ESCU - Suspicious MSBuild Rename - Rule", "ESCU - Suspicious MSBuild Spawn - Rule"] description = Monitor and detect techniques used by attackers who leverage the msbuild.exe process to execute malicious code. narrative = Adversaries may use MSBuild to proxy execution of code through a trusted Windows utility. MSBuild.exe (Microsoft Build Engine) is a software build platform used by Visual Studio and is native to Windows. It handles XML formatted project files that define requirements for loading and building various platforms and configurations.\ The inline task capability of MSBuild that was introduced in .NET version 4 allows for C# code to be inserted into an XML project file. MSBuild will compile and execute the inline task. MSBuild.exe is a signed Microsoft binary, so when it is used this way it can execute arbitrary code and bypass application control defenses that are configured to allow MSBuild.exe execution.\ @@ -1103,7 +1147,7 @@ version = 2 references = ["https://www.fireeye.com/blog/threat-research/2017/08/monitoring-windows-console-activity-part-two.html", "https://www.splunk.com/pdfs/technical-briefs/advanced-threat-detection-and-response-tech-brief.pdf", "https://www.sans.org/reading-room/whitepapers/logging/detecting-security-incidents-windows-workstation-event-logs-34262"] maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - Detect processes used for System Network Configuration Discovery - Rule", "ESCU - Unusually Long Command Line - Rule", "ESCU - Uncommon Processes On Endpoint - Rule", "ESCU - System Processes Run From Unexpected Locations - Rule", "ESCU - Detect Rare Executables - Rule", "ESCU - Unusually Long Command Line - MLTK - Rule", "ESCU - RunDLL Loading DLL By Ordinal - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Uncommon Processes On Endpoint - Rule", "ESCU - Detect processes used for System Network Configuration Discovery - Rule", "ESCU - RunDLL Loading DLL By Ordinal - Rule", "ESCU - Detect Rare Executables - Rule", "ESCU - Unusually Long Command Line - Rule", "ESCU - Unusually Long Command Line - MLTK - Rule", "ESCU - System Processes Run From Unexpected Locations - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Quickly identify systems running new or unusual processes in your environment that could be indicators of suspicious activity. Processes run from unusual locations, those with conspicuously long command lines, and rare executables are all examples of activities that may warrant deeper investigation. narrative = Being able to profile a host's processes within your environment can help you more quickly identify processes that seem out of place when compared to the rest of the population of hosts or asset types.\ This Analytic Story lets you identify processes that are either a) not typically seen running or b) have some sort of suspicious command-line arguments associated with them. This Analytic Story will also help you identify the user running these processes and the associated process activity on the host.\ @@ -1127,7 +1171,7 @@ version = 1 references = ["https://www.fbi.gov/scams-and-safety/common-fraud-schemes/internet-fraud", "https://www.fbi.gov/news/stories/2017-internet-crime-report-released-050718"] maintainers = [{"company": "Splunk", "email": "-", "name": "Jim Apger"}] spec_version = 3 -searches = ["ESCU - Web Fraud - Password Sharing Across Accounts - Rule", "ESCU - Web Fraud - Account Harvesting - Rule", "ESCU - Web Fraud - Anomalous User Clickspeed - Rule", "ESCU - Get Web Session Information via session id - Response Task", "ESCU - Get Emails From Specific Sender - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Web Fraud - Account Harvesting - Rule", "ESCU - Web Fraud - Anomalous User Clickspeed - Rule", "ESCU - Web Fraud - Password Sharing Across Accounts - Rule", "ESCU - Get Emails From Specific Sender - Response Task", "ESCU - Get Web Session Information via session id - Response Task", "ESCU - Get Notable History - Response Task"] description = Monitor your environment for activity consistent with common attack techniques bad actors use when attempting to compromise web servers or other web-related assets. narrative = The Federal Bureau of Investigations (FBI) defines Internet fraud as the use of Internet services or software with Internet access to defraud victims or to otherwise take advantage of them. According to the Bureau, Internet crime schemes are used to steal millions of dollars each year from victims and continue to plague the Internet through various methods. The agency includes phishing scams, data breaches, Denial of Service (DOS) attacks, email account compromise, malware, spoofing, and ransomware in this category.\ These crimes are not the fraud itself, but rather the attack techniques commonly employed by fraudsters in their pursuit of data that enables them to commit malicious actssuch as obtaining and using stolen credit cards. They represent a serious problem that is steadily increasing and not likely to go away anytime soon.\ @@ -1143,7 +1187,7 @@ version = 1 references = ["https://research.checkpoint.com/2020/resolving-your-way-into-domain-admin-exploiting-a-17-year-old-bug-in-windows-dns-servers/", "https://support.microsoft.com/en-au/help/4569509/windows-dns-server-remote-code-execution-vulnerability"] maintainers = [{"company": "Splunk", "email": "-", "name": "Shannon Davis"}] spec_version = 3 -searches = ["ESCU - Detect Windows DNS SIGRed via Zeek - Rule", "ESCU - Detect Windows DNS SIGRed via Splunk Stream - Rule", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Detect Windows DNS SIGRed via Splunk Stream - Rule", "ESCU - Detect Windows DNS SIGRed via Zeek - Rule", "ESCU - Get Notable History - Response Task"] description = Uncover activity consistent with CVE-2020-1350, or SIGRed. Discovered by Checkpoint researchers, this vulnerability affects Windows 2003 to 2019, and is triggered by a malicious DNS response (only affects DNS over TCP). An attacker can use the malicious payload to cause a buffer overflow on the vulnerable system, leading to compromise. The included searches in this Analytic Story are designed to identify the large response payload for SIG and KEY DNS records which can be used for the exploit. narrative = When a client requests a DNS record for a particular domain, that request gets routed first through the client's locally configured DNS server, then to any DNS server(s) configured as forwarders, and then onto the target domain's own DNS server(s). If a attacker wanted to, they could host a malicious DNS server that responds to the initial request with a specially crafted large response (~65KB). This response would flow through to the client's local DNS server, which if not patched for CVE-2020-1350, would cause the buffer overflow. The detection searches in this Analytic Story use wire data to detect the malicious behavior. Searches for Splunk Stream and Zeek are included. The Splunk Stream search correlates across stream:dns and stream:tcp, while the Zeek search correlates across bro:dns:json and bro:conn:json. These correlations are required to pick up both the DNS record types (SIG and KEY) along with the payload size (>65KB). @@ -1154,7 +1198,7 @@ version = 1 references = ["https://attack.mitre.org/wiki/Defense_Evasion"] maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}] spec_version = 3 -searches = ["ESCU - Remote Registry Key modifications - Rule", "ESCU - Disabling Remote User Account Control - Rule", "ESCU - Eventvwr UAC Bypass - Rule", "ESCU - Suspicious Reg exe Process - Rule", "ESCU - FodHelper UAC Bypass - Rule", "ESCU - Hiding Files And Directories With Attrib exe - Rule", "ESCU - Reg exe used to hide files directories via registry keys - Rule", "ESCU - Windows DisableAntiSpyware Registry - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Remote Registry Key modifications - Rule", "ESCU - Windows DisableAntiSpyware Registry - Rule", "ESCU - Disabling Remote User Account Control - Rule", "ESCU - Suspicious Reg exe Process - Rule", "ESCU - FodHelper UAC Bypass - Rule", "ESCU - Reg exe used to hide files directories via registry keys - Rule", "ESCU - Hiding Files And Directories With Attrib exe - Rule", "ESCU - Eventvwr UAC Bypass - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Detect tactics used by malware to evade defenses on Windows endpoints. A few of these include suspicious `reg.exe` processes, files hidden with `attrib.exe` and disabling user-account control, among many others narrative = Defense evasion is a tactic--identified in the MITRE ATT&CK framework--that adversaries employ in a variety of ways to bypass or defeat defensive security measures. There are many techniques enumerated by the MITRE ATT&CK framework that are applicable in this context. This Analytic Story includes searches designed to identify the use of such techniques on Windows platforms. @@ -1165,7 +1209,7 @@ version = 1 references = ["https://blog.malwarebytes.com/cybercrime/2013/12/file-extensions-2/", "https://attack.mitre.org/wiki/Technique/T1042"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}] spec_version = 3 -searches = ["ESCU - Execution of File with Multiple Extensions - Rule", "ESCU - Suspicious Changes to File Associations - Rule", "ESCU - Execution of File With Spaces Before Extension - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Execution of File With Spaces Before Extension - Rule", "ESCU - Suspicious Changes to File Associations - Rule", "ESCU - Execution of File with Multiple Extensions - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Detect and investigate suspected abuse of file extensions and Windows file associations. Some of the malicious behaviors involved may include inserting spaces before file extensions or prepending the file extension with a different one, among other techniques. narrative = Attackers use a variety of techniques to entice users to run malicious code or to persist on an endpoint. One way to accomplish these goals is to leverage file extensions and the mechanism Windows uses to associate files with specific applications. \ Since its earliest days, Windows has used extensions to identify file types. Users have become familiar with these extensions and their application associations. For example, if users see that a file ends in `.doc` or `.docx`, they will assume that it is a Microsoft Word document and expect that double-clicking will open it using `winword.exe`. The user will typically also presume that the `.docx` file is safe. \ @@ -1180,7 +1224,7 @@ version = 2 references = ["https://www.crowdstrike.com/blog/bears-midst-intrusion-democratic-national-committee/", "https://zeltser.com/security-incident-log-review-checklist/", "http://journeyintoir.blogspot.com/2013/01/re-introducing-usnjrnl.html"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}] spec_version = 3 -searches = ["ESCU - Suspicious wevtutil Usage - Rule", "ESCU - Windows Event Log Cleared - Rule", "ESCU - USN Journal Deletion - Rule", "ESCU - Deleting Shadow Copies - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Suspicious wevtutil Usage - Rule", "ESCU - USN Journal Deletion - Rule", "ESCU - Windows Event Log Cleared - Rule", "ESCU - Deleting Shadow Copies - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Adversaries often try to cover their tracks by manipulating Windows logs. Use these searches to help you monitor for suspicious activity surrounding log files--an essential component of an effective defense. narrative = Because attackers often modify system logs to cover their tracks and/or to thwart the investigative process, log monitoring is an industry-recognized best practice. While there are legitimate reasons to manipulate system logs, it is still worthwhile to keep track of who manipulated the logs, when they manipulated them, and in what way they manipulated them (determining which accesses, tools, or utilities were employed). Even if no malicious activity is detected, the knowledge of an attempt to manipulate system logs may be indicative of a broader security risk that should be thoroughly investigated.\ The Analytic Story gives users two different ways to detect manipulation of Windows Event Logs and one way to detect deletion of the Update Sequence Number (USN) Change Journal. The story helps determine the history of the host and the users who have accessed it. Finally, the story aides in investigation by retrieving all the information on the process that caused these events (if the process has been identified). @@ -1192,7 +1236,7 @@ version = 2 references = ["http://www.fuzzysecurity.com/tutorials/19.html", "https://www.fireeye.com/blog/threat-research/2010/07/malware-persistence-windows-registry.html", "http://resources.infosecinstitute.com/common-malware-persistence-mechanisms/", "https://www.fireeye.com/blog/threat-research/2017/05/fin7-shim-databases-persistence.html", "https://www.youtube.com/watch?v=dq2Hv7J9fvk"] maintainers = [{"company": "Splunk", "email": "-", "name": "Bhavin Patel"}] spec_version = 3 -searches = ["ESCU - Shim Database Installation With Suspicious Parameters - Rule", "ESCU - Registry Keys for Creating SHIM Databases - Rule", "ESCU - Remote Registry Key modifications - Rule", "ESCU - Schtasks used for forcing a reboot - Rule", "ESCU - Suspicious Scheduled Task from Public Directory - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Sc exe Manipulating Windows Services - Rule", "ESCU - Certutil exe certificate extraction - Rule", "ESCU - Detect Path Interception By Creation Of program exe - Rule", "ESCU - Monitor Registry Keys for Print Monitors - Rule", "ESCU - Reg exe Manipulating Windows Services Registry Keys - Rule", "ESCU - Hiding Files And Directories With Attrib exe - Rule", "ESCU - Reg exe used to hide files directories via registry keys - Rule", "ESCU - Shim Database File Creation - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Registry Keys for Creating SHIM Databases - Rule", "ESCU - Sc exe Manipulating Windows Services - Rule", "ESCU - Detect Path Interception By Creation Of program exe - Rule", "ESCU - Remote Registry Key modifications - Rule", "ESCU - Shim Database File Creation - Rule", "ESCU - Reg exe Manipulating Windows Services Registry Keys - Rule", "ESCU - Certutil exe certificate extraction - Rule", "ESCU - Shim Database Installation With Suspicious Parameters - Rule", "ESCU - Schtasks used for forcing a reboot - Rule", "ESCU - Suspicious Scheduled Task from Public Directory - Rule", "ESCU - Monitor Registry Keys for Print Monitors - Rule", "ESCU - Reg exe used to hide files directories via registry keys - Rule", "ESCU - Hiding Files And Directories With Attrib exe - Rule", "ESCU - Registry Keys Used For Persistence - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Monitor for activities and techniques associated with maintaining persistence on a Windows system--a sign that an adversary may have compromised your environment. narrative = Maintaining persistence is one of the first steps taken by attackers after the initial compromise. Attackers leverage various custom and built-in tools to ensure survivability and persistent access within a compromised enterprise. This Analytic Story provides searches to help you identify various behaviors used by attackers to maintain persistent access to a Windows environment. @@ -1203,7 +1247,7 @@ version = 2 references = ["https://attack.mitre.org/tactics/TA0004/"] maintainers = [{"company": "Splunk", "email": "-", "name": "David Dorsey"}] spec_version = 3 -searches = ["ESCU - Child Processes of Spoolsv exe - Rule", "ESCU - Registry Keys Used For Privilege Escalation - Rule", "ESCU - Overwriting Accessibility Binaries - Rule", "ESCU - Uncommon Processes On Endpoint - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - Child Processes of Spoolsv exe - Rule", "ESCU - Registry Keys Used For Privilege Escalation - Rule", "ESCU - Uncommon Processes On Endpoint - Rule", "ESCU - Overwriting Accessibility Binaries - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Monitor for and investigate activities that may be associated with a Windows privilege-escalation attack, including unusual processes running on endpoints, modified registry keys, and more. narrative = Privilege escalation is a "land-and-expand" technique, wherein an adversary gains an initial foothold on a host and then exploits its weaknesses to increase his privileges. The motivation is simple: certain actions on a Windows machine--such as installing software--may require higher-level privileges than those the attacker initially acquired. By increasing his privilege level, the attacker can gain the control required to carry out his malicious ends. This Analytic Story provides searches to detect and investigate behaviors that attackers may use to elevate their privileges in your environment. @@ -1214,7 +1258,7 @@ version = 3 references = ["https://attack.mitre.org/wiki/Technique/T1050", "https://attack.mitre.org/wiki/Technique/T1031"] maintainers = [{"company": "Splunk", "email": "-", "name": "Rico Valdez"}] spec_version = 3 -searches = ["ESCU - Reg exe Manipulating Windows Services Registry Keys - Rule", "ESCU - Sc exe Manipulating Windows Services - Rule", "ESCU - First Time Seen Running Windows Service - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] +searches = ["ESCU - First Time Seen Running Windows Service - Rule", "ESCU - Sc exe Manipulating Windows Services - Rule", "ESCU - Reg exe Manipulating Windows Services Registry Keys - Rule", "ESCU - Get Parent Process Info - Response Task", "ESCU - Get Process Info - Response Task", "ESCU - Get Notable History - Response Task"] description = Windows services are often used by attackers for persistence and the ability to load drivers or otherwise interact with the Windows kernel. This Analytic Story helps you monitor your environment for indications that Windows services are being modified or created in a suspicious manner. narrative = The Windows operating system uses a services architecture to allow for running code in the background, similar to a UNIX daemon. Attackers will often leverage Windows services for persistence, hiding in plain sight, seeking the ability to run privileged code that can interact with the kernel. In many cases, attackers will create a new service to host their malicious code. Attackers have also been observed modifying unnecessary or unused services to point to their own code, as opposed to what was intended. In these cases, attackers often use tools to create or modify services in ways that are not typical for most environments, providing opportunities for detection. @@ -1266,6 +1310,36 @@ known_false_positives = This is a strictly behavioral search, so we define "fals This search will fire any time a new region is seen in the **GeoIP** database for any kind of provisioning activity. If you typically do all provisioning from tools inside of your region, there should be few false positives. If you are located in regions where the free version of **MaxMind GeoIP** that ships by default with Splunk has weak resolution (particularly small countries in less economically powerful regions), this may be much less valuable to you. providing_technologies = [] +[savedsearch://ESCU - AWS Create Policy Version to allow all resources - Rule] +type = detection +asset_type = AWS Account +confidence = medium +explanation = This search looks for CloudTrail events where a user created a policy version that allows them to access any resource in their account +how_to_implement = You must install splunk AWS add on and Splunk App for AWS. This search works with cloudtrail logs. +annotations = {"cis20": ["CIS 13"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1078.004"], "nist": ["PR.DS", "PR.AC", "DE.CM"]} +known_false_positives = While this search has no known false positives, it is possible that an AWS admin has legitimately created a policy to allow a user to access all resources. That said, AWS strongly advises against granting full control to all AWS resources +providing_technologies = [] + +[savedsearch://ESCU - AWS CreateAccessKey - Rule] +type = detection +asset_type = AWS Account +confidence = medium +explanation = This search looks for CloudTrail events where a user A who has already permission to create access keys, makes an API call to create access keys for another user B. Attackers have been know to use this technique for Privilege Escalation in case new victim(user B) has more permissions than old victim(user B) +how_to_implement = You must install splunk AWS add on and Splunk App for AWS. This search works with cloudtrail logs. +annotations = {"cis20": ["CIS 13"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1136.003"], "nist": ["PR.DS", "PR.AC", "DE.CM"]} +known_false_positives = While this search has no known false positives, it is possible that an AWS admin has legitimately created keys for another user. +providing_technologies = [] + +[savedsearch://ESCU - AWS CreateLoginProfile - Rule] +type = detection +asset_type = AWS Account +confidence = medium +explanation = This search looks for CloudTrail events where a user A(victim A) creates a login profile for user B, followed by a AWS Console login event from user B from the same src_ip as user B. This correlated event can be indicative of privilege escalation since both events happened from the same src_ip +how_to_implement = You must install splunk AWS add on and Splunk App for AWS. This search works with cloudtrail logs. +annotations = {"cis20": ["CIS 13"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1136.003"], "nist": ["PR.DS", "PR.AC", "DE.CM"]} +known_false_positives = While this search has no known false positives, it is possible that an AWS admin has legitimately created a login profile for another user. +providing_technologies = [] + [savedsearch://ESCU - AWS Cross Account Activity From Previously Unseen Account - Rule] type = detection asset_type = AWS Instance @@ -1346,6 +1420,26 @@ annotations = {"mitre_attack": ["T1078"]} known_false_positives = Updating a SAML provider or creating a new one may not necessarily be malicious however it needs to be closely monitored. providing_technologies = [] +[savedsearch://ESCU - AWS SetDefaultPolicyVersion - Rule] +type = detection +asset_type = AWS Account +confidence = medium +explanation = This search looks for CloudTrail events where a user has set a default policy versions. Attackers have been know to use this technique for Privilege Escalation in case the previous versions of the policy had permissions to access more resources than the current version of the policy +how_to_implement = You must install splunk AWS add on and Splunk App for AWS. This search works with cloudtrail logs. +annotations = {"cis20": ["CIS 13"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1078.004"], "nist": ["PR.DS", "PR.AC", "DE.CM"]} +known_false_positives = While this search has no known false positives, it is possible that an AWS admin has legitimately set a default policy to allow a user to access all resources. That said, AWS strongly advises against granting full control to all AWS resources +providing_technologies = [] + +[savedsearch://ESCU - AWS UpdateLoginProfile - Rule] +type = detection +asset_type = AWS Account +confidence = medium +explanation = This search looks for CloudTrail events where a user A who has already permission to update login profile, makes an API call to update login profile for another user B . Attackers have been know to use this technique for Privilege Escalation in case new victim(user B) has more permissions than old victim(user B) +how_to_implement = You must install splunk AWS add on and Splunk App for AWS. This search works with cloudtrail logs. +annotations = {"cis20": ["CIS 13"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1136.003"], "nist": ["PR.DS", "PR.AC", "DE.CM"]} +known_false_positives = While this search has no known false positives, it is possible that an AWS admin has legitimately created keys for another user. +providing_technologies = [] + [savedsearch://ESCU - Abnormally High AWS Instances Launched by User - Rule] type = detection asset_type = AWS Instance @@ -1480,7 +1574,7 @@ providing_technologies = [] type = detection asset_type = Endpoint confidence = medium -explanation = Attempt to add a certificate to the certificate store +explanation = Attempt To Add Certificate To Untrusted Store how_to_implement = You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. annotations = {"cis20": ["CIS 3", "CIS 5", "CIS 8"], "kill_chain_phases": ["Installation", "Actions on Objectives"], "mitre_attack": ["T1553.004"], "nist": ["PR.PT", "DE.CM", "PR.IP"]} known_false_positives = There may be legitimate reasons for administrators to add a certificate to the untrusted certificate store. In such cases, this will typically be done on a large number of systems. @@ -1536,6 +1630,36 @@ annotations = {"cis20": ["CIS 8"], "kill_chain_phases": ["Delivery"], "mitre_att known_false_positives = It is possible for this search to generate a notable event for a batch file write to a path that includes the string "system32", but is not the actual Windows system directory. As such, you should confirm the path of the batch file identified by the search. In addition, a false positive may be generated by an administrator copying a legitimate batch file in this directory tree. You should confirm that the activity is legitimate and modify the search to add exclusions, as necessary. providing_technologies = [] +[savedsearch://ESCU - CertUtil Download With URLCache and Split Arguments - Rule] +type = detection +asset_type = +confidence = medium +explanation = Certutil.exe may download a file from a remote destination using `-urlcache`. This behavior does require a URL to be passed on the command-line. In addition, `-f` (force) and `-split` (Split embedded ASN.1 elements, and save to files) will be used. It is not entirely common for `certutil.exe` to contact public IP space. However, it is uncommon for `certutil.exe` to write files to world writeable paths.\ During triage, capture any files on disk and review. Review the reputation of the remote IP or domain in question. +how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. +annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1105"]} +known_false_positives = Limited false positives in most environments, however tune as needed based on parent-child relationship or network connection. +providing_technologies = [] + +[savedsearch://ESCU - CertUtil Download With VerifyCtl and Split Arguments - Rule] +type = detection +asset_type = +confidence = medium +explanation = Certutil.exe may download a file from a remote destination using `-VerifyCtl`. This behavior does require a URL to be passed on the command-line. In addition, `-f` (force) and `-split` (Split embedded ASN.1 elements, and save to files) will be used. It is not entirely common for `certutil.exe` to contact public IP space. \ During triage, capture any files on disk and review. Review the reputation of the remote IP or domain in question. Using `-VerifyCtl`, the file will either be written to the current working directory or `%APPDATA%\..\LocalLow\Microsoft\CryptnetUrlCache\Content\`. +how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. +annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1105"]} +known_false_positives = Limited false positives in most environments, however tune as needed based on parent-child relationship or network connection. +providing_technologies = [] + +[savedsearch://ESCU - CertUtil With Decode Argument - Rule] +type = detection +asset_type = +confidence = medium +explanation = CertUtil.exe may be used to `encode` and `decode` a file, including PE and script code. Encoding will convert a file to base64 with `-----BEGIN CERTIFICATE-----` and `-----END CERTIFICATE-----` tags. Malicious usage will include decoding a encoded file that was downloaded. Once decoded, it will be loaded by a parallel process. Note that there are two additional command switches that may be used - `encodehex` and `decodehex`. Similarly, the file will be encoded in HEX and later decoded for further execution. During triage, identify the source of the file being decoded. Review its contents or execution behavior for further analysis. +how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. +annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1140"]} +known_false_positives = Typically seen used to `encode` files, but it is possible to see legitimate use of `decode`. Filter based on parent-child relationship, file paths, endpoint or user. +providing_technologies = [] + [savedsearch://ESCU - Certutil exe certificate extraction - Rule] type = detection asset_type = Endpoint @@ -1568,6 +1692,26 @@ annotations = {"cis20": ["CIS 9", "CIS 12", "CIS 13"], "kill_chain_phases": ["Co known_false_positives = It's possible that an enterprise has more than five DNS servers that are configured in a round-robin rotation. Please customize the search, as appropriate. providing_technologies = [] +[savedsearch://ESCU - Clop Common Exec Parameter - Rule] +type = detection +asset_type = +confidence = medium +explanation = The following analytics are designed to identifies some CLOP ransomware variant that using arguments to execute its main code or feature of its code. In this variant if the parameter is "runrun", CLOP ransomware will try to encrypt files in network shares and if it is "temp.dat", it will try to read from some stream pipe or file start encrypting files within the infected local machines. This technique can be also identified as an anti-sandbox technique to make its code non-responsive since it is waiting for some parameter to execute properly. +how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. +annotations = {"kill_chain_phases": ["Obfuscation"], "mitre_attack": ["T1204"]} +known_false_positives = Operators can execute third party tools using these parameters. +providing_technologies = [] + +[savedsearch://ESCU - Clop Ransomware Known Service Name - Rule] +type = detection +asset_type = +confidence = medium +explanation = This detection is to identify the common service name created by the CLOP ransomware as part of its persistence and high privilege code execution in the infected machine. Ussually CLOP ransomware use StartServiceCtrlDispatcherW API in creating this service entry. +how_to_implement = To successfully implement this search, you need to be ingesting logs with the Service name, Service File Name Service Start type, and Service Type from your endpoints. +annotations = {"kill_chain_phases": ["Privilege Escalation"], "mitre_attack": ["T1543"]} +known_false_positives = unknown +providing_technologies = [] + [savedsearch://ESCU - Cloud API Calls From Previously Unseen User Roles - Rule] type = detection asset_type = AWS Instance @@ -1727,6 +1871,16 @@ annotations = {"cis20": ["CIS 8", "CIS 16"], "kill_chain_phases": ["Actions on O known_false_positives = Other tools can access LSASS for legitimate reasons and generate an event. In these cases, tweaking the search may help eliminate noise. providing_technologies = [] +[savedsearch://ESCU - Create Service In Suspicious File Path - Rule] +type = detection +asset_type = +confidence = medium +explanation = This detection is to identify a creation of "user mode service" where the service file path is located in non-common service folder in windows. +how_to_implement = To successfully implement this search, you need to be ingesting logs with the Service name, Service File Name Service Start type, and Service Type from your endpoints. +annotations = {"kill_chain_phases": ["Privilege Escalation"], "mitre_attack": ["T1569.001, T1569.002"]} +known_false_positives = unknown +providing_technologies = [] + [savedsearch://ESCU - Create local admin accounts using net exe - Rule] type = detection asset_type = Endpoint @@ -2041,7 +2195,7 @@ providing_technologies = [] type = detection asset_type = confidence = medium -explanation = The following query identifies suspicious .aspx created in 3 paths identified by Microsoft as known drop locations for Exchange exploitation related to HAFNIUM group. Paths include: `\HttpProxy\owa\auth\`, `\inetpub\wwwroot\aspnet_client\`, and `\HttpProxy\OAB\`. Upon triage, the suspicious .aspx file will have a randomized name of 8 characters long. Review the file for suspect commands. Identify additional log sources, IIS included, to review source and other potential exploitation. +explanation = The following query identifies suspicious .aspx created in 3 paths identified by Microsoft as known drop locations for Exchange exploitation related to HAFNIUM group. Paths include: `\HttpProxy\owa\auth\`, `\inetpub\wwwroot\aspnet_client\`, and `\HttpProxy\OAB\`. Upon triage, the suspicious .aspx file will likely look obvious on the surface. inspect the contents for script code inside. Identify additional log sources, IIS included, to review source and other potential exploitation. how_to_implement = To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node and `Filesystem` node. annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1505.003"]} known_false_positives = The query is structured in a way that `action` (read, create) is not defined. Review the results of this query, filter, and tune as necessary. It may be necessary to generate this query specific to your endpoint product. @@ -3000,6 +3154,16 @@ annotations = {"cis20": ["CIS 8"], "kill_chain_phases": ["Actions on Objectives" known_false_positives = Some applications and users may legitimately use attrib.exe to interact with the files. providing_technologies = [] +[savedsearch://ESCU - High File Deletion Frequency - Rule] +type = detection +asset_type = +confidence = medium +explanation = This search looks for high frequency of file deletion relative to process name and process id. These events usually happen when the ransomware tries to encrypt the files with the ransomware file extensions and sysmon treat the original files to be deleted as soon it was replace as encrypted data. +how_to_implement = To successfully implement this search, you need to be ingesting logs with the deleted target file name, process name and process id from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. +annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1485"]} +known_false_positives = user may delete bunch of pictures or files in a folder. +providing_technologies = [] + [savedsearch://ESCU - High Number of Login Failures from a single source - Rule] type = detection asset_type = Office 365 @@ -3010,6 +3174,16 @@ annotations = {"cis20": ["CIS 16"], "kill_chain_phases": ["Actions on Objectives known_false_positives = unknown providing_technologies = [] +[savedsearch://ESCU - High Process Termination Frequency - Rule] +type = detection +asset_type = +confidence = medium +explanation = This analytics are designed to indentify a high frequency of process termination on a machine which is a common behavior of ransomware malware before encrypting files. This technique is designed to avoid an exception error while accessing (docs, images, database and etc..) in the infected machine for encryption. +how_to_implement = To successfully implement this search, you need to be ingesting logs with the Image (process full path of terminated process) from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. +annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1486"]} +known_false_positives = admin or user tool that can terminate multiple process. +providing_technologies = [] + [savedsearch://ESCU - Hosts receiving high volume of network traffic from email server - Rule] type = detection asset_type = Endpoint @@ -3487,7 +3661,7 @@ type = detection asset_type = Office 365 confidence = medium explanation = This search detects when an admin configured a forwarding rule for multiple mailboxes to the same destination. -how_to_implement = +how_to_implement = You must install splunk Microsoft Office 365 add-on. This search works with o365:management:activity annotations = {"cis20": ["CIS 16"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1114.003"], "nist": ["DE.DP", "DE.AE"]} known_false_positives = unknown providing_technologies = [] @@ -3497,7 +3671,7 @@ type = detection asset_type = Office 365 confidence = medium explanation = This search detects the assignment of rights to accesss content from another mailbox. This is usually only assigned to a service account. -how_to_implement = +how_to_implement = You must install splunk Microsoft Office 365 add-on. This search works with o365:management:activity annotations = {"cis20": ["CIS 16"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1114.002"], "nist": ["DE.DP", "DE.AE"]} known_false_positives = Service Accounts providing_technologies = [] @@ -3507,7 +3681,7 @@ type = detection asset_type = Office 365 confidence = medium explanation = This search detects when multiple user configured a forwarding rule to the same destination. -how_to_implement = +how_to_implement = You must install splunk Microsoft Office 365 add-on. This search works with o365:management:activity annotations = {"cis20": ["CIS 16"], "kill_chain_phases": ["Actions on Objectives"], "mitre_attack": ["T1114.003"], "nist": ["DE.DP", "DE.AE"]} known_false_positives = unknown providing_technologies = [] @@ -3582,6 +3756,16 @@ annotations = {"cis20": ["CIS 7", "CIS 8"], "kill_chain_phases": ["Installation" known_false_positives = This detection should yield little or no false positive results. It is uncommon for LNK files to be executed from temporary or user directories. providing_technologies = [] +[savedsearch://ESCU - Process Deleting Its Process File Path - Rule] +type = detection +asset_type = +confidence = medium +explanation = This detection is to identify a suspicious process that tries to delete the process file path related to its process. This technique is known to be defense evasion once a certain condition of malware is satisfied or not. Clop ransomware use this technique where it will try to delete its process file path using a .bat command if the keyboard layout is not the layout it tries to infect. +how_to_implement = You must be ingesting data that records process activity from your hosts to populate the Endpoint data model in the Processes node. You must also be ingesting logs with both the process name and command line from your endpoints. The command-line arguments are mapped to the "process" field in the Endpoint data model. +annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1003.002"]} +known_false_positives = unknown +providing_technologies = [] + [savedsearch://ESCU - Process Execution via WMI - Rule] type = detection asset_type = Endpoint @@ -3662,6 +3846,16 @@ annotations = {"cis20": ["CIS 9", "CIS 14"], "kill_chain_phases": ["Reconnaissan known_false_positives = Some networks may use kerberized FTP or telnet servers, however, this is rare. providing_technologies = [] +[savedsearch://ESCU - Ransomware Notes bulk creation - Rule] +type = detection +asset_type = +confidence = medium +explanation = The following analytics identifies a big number of instance of ransomware notes (filetype e.g .txt, .html, .hta) file creation to the infected machine. This behavior is a good sensor if the ransomware note filename is quite new for security industry or the ransomware note filename is not in your lookup table list for monitoring. +how_to_implement = You must be ingesting data that records the filesystem activity from your hosts to populate the Endpoint file-system data model node. If you are using Sysmon, you will need a Splunk Universal Forwarder on each endpoint from which you want to collect data. +annotations = {"kill_chain_phases": ["Obfuscation"], "mitre_attack": ["T1486"]} +known_false_positives = unknown +providing_technologies = [] + [savedsearch://ESCU - Reg exe Manipulating Windows Services Registry Keys - Rule] type = detection asset_type = Endpoint @@ -3772,6 +3966,16 @@ annotations = {"cis20": ["CIS 3", "CIS 5"], "kill_chain_phases": ["Actions on Ob known_false_positives = Administrators may use this legitimately to gather info from remote systems. providing_technologies = [] +[savedsearch://ESCU - Resize ShadowStorage volume - Rule] +type = detection +asset_type = +confidence = medium +explanation = The following analytics identifies the resizing of shadowstorage by ransomware malware to avoid the shadow volumes being made again. this technique is an alternative by ransomware attacker than deleting the shadowstorage which is known alert in defensive team. one example of ransomware that use this technique is CLOP ransomware where it drops a .bat file that will resize the shadowstorage to minimum size as much as possible +how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. +annotations = {"kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1490"]} +known_false_positives = network admin can resize the shadowstorage for valid purposes. +providing_technologies = [] + [savedsearch://ESCU - RunDLL Loading DLL By Ordinal - Rule] type = detection asset_type = Endpoint @@ -4227,7 +4431,7 @@ asset_type = Endpoint confidence = medium explanation = The following analytic identifies a renamed instance of microsoft.workflow.compiler.exe. Microsoft.workflow.compiler.exe is natively found in C:\Windows\Microsoft.NET\Framework64\v4.0.30319 and is rarely utilized. When investigating, identify the executed code on disk and review. A spawned child process from microsoft.workflow.compiler.exe is uncommon. In any instance, microsoft.workflow.compiler.exe spawning from an Office product or any living off the land binary is highly suspect. how_to_implement = To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA. -annotations = {"cis20": ["CIS 8"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1127, T1036.003"], "nist": ["PR.PT", "DE.CM"]} +annotations = {"cis20": ["CIS 8"], "kill_chain_phases": ["Exploitation"], "mitre_attack": ["T1127", "T1036.003"], "nist": ["PR.PT", "DE.CM"]} known_false_positives = Although unlikely, some legitimate applications may use a moved copy of microsoft.workflow.compiler.exe, triggering a false positive. providing_technologies = [] diff --git a/package/lookups/ransomware_extensions.csv b/package/lookups/ransomware_extensions.csv index 0f003c3d8f..9e8fe7eff6 100644 --- a/package/lookups/ransomware_extensions.csv +++ b/package/lookups/ransomware_extensions.csv @@ -285,4 +285,6 @@ Extensions,Name .wnry,WannaCry .wncryt,WannaCry .WNCRYT,WannaCry -.RYK,Ryuk \ No newline at end of file +.RYK,Ryuk +.Clop,Clop +.Cllp,Clop \ No newline at end of file diff --git a/package/lookups/ransomware_notes.csv b/package/lookups/ransomware_notes.csv index ead875e6e9..ecdfd2479d 100644 --- a/package/lookups/ransomware_notes.csv +++ b/package/lookups/ransomware_notes.csv @@ -57,3 +57,5 @@ HELP_DECRYPT_YOUR_FILES.HTML,True *-SORRY-FOR-FILES.html,True *-READ-FOR-HELLPP.html,True RyukReadMe.html,True +ClopReadMe.txt,True +README_README.txt,True \ No newline at end of file From 1259c0aa3429017479d58f6635332350fae452d9 Mon Sep 17 00:00:00 2001 From: divious1 Date: Thu, 25 Mar 2021 22:54:23 -0400 Subject: [PATCH 2/2] bug in mitre_id that caused it to not be stored as a yaml array correctly --- bin/jinja2_templates/detection.j2 | 6 ++++-- bin/newcontent.py | 8 ++++++-- 2 files changed, 10 insertions(+), 4 deletions(-) diff --git a/bin/jinja2_templates/detection.j2 b/bin/jinja2_templates/detection.j2 index fa5e47448e..eb398c90d2 100644 --- a/bin/jinja2_templates/detection.j2 +++ b/bin/jinja2_templates/detection.j2 @@ -26,11 +26,13 @@ tags: - {{kill_chain_phase}} {% endfor -%} mitre_attack_id: - - {{mitre_attack_id}} + {% for id in mitre_attack_id -%} + - {{id}} + {% endfor -%} product: {% for product in products -%} - {{product}} {% endfor -%} required_fields: - _time - security_domain: {{security_domain}} \ No newline at end of file + security_domain: {{security_domain}} diff --git a/bin/newcontent.py b/bin/newcontent.py index d5cc61f4cf..004588ddc2 100644 --- a/bin/newcontent.py +++ b/bin/newcontent.py @@ -195,7 +195,11 @@ def detection_wizard(security_content_path,type,TEMPLATE_PATH): ] answers = prompt(questions) - mitre_attack_id = answers['mitre_attack_ids'].split(',') + + mitre_attack_id = [x.strip() for x in answers['mitre_attack_ids'].split(',')] + + print(mitre_attack_id) + j2_env = Environment(loader=FileSystemLoader(TEMPLATE_PATH), trim_blocks=True) @@ -218,7 +222,7 @@ def detection_wizard(security_content_path,type,TEMPLATE_PATH): description='UPDATE_DESCRIPTION', how_to_implement='UPDATE_HOW_TO_IMPLEMENT', known_false_positives='UPDATE_KNOWN_FALSE_POSITIVES', references='',datamodels=answers['datamodels'], search= answers['detection_search'] + ' | `' + detection_file_name + '_filter`', - type=answers['detection_type'], analytic_story_name='UPDATE_STORY_NAME', mitre_attack_id = answers['mitre_attack_ids'], + type=answers['detection_type'], analytic_story_name='UPDATE_STORY_NAME', mitre_attack_id=mitre_attack_id, kill_chain_phases=answers['kill_chain_phases'], dataset_url='UPDATE_DATASET_URL', products=answers['products'], security_domain=answers['security_domain']) with open(output_path, 'w', encoding="utf-8") as f: